[DPEDE-1784](deps): Bump systeminformation from 5.31.5 to 5.31.17 - #2116
[DPEDE-1784](deps): Bump systeminformation from 5.31.5 to 5.31.17#2116dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [systeminformation](https://github.com/sebhildebrandt/systeminformation) from 5.31.5 to 5.31.17. - [Release notes](https://github.com/sebhildebrandt/systeminformation/releases) - [Changelog](https://github.com/sebhildebrandt/systeminformation/blob/master/CHANGELOG.md) - [Commits](sebhildebrandt/systeminformation@v5.31.5...v5.31.17) --- updated-dependencies: - dependency-name: systeminformation dependency-version: 5.31.17 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
SonarQube Quality Gate |
|
The CI pipeline has run successfully in https://jenkinsprod.corp.intranet:8443/job/UX-CHI/job/Productive/job/Chi/job/PR-2116/1/. ✅ |
|
You can check this PRs instance in https://nginx-pr-2116-ux-chi.rke-odc-test.corp.intranet (internal) |
|
🔖 AiFEL verdict — 🚨 Escalate (ci-health) — human review required
TL;DR
📋 Why this route + what AiFEL checked (click to expand)Why this route?escalate because: critical CI confidence is Escalation category: Confidence breakdown — score:
What AiFEL checked
Will merging break your code?✅ Per AiFEL analysis, most likely won't impact your code. Security advisories✅ Nothing still affects ✅ Resolved by this bump (2): ✅ This bump resolves both known advisories that affected 5.31.5 and none affect 5.31.17 — clear on the security axis. Advisory details (fixed by this bump)GHSA-hvx9-hwr7-wjj9 (CVE-2026-44724) — CVSS 7.8 (high): Linux command injection in GHSA-5xpp-75jx-m839 (CVE-2026-50289) — CVSS not scored, severity high: OS command injection in Packages — what you have vs what this PR installs
Machine-readable verdict{
"schema_version": "1.1",
"classification": "patch",
"risk_band": "low",
"ci_confidence": "low",
"decision_route": "escalate",
"data_completeness": "complete",
"escalate_reason": "risk",
"missing_signals": [],
"confidence": 0.85,
"packages": [{"ecosystem": "npm", "name": "systeminformation", "old_version": "5.31.5", "new_version": "5.31.17"}],
"breaking_changes": [],
"cascade_conflicts": [],
"summary": "Routine patch bump (5.31.5→5.31.17) of an unused package that fixes two high-severity OS command injection advisories; dependency and security risk are low, but critical CI confidence is low (61.5% pass rate) — escalated on ci-health.",
"upgrade_risk_note": null,
"cross_repo_signal": "standalone",
"api_usage_found": false,
"advisory_ids": [],
"max_cvss": null,
"feedback_capture_marker": "aifel-CenturyLink-Chi-2116",
"agent_version": "1.1.1-aw"
}
|








Bumps systeminformation from 5.31.5 to 5.31.17.
Release notes
Sourced from systeminformation's releases.
Changelog
Sourced from systeminformation's changelog.
... (truncated)
Commits
9e799885.31.17c697de0fsSize() fixed parsing - spaces (linux)ee6b544getNvidiaSmi() System32 fastpath (windows), wifiConnections() query by UUID (...8ff6471fsSize() fixed parsing (linux)f5b93155.31.160e4bf2egetLoad(), getFullLoad() adapted (windows)b702b03getLoad(), getFullLoad() adapted (windows)85af0935.31.156f799d3code refacroting, hardening2ad8065smaller lib hardening changesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.