Skip to content

build(deps): bump @slack/web-api to v8 - #176

Merged
MarshallOfSound merged 1 commit into
mainfrom
bump-slack-axios-free
Oct 10, 2026
Merged

MarshallOfSound merged 1 commit into
mainfrom
bump-slack-axios-free

Conversation

@claude

@claude claude Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Requested by David Babenko-Sanders · Slack thread

Bumps @slack/web-api from ^6.10.0 (locked at 6.13.0) to ^8.2.0, which uses native fetch instead of axios, so axios and its transitive dependencies (agent-base, form-data, is-stream and friends) drop out of yarn.lock entirely. No code changes were needed: the WebClient is constructed with only a token and the code only calls chat.postMessage and users.profile.get, none of which are affected by the v7/v8 breaking changes; lint and tests pass, and both calls were smoke-tested against a local mock Slack API.

🤖 Generated with Claude Code

https://claude.ai/code/session_01JNyjV4J2pgJaC2WfJpGfCb


Generated by Claude Code

Bumps @slack/web-api from ^6.10.0 (locked 6.13.0) to ^8.2.0. v8 uses
native fetch instead of axios, so axios and its transitive dependencies
drop out of the lockfile. No code changes needed: the WebClient is
constructed with only a token and only chat.postMessage and
users.profile.get are used.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JNyjV4J2pgJaC2WfJpGfCb
@claude
claude Bot requested a review from a team as a code owner October 10, 2026 00:07
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​slack/​web-api@​6.13.0 ⏵ 8.2.099 +1100100 +198 +1100

View full report

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, straightforward dependency bump. Verified @ slack/web-api v6→v8 upgrade in package.json/yarn.lock: checked actual usage in action-audit.js and utils/helpers.js — WebClient is constructed with only a token and only chat.postMessage / users.profile.get are called, neither affected by the v7/v8 breaking changes. Confirmed the yarn.lock diff is internally consistent: axios/form-data/agent-base and related transitive deps are removed (v8 uses native fetch) while the new direct deps (@ slack/logger@^5, @ slack/types@^3, @ types/retry, retry, eventemitter3@^5) match @ slack/web-api@ 8.2.0's own package.json dependencies.

Extended reasoning...

Two-file diff (package.json, yarn.lock) bumping @ slack/web-api from ^6.10.0 to ^8.2.0 with no application code changes. Checked the only two Slack SDK call sites in the repo (action-audit.js, utils/helpers.js) against the v8 breaking-change surface and found no incompatibility. No security-sensitive surface is touched (no auth/crypto logic changed, just an HTTP client dependency swap from axios to native fetch). CODEOWNERS only has a generic fallback, no specific ownership concern, and the lockfile removals/additions are mechanically consistent with the new package's dependency tree.

@MarshallOfSound
MarshallOfSound enabled auto-merge (squash) October 10, 2026 10:36
@MarshallOfSound
MarshallOfSound merged commit efe3d49 into main Oct 10, 2026
8 checks passed
@MarshallOfSound
MarshallOfSound deleted the bump-slack-axios-free branch October 10, 2026 10:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants