Skip to content

Update Risk SDK dependency to 6.0.1 - #555

Merged
ali-farhadi-cko merged 1 commit into
mainfrom
chore/update-risk-sdk-6.0.1
Oct 2, 2026
Merged

ali-farhadi-cko merged 1 commit into
mainfrom
chore/update-risk-sdk-6.0.1

Conversation

@ali-farhadi-cko

Copy link
Copy Markdown
Contributor

Summary

Bumps the Risk SDK dependency from 4.0.1 to 6.0.1.

  • Package.swift: SwiftPM checkout-risk-sdk-ios from: "4.0.1" → from: "6.0.1"
  • Checkout.podspec: Risk ~> 4.0.1 → ~> 6.0.1
  • Regenerated iOS Example Frame/Podfile.lock and Checkout/Samples/CocoapodsSample/Podfile.lock

The major bump pulls in FingerprintPro >= 2.12.0 (locks moved 2.13.0 → 2.17.2) and a new FingerprintJS 1.7.0 transitive dependency.

Notes

  • No source changes were needed — the Risk API used in CheckoutAPIService (RiskConfig, Risk.init(config:), configure, publishData, RiskEnvironment) is unchanged in 6.0.1.
  • The iOS Example Frame SPM project's Package.resolved was intentionally left untouched: it tracks the published frames-ios package and will pick up Risk 6.0.1 once a release ships with this change.

Testing

  • Built the Checkout scheme against the iOS simulator — BUILD SUCCEEDED linking against Risk 6.0.1.

🤖 Generated with Claude Code

Bump the Risk SDK from 4.0.1 to 6.0.1 in the SwiftPM manifest and the
CocoaPods podspec, and regenerate both sample Podfile.lock files. The
major bump pulls in FingerprintPro >= 2.12.0 and a new FingerprintJS
1.7.0 dependency, both reflected in the locks. No source changes were
needed: the Risk API used in CheckoutAPIService is unchanged in 6.0.1.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@agent-wall-e

agent-wall-e Bot commented Oct 2, 2026

Copy link
Copy Markdown

🟡 Risk Classification: MINOR

Approval route: AI Review + Human Approval
Rollback controls: Staged rollout + rollback

Classification reasons

  • no_low_class_matched
  • prod_source_modified

Operational gates

  • ✅ jira_ticket
  • ✅ independent_review

Files analysed: 4


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Oct 2, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
no_low_class_matched informational §2.2 (fall-through) None of the deterministic Low classes (§2.2.3, §2.2.4, §2.2.7, docs-only) applied; classifier fell through to LLM evaluation.
prod_source_modified informational §2.1 M7 (informational) At least one file is non-doc, non-test, non-IaC — i.e. application source code was modified.

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Oct 2, 2026

Copy link
Copy Markdown

🔵 Advisory review: Sound, but needs your judgement

This PR needs a human approval. The code itself reads as correct; whether it should land depends on context I don't have.

This is a straightforward dependency bump of Risk SDK from 4.0.1 to 6.0.1, updating Package.swift, the podspec, and regenerating both Podfile.lock files consistently. The diff is internally consistent, but skipping a major version (4→6) and adding a new transitive dependency (FingerprintJS) warrants human sign-off on behavioral and privacy implications.

For you to decide

  • The version jump skips major version 5 entirely (4.0.1 → 6.0.1), which typically implies two sets of potentially breaking changes — a reviewer should verify whether any Risk SDK API changes between v4 and v6 are silently ignored or whether the 'no source changes needed' claim has been validated against the full changelog.
  • FingerprintJS 1.7.0 is a brand-new transitive dependency not present in the previous lock files; this is a data-collection/device-fingerprinting library and its addition may have privacy policy, App Store review, or legal implications that only the team can assess.
  • FingerprintPro bumped from 2.13.0 to 2.17.2 — the reviewer should check whether any behavioral changes in that range affect how device signals are collected or transmitted.
  • PhoneNumberKit checksum changed (b05dfa2f → 8b6138c9) in the iOS Example Frame Podfile.lock without an explicit version bump in the diff, suggesting CocoaPods 1.17.0 resolved a different version or the checksum algorithm changed; this should be confirmed as benign.
  • Both Podfile.lock files show a CocoaPods version upgrade from 1.16.2 to 1.17.0, which is fine but means the locks cannot be reproduced by teammates still on 1.16.2.

This is not an approval. wall-e cannot auto-approve this PR — it is an opinion to help whoever does. Advisory review · us.anthropic.claude-sonnet-4-6 · wall-e 2026.06.19-02

@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@ali-farhadi-cko
ali-farhadi-cko merged commit f4886c8 into main Oct 2, 2026
8 checks passed
@ali-farhadi-cko
ali-farhadi-cko deleted the chore/update-risk-sdk-6.0.1 branch October 2, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants