Update Risk SDK dependency to 6.0.1 - #555
Conversation
Bump the Risk SDK from 4.0.1 to 6.0.1 in the SwiftPM manifest and the CocoaPods podspec, and regenerate both sample Podfile.lock files. The major bump pulls in FingerprintPro >= 2.12.0 and a new FingerprintJS 1.7.0 dependency, both reflected in the locks. No source changes were needed: the Risk API used in CheckoutAPIService is unchanged in 6.0.1. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
🟡 Risk Classification: MINORApproval route: AI Review + Human Approval Classification reasons
Operational gates
Files analysed: 4 wall-e 2026.06.19-02 · policy |
🔬 Debug — why this classification?Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.
Kinds:
See issue #3 for the proposal to formalise this map as Appendix A of the standards doc. wall-e 2026.06.19-02 · debug |
🔵 Advisory review: Sound, but needs your judgementThis PR needs a human approval. The code itself reads as correct; whether it should land depends on context I don't have. This is a straightforward dependency bump of Risk SDK from 4.0.1 to 6.0.1, updating Package.swift, the podspec, and regenerating both Podfile.lock files consistently. The diff is internally consistent, but skipping a major version (4→6) and adding a new transitive dependency (FingerprintJS) warrants human sign-off on behavioral and privacy implications. For you to decide
This is not an approval. wall-e cannot auto-approve this PR — it is an opinion to help whoever does. Advisory review · us.anthropic.claude-sonnet-4-6 · wall-e 2026.06.19-02 |
|



Summary
Bumps the Risk SDK dependency from 4.0.1 to 6.0.1.
Package.swift: SwiftPMcheckout-risk-sdk-iosfrom: "4.0.1"→from: "6.0.1"Checkout.podspec:Risk~> 4.0.1→~> 6.0.1iOS Example Frame/Podfile.lockandCheckout/Samples/CocoapodsSample/Podfile.lockThe major bump pulls in FingerprintPro
>= 2.12.0(locks moved 2.13.0 → 2.17.2) and a new FingerprintJS1.7.0transitive dependency.Notes
CheckoutAPIService(RiskConfig,Risk.init(config:),configure,publishData,RiskEnvironment) is unchanged in 6.0.1.iOS Example Frame SPMproject'sPackage.resolvedwas intentionally left untouched: it tracks the publishedframes-iospackage and will pick up Risk 6.0.1 once a release ships with this change.Testing
Checkoutscheme against the iOS simulator — BUILD SUCCEEDED linking against Risk 6.0.1.🤖 Generated with Claude Code