Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security updates #859

Open
wants to merge 7 commits into
base: master
Choose a base branch
from

Conversation

starlightretailceo
Copy link

This pull request introduces a SECURITY.md file to the project. The file outlines the project's security policy, including the versions of the project that are currently supported with security updates, and instructions on how to report a vulnerability.

Main changes:

  • SECURITY.md: Added a new file to provide information about the project's security policy. It lists the versions of the project that are currently supported with security updates, and provides instructions on how to report a vulnerability.

starlightretailceo and others added 6 commits July 3, 2024 19:34
Signed-off-by: Mammon Baloch <154027819+starlightretailceo@users.noreply.github.com>
Bumps the npm_and_yarn group with 1 update in the / directory: [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse).


Updates `@babel/traverse` from 7.20.10 to 7.24.7
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.24.7/packages/babel-traverse)

---
updated-dependencies:
- dependency-name: "@babel/traverse"
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the npm_and_yarn group with 1 update in the / directory: [ws](https://github.com/websockets/ws).


Updates `ws` from 7.5.9 to 7.5.10
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@7.5.9...7.5.10)

---
updated-dependencies:
- dependency-name: ws
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
…m_and_yarn-f9fce6bf0c

build(deps-dev): bump @babel/traverse from 7.20.10 to 7.24.7 in the npm_and_yarn group across 1 directory
…m_and_yarn-9b5403960e

build(deps-dev): bump ws from 7.5.9 to 7.5.10 in the npm_and_yarn group across 1 directory
…dates

Bumps the npm_and_yarn group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [express](https://github.com/expressjs/express) | `4.18.2` | `4.19.2` |
| [postcss](https://github.com/postcss/postcss) | `8.4.20` | `8.4.31` |
| [ejs](https://github.com/mde/ejs) | `2.7.4` | `3.1.10` |
| [@open-wc/building-rollup](https://github.com/open-wc/open-wc/tree/HEAD/packages/building-rollup) | `1.10.0` | `3.0.2` |
| [flat](https://github.com/hughsk/flat) | `4.1.1` | `removed` |
| [@open-wc/testing](https://github.com/open-wc/open-wc/tree/HEAD/packages/testing) | `2.5.33` | `4.0.0` |
| [follow-redirects](https://github.com/follow-redirects/follow-redirects) | `1.15.4` | `1.15.6` |
| [tough-cookie](https://github.com/salesforce/tough-cookie) | `4.1.2` | `4.1.4` |
| [ws](https://github.com/websockets/ws) | `7.5.9` | `7.5.10` |



Updates `express` from 4.18.2 to 4.19.2
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/master/History.md)
- [Commits](expressjs/express@4.18.2...4.19.2)

Updates `postcss` from 8.4.20 to 8.4.31
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.4.20...8.4.31)

Updates `ejs` from 2.7.4 to 3.1.10
- [Release notes](https://github.com/mde/ejs/releases)
- [Commits](mde/ejs@v2.7.4...v3.1.10)

Updates `@open-wc/building-rollup` from 1.10.0 to 3.0.2
- [Release notes](https://github.com/open-wc/open-wc/releases)
- [Changelog](https://github.com/open-wc/open-wc/blob/master/packages/building-rollup/CHANGELOG.md)
- [Commits](https://github.com/open-wc/open-wc/commits/@open-wc/building-rollup@3.0.2/packages/building-rollup)

Removes `flat`

Updates `@open-wc/testing` from 2.5.33 to 4.0.0
- [Release notes](https://github.com/open-wc/open-wc/releases)
- [Changelog](https://github.com/open-wc/open-wc/blob/master/packages/testing/CHANGELOG.md)
- [Commits](https://github.com/open-wc/open-wc/commits/@open-wc/testing@4.0.0/packages/testing)

Updates `follow-redirects` from 1.15.4 to 1.15.6
- [Release notes](https://github.com/follow-redirects/follow-redirects/releases)
- [Commits](follow-redirects/follow-redirects@v1.15.4...v1.15.6)

Updates `tough-cookie` from 4.1.2 to 4.1.4
- [Release notes](https://github.com/salesforce/tough-cookie/releases)
- [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md)
- [Commits](salesforce/tough-cookie@v4.1.2...v4.1.4)

Updates `ws` from 7.5.9 to 7.5.10
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@7.5.9...7.5.10)

---
updated-dependencies:
- dependency-name: express
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: postcss
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: ejs
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: "@open-wc/building-rollup"
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: flat
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: "@open-wc/testing"
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: follow-redirects
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: tough-cookie
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ws
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@starlightretailceo starlightretailceo requested a review from a team as a code owner July 4, 2024 02:41
Copy link

salesforce-cla bot commented Jul 4, 2024

Thanks for the contribution! Before we can merge this, we need @starlightretailceo to sign the Salesforce Inc. Contributor License Agreement.

@starlightretailceo starlightretailceo marked this pull request as draft July 4, 2024 02:43
@starlightretailceo starlightretailceo marked this pull request as ready for review July 4, 2024 02:43
@starlightretailceo
Copy link
Author

This pull request introduces a new SECURITY.md file. This file outlines the project's security policy, including the versions currently supported with security updates and how to report a vulnerability.

  • SECURITY.md: Added a new file to define the project's security policy. It includes a table listing the supported versions and instructions on how to report a vulnerability.
    CLA IS SIGNED

@starlightretailceo
Copy link
Author

This pull request introduces a new SECURITY.md file to the project. The file outlines the project's security policy, including which versions are currently supported with security updates and how to report a vulnerability.

  • SECURITY.md: A new file that provides guidelines on the project's security policy. It includes a table of supported versions for security updates and instructions on how to report a vulnerability.

…m_and_yarn-dd4e65e81c

build(deps): bump the npm_and_yarn group across 1 directory with 9 updates
@starlightretailceo
Copy link
Author

This pull request includes updates to the security policy and dependency versions in the project. The most important changes are the addition of a SECURITY.md file and updates to several dependencies in package.json.

Security Policy:

  • SECURITY.md: Added a new security policy document outlining supported versions and the process for reporting vulnerabilities.

Dependency Updates:

  • package.json: Updated @open-wc/building-rollup from ^1.2.6 to ^3.0.2.
  • package.json: Updated @open-wc/testing from ^2.5.16 to ^4.0.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant