From 73bf1f8aebfbff40928ea8dd01fadc5f38d5b2cb Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Fri, 28 Aug 2026 14:00:56 +0000 Subject: [PATCH] chore(deps): update dependency @scalar/api-reference to v1.67.0 --- internal/serviceoffercontroller/scalar_html.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/internal/serviceoffercontroller/scalar_html.go b/internal/serviceoffercontroller/scalar_html.go index c77f21d6d..9a8bef12d 100644 --- a/internal/serviceoffercontroller/scalar_html.go +++ b/internal/serviceoffercontroller/scalar_html.go @@ -14,7 +14,7 @@ import ( // payload never drifts silently. After a bump, refresh the SRI hash below // with scripts/update-scalar-sri.sh (the renovate PR body links it too). // renovate: datasource=npm depName=@scalar/api-reference -const scalarBundleVersion = "1.64.0" +const scalarBundleVersion = "1.67.0" // scalarBundleSRI is the Subresource Integrity hash for the pinned bundle. // The /api page is served over the public tunnel, so the third-party Scalar @@ -24,7 +24,7 @@ const scalarBundleVersion = "1.64.0" // bundle and rewrites this constant). The hash is taken over the exact // (jsdelivr-minified) bytes that the pinned URL serves; it must be refreshed // in lockstep with scalarBundleVersion or the browser will block the script. -const scalarBundleSRI = "sha384-MjGH/UsAZcRWbWSD70Yp9VOYGaCELxb+2a6meIvJsl5NkpqfdvkepJM6+ExL2Vmv" +const scalarBundleSRI = "sha384-zH522fC6a57bnP3yLzTekKbq61WR1WnYu4dxusbB48q1eska2wE6/qmqHAHEkv+H" // scalarHTML returns the static HTML shell served at /api. It loads the // pinned @scalar/api-reference bundle from jsdelivr, points it at the