Skip to content

Conversation

@gratestas
Copy link
Contributor

@gratestas gratestas commented Jun 22, 2022

Upgraded the version of several packages w.r.t. dependabot's suggestion.

  • node-forge ^0.10.0 to ^1.3.0
  • lodash ^4.7.20 to ^4.7,21
  • ejs ^2.6.1 to ^3.1.7

Also, in forked repo enabled security updates and merged several resulted PRs.

dependabot bot and others added 11 commits June 22, 2022 18:48
Bumps [@typescript-eslint/utils](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/utils) from 5.27.1 to 5.29.0.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/utils/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v5.29.0/packages/utils)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/utils"
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1 to 2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v1...v2)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v2...v3)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 2.5.1 to 3.3.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v2.5.1...v3.3.0)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 2.3.1 to 3.1.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v2.3.1...v3.1.0)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
…pt-eslint/utils-5.29.0

chore(deps-dev): bump @typescript-eslint/utils from 5.27.1 to 5.29.0
…s/checkout-3

chore(deps): bump actions/checkout from 2 to 3
…s/upload-artifact-3.1.0

chore(deps): bump actions/upload-artifact from 2.3.1 to 3.1.0
…s/setup-node-3.3.0

chore(deps): bump actions/setup-node from 2.5.1 to 3.3.0
…/codeql-action-2

chore(deps): bump github/codeql-action from 1 to 2
@gratestas gratestas requested review from alcercu and jaybuidl June 22, 2022 19:45
@netlify
Copy link

netlify bot commented Jun 22, 2022

Deploy Preview for kleros-v2 ready!

Name Link
🔨 Latest commit 5c21742
🔍 Latest deploy log https://app.netlify.com/sites/kleros-v2/deploys/62b436da5a45620009f45313
😎 Deploy Preview https://deploy-preview-107--kleros-v2.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@qlty-cloud-legacy
Copy link

Code Climate has analyzed commit 5c21742 and detected 0 issues on this pull request.

View more on Code Climate.

@sonarqubecloud
Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@gratestas gratestas changed the title Fixing dependabot alerts arose due to the node-forge package (fix-deps): Fixing dependabot alerts Jun 23, 2022
@gratestas gratestas added dependencies Pull requests that update a dependency file Type: Security Patch🛡️ labels Jun 23, 2022
@gratestas gratestas closed this Jun 23, 2022
@gratestas
Copy link
Contributor Author

reopened this PR from another branch #108

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file Type: Security Patch🛡️

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant