Skip to content

Conversation

@nfgallimore
Copy link
Member

No description provided.

snyk-bot and others added 21 commits August 31, 2024 07:52
Snyk has created this PR to upgrade winston from 3.13.1 to 3.14.1.

See this package in npm:
winston

See this project in Snyk:
https://app.snyk.io/org/ahim-gillamore/project/ee7fcd19-3ca5-400d-9ebb-c16580a5f566?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade mongoose from 8.5.1 to 8.5.2.

See this package in npm:
mongoose

See this project in Snyk:
https://app.snyk.io/org/ahim-gillamore/project/ee7fcd19-3ca5-400d-9ebb-c16580a5f566?utm_source=github&utm_medium=referral&page=upgrade-pr
Development update batch record to store schema for formula and product sku
Staging update batch record to add schema for formula and productsku
Snyk has created this PR to upgrade nodemailer from 6.9.14 to 6.9.15.

See this package in npm:
nodemailer

See this project in Snyk:
https://app.snyk.io/org/ahim-gillamore/project/ee7fcd19-3ca5-400d-9ebb-c16580a5f566?utm_source=github&utm_medium=referral&page=upgrade-pr
…00463be0e2d00f0ff0eecc7

[Snyk] Upgrade nodemailer from 6.9.14 to 6.9.15
…1cd5d8bd15583c5abb7467

[Snyk] Upgrade winston from 3.13.1 to 3.14.1
…84bba11b0ba7d4a7c209de9

[Snyk] Upgrade mongoose from 8.5.1 to 8.5.2
…cca57433974e4788e94

[Snyk] Security upgrade express from 4.19.2 to 4.20.0
…b01adba5a58e0f50dcb

[Snyk] Security upgrade express from 4.19.2 to 4.21.0
Bumps [send](https://github.com/pillarjs/send) from 0.18.0 to 0.19.0.
- [Release notes](https://github.com/pillarjs/send/releases)
- [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md)
- [Commits](pillarjs/send@0.18.0...0.19.0)

---
updated-dependencies:
- dependency-name: send
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [axios](https://github.com/axios/axios) to 1.7.7 and updates ancestor dependency [@openapitools/openapi-generator-cli](https://github.com/OpenAPITools/openapi-generator-cli). These dependencies need to be updated together.


Updates `axios` from 1.6.8 to 1.7.7
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.6.8...v1.7.7)

Updates `@openapitools/openapi-generator-cli` from 2.13.4 to 2.13.12
- [Release notes](https://github.com/OpenAPITools/openapi-generator-cli/releases)
- [Changelog](https://github.com/OpenAPITools/openapi-generator-cli/blob/master/.releaserc)
- [Commits](OpenAPITools/openapi-generator-cli@v2.13.4...v2.13.12)

---
updated-dependencies:
- dependency-name: axios
  dependency-type: indirect
- dependency-name: "@openapitools/openapi-generator-cli"
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [braces](https://github.com/micromatch/braces) to 3.0.3 and updates ancestor dependency [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest). These dependencies need to be updated together.


Updates `braces` from 2.3.2 to 3.0.3
- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md)
- [Commits](https://github.com/micromatch/braces/commits/3.0.3)

Updates `jest` from 26.6.3 to 29.7.0
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v29.7.0/packages/jest)

---
updated-dependencies:
- dependency-name: braces
  dependency-type: indirect
- dependency-name: jest
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
…n/send-0.19.0

Bump send from 0.18.0 to 0.19.0
Bumps [micromatch](https://github.com/micromatch/micromatch) to 4.0.8 and updates ancestor dependency [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest). These dependencies need to be updated together.


Updates `micromatch` from 4.0.7 to 4.0.8
- [Release notes](https://github.com/micromatch/micromatch/releases)
- [Changelog](https://github.com/micromatch/micromatch/blob/master/CHANGELOG.md)
- [Commits](micromatch/micromatch@4.0.7...4.0.8)

Updates `jest` from 26.6.3 to 29.7.0
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v29.7.0/packages/jest)

---
updated-dependencies:
- dependency-name: micromatch
  dependency-type: indirect
- dependency-name: jest
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
…n/multi-40a28fdfab

Bump axios and @openapitools/openapi-generator-cli
…n/multi-8dcb132c99

Bump micromatch and jest
@vercel
Copy link

vercel bot commented Sep 28, 2024

@nfgallimore is attempting to deploy a commit to the Ahim-GallimoreSoftrware's projects team on Vercel, but is not a member of this team. To resolve this issue, you can:

  • Make your repository public. Collaboration is free for open source and public repositories.
  • Upgrade to pro and add @nfgallimore as a member. A Pro subscription is required to access Vercel's collaborative features.
    • If you're the owner of the team, click here to upgrade and add @nfgallimore as a member.
    • If you're the user who initiated this build request, click here to request access.
    • If you're already a member of the Ahim-GallimoreSoftrware's projects team, make sure that your Vercel account is connected to your GitHub account.

To read more about collaboration on Vercel, click here.

@gitguardian
Copy link

gitguardian bot commented Sep 28, 2024

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
13251735 Triggered Generic High Entropy Secret f8e5680 .env.testing View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants