Skip to content

chore(deps): bump analyticssdk to 1.3.1 - #5

Merged
bbsnly merged 1 commit into
mainfrom
chore-bump-analyticssdk-1.3.1
Aug 10, 2026
Merged

bbsnly merged 1 commit into
mainfrom
chore-bump-analyticssdk-1.3.1

Conversation

@bbsnly

@bbsnly bbsnly commented Aug 6, 2026 •

Copy link
Copy Markdown
Collaborator

Why

Follow-up to #4's mitigation. #4 forces a patched koin-core version locally as a stopgap; this bumps the actual analyticssdk dependency to pick up the real fix from the SDK repo.

Change

Bumps com.siteimprove:analyticssdk from 1.1.0 to 1.3.1 in android/app/build.gradle.

Once this merges

Re-evaluate whether the resolutionStrategy.force for kotlin-stdlib/koin-core added in #4 is still needed, or can be narrowed/dropped now that the dependency itself is patched.

🤖 Generated with Claude Code

Picks up the koin-core CVE fix (Siteimprove/appanalytics-android-sdk#14)
once that SDK version is published. Once merged, the kotlin-stdlib/
koin-core resolutionStrategy.force added in #4 can likely be
re-evaluated/dropped.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@bbsnly
bbsnly marked this pull request as ready for review August 6, 2026 09:02
@bbsnly
bbsnly requested a review from Copilot August 6, 2026 09:02

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the Android app module’s dependency on com.siteimprove:analyticssdk to a newer version intended to pick up upstream fixes (notably around the transitive dependency mitigation discussed in #4).

Changes:

  • Bump com.siteimprove:analyticssdk from 1.1.0 to 1.3.1 in android/app/build.gradle.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@bbsnly
bbsnly merged commit 571bd74 into main Aug 10, 2026
1 check passed
@bbsnly
bbsnly deleted the chore-bump-analyticssdk-1.3.1 branch August 10, 2026 07:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants