Skip to content

(fix-deps): Fixing dependabot alerts #107

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 13 commits into from
Closed

Conversation

gratestas
Copy link
Contributor

@gratestas gratestas commented Jun 22, 2022

Upgraded the version of several packages w.r.t. dependabot's suggestion.

  • node-forge ^0.10.0 to ^1.3.0
  • lodash ^4.7.20 to ^4.7,21
  • ejs ^2.6.1 to ^3.1.7

Also, in forked repo enabled security updates and merged several resulted PRs.

dependabot bot and others added 11 commits June 22, 2022 18:48
Bumps [@typescript-eslint/utils](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/utils) from 5.27.1 to 5.29.0.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/utils/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v5.29.0/packages/utils)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/utils"
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1 to 2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v1...v2)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v2...v3)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 2.5.1 to 3.3.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v2.5.1...v3.3.0)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 2.3.1 to 3.1.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v2.3.1...v3.1.0)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…pt-eslint/utils-5.29.0

chore(deps-dev): bump @typescript-eslint/utils from 5.27.1 to 5.29.0
…s/checkout-3

chore(deps): bump actions/checkout from 2 to 3
…s/upload-artifact-3.1.0

chore(deps): bump actions/upload-artifact from 2.3.1 to 3.1.0
…s/setup-node-3.3.0

chore(deps): bump actions/setup-node from 2.5.1 to 3.3.0
…/codeql-action-2

chore(deps): bump github/codeql-action from 1 to 2
@gratestas gratestas requested review from jaybuidl and alcercu June 22, 2022 19:45
@netlify
Copy link

netlify bot commented Jun 22, 2022

Deploy Preview for kleros-v2 ready!

Name Link
🔨 Latest commit 5c21742
🔍 Latest deploy log https://app.netlify.com/sites/kleros-v2/deploys/62b436da5a45620009f45313
😎 Deploy Preview https://deploy-preview-107--kleros-v2.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@codeclimate
Copy link

codeclimate bot commented Jun 23, 2022

Code Climate has analyzed commit 5c21742 and detected 0 issues on this pull request.

View more on Code Climate.

@sonarqubecloud
Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@gratestas gratestas changed the title Fixing dependabot alerts arose due to the node-forge package (fix-deps): Fixing dependabot alerts Jun 23, 2022
@gratestas gratestas added dependencies Pull requests that update a dependency file Type: Security Patch🛡️ labels Jun 23, 2022
@gratestas gratestas closed this Jun 23, 2022
@gratestas
Copy link
Contributor Author

reopened this PR from another branch #108

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file Type: Security Patch🛡️
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant