Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

admin/upgrade-dependabot (#150) #151

Merged
merged 1 commit into from
Dec 6, 2023
Merged

admin/upgrade-dependabot (#150) #151

merged 1 commit into from
Dec 6, 2023

Conversation

tohuynh
Copy link
Collaborator

@tohuynh tohuynh commented Dec 6, 2023

  • Allow only high or critical security upgrades to production deps with widen strategy

  • Security and severity are not valid schema

  • Ignore dev deps

  • Disable version updates Add comments
    Use auto strategy

  • Use npm ci in workflows

  • Revert to [email protected]

  • Add back comments


Pull request recommendations:

  • Name your pull request your-development-type/short-description. Ex: feature/read-tiff-files
  • Link to any relevant issue in the PR description. Ex: Resolves [admin/update-packpage-dependencies #12], adds tiff file format support
  • Provide context of changes.
  • Provide relevant tests for your feature or bug fix.
  • Provide or update documentation for any feature added by your pull request.

Thanks for contributing!

* Allow only high or critical security upgrades to production deps with widen strategy

* Security and severity are not valid schema

* Ignore dev deps

* Disable version updates
Add comments
Use auto strategy

* Use npm ci in workflows

* Revert to [email protected]

* Add back comments

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>
@tohuynh tohuynh merged commit c065e30 into main Dec 6, 2023
7 checks passed
tohuynh added a commit that referenced this pull request Dec 6, 2023
* admin/upgrade-dependabot (#150) (#151)

* Allow only high or critical security upgrades to production deps with widen strategy

* Security and severity are not valid schema

* Ignore dev deps

* Disable version updates
Add comments
Use auto strategy

* Use npm ci in workflows

* Revert to [email protected]

* Add back comments

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>

* Resolve axios and follow-redirects security issues

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>
tohuynh added a commit that referenced this pull request Dec 7, 2023
* admin/upgrade-dependabot (#150)

* Allow only high or critical security upgrades to production deps with widen strategy

* Security and severity are not valid schema

* Ignore dev deps

* Disable version updates
Add comments
Use auto strategy

* Use npm ci in workflows

* Revert to [email protected]

* Add back comments

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>

* admin/upgrade-axios-deps (#153)

* admin/upgrade-dependabot (#150) (#151)

* Allow only high or critical security upgrades to production deps with widen strategy

* Security and severity are not valid schema

* Ignore dev deps

* Disable version updates
Add comments
Use auto strategy

* Use npm ci in workflows

* Revert to [email protected]

* Add back comments

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>

* Resolve axios and follow-redirects security issues

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>

* Upgrade next-auth (#154)

* Upgrade a few transitive deps (#155)

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>
tohuynh added a commit that referenced this pull request Mar 21, 2024
* admin/upgrade-dependabot (#150) (#151)

* Allow only high or critical security upgrades to production deps with widen strategy

* Security and severity are not valid schema

* Ignore dev deps

* Disable version updates
Add comments
Use auto strategy

* Use npm ci in workflows

* Revert to [email protected]

* Add back comments

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>

* admin/upgrade-deps-in-main (#157)

* admin/upgrade-dependabot (#150)

* Allow only high or critical security upgrades to production deps with widen strategy

* Security and severity are not valid schema

* Ignore dev deps

* Disable version updates
Add comments
Use auto strategy

* Use npm ci in workflows

* Revert to [email protected]

* Add back comments

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>

* admin/upgrade-axios-deps (#153)

* admin/upgrade-dependabot (#150) (#151)

* Allow only high or critical security upgrades to production deps with widen strategy

* Security and severity are not valid schema

* Ignore dev deps

* Disable version updates
Add comments
Use auto strategy

* Use npm ci in workflows

* Revert to [email protected]

* Add back comments

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>

* Resolve axios and follow-redirects security issues

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>

* Upgrade next-auth (#154)

* Upgrade a few transitive deps (#155)

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>

* Upgrade axios to 0.21.4

* Don't pre-stringified json-ld

---------

Co-authored-by: Sebastian Ostrowski <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant