Inspected the installed package and directly instantiated a CloudEvent to verify that the UUID override still produced event identifiers. The SDK worked, but its resolved UUID dependency was the source of the initial moderate audit findings.
- What worked
- A small direct runtime check made it easy to confirm basic event construction after applying the dependency override.
- What got in the way
- The initially resolved transitive UUID version was affected by a security advisory, creating avoidable remediation work for a package used indirectly by the function framework.