-
Notifications
You must be signed in to change notification settings - Fork 237
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security updates #859
base: master
Are you sure you want to change the base?
Security updates #859
Conversation
Signed-off-by: Mammon Baloch <154027819+starlightretailceo@users.noreply.github.com>
Bumps the npm_and_yarn group with 1 update in the / directory: [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse). Updates `@babel/traverse` from 7.20.10 to 7.24.7 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.24.7/packages/babel-traverse) --- updated-dependencies: - dependency-name: "@babel/traverse" dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the npm_and_yarn group with 1 update in the / directory: [ws](https://github.com/websockets/ws). Updates `ws` from 7.5.9 to 7.5.10 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@7.5.9...7.5.10) --- updated-dependencies: - dependency-name: ws dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
…m_and_yarn-f9fce6bf0c build(deps-dev): bump @babel/traverse from 7.20.10 to 7.24.7 in the npm_and_yarn group across 1 directory
…m_and_yarn-9b5403960e build(deps-dev): bump ws from 7.5.9 to 7.5.10 in the npm_and_yarn group across 1 directory
…dates Bumps the npm_and_yarn group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [express](https://github.com/expressjs/express) | `4.18.2` | `4.19.2` | | [postcss](https://github.com/postcss/postcss) | `8.4.20` | `8.4.31` | | [ejs](https://github.com/mde/ejs) | `2.7.4` | `3.1.10` | | [@open-wc/building-rollup](https://github.com/open-wc/open-wc/tree/HEAD/packages/building-rollup) | `1.10.0` | `3.0.2` | | [flat](https://github.com/hughsk/flat) | `4.1.1` | `removed` | | [@open-wc/testing](https://github.com/open-wc/open-wc/tree/HEAD/packages/testing) | `2.5.33` | `4.0.0` | | [follow-redirects](https://github.com/follow-redirects/follow-redirects) | `1.15.4` | `1.15.6` | | [tough-cookie](https://github.com/salesforce/tough-cookie) | `4.1.2` | `4.1.4` | | [ws](https://github.com/websockets/ws) | `7.5.9` | `7.5.10` | Updates `express` from 4.18.2 to 4.19.2 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/master/History.md) - [Commits](expressjs/express@4.18.2...4.19.2) Updates `postcss` from 8.4.20 to 8.4.31 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.4.20...8.4.31) Updates `ejs` from 2.7.4 to 3.1.10 - [Release notes](https://github.com/mde/ejs/releases) - [Commits](mde/ejs@v2.7.4...v3.1.10) Updates `@open-wc/building-rollup` from 1.10.0 to 3.0.2 - [Release notes](https://github.com/open-wc/open-wc/releases) - [Changelog](https://github.com/open-wc/open-wc/blob/master/packages/building-rollup/CHANGELOG.md) - [Commits](https://github.com/open-wc/open-wc/commits/@open-wc/building-rollup@3.0.2/packages/building-rollup) Removes `flat` Updates `@open-wc/testing` from 2.5.33 to 4.0.0 - [Release notes](https://github.com/open-wc/open-wc/releases) - [Changelog](https://github.com/open-wc/open-wc/blob/master/packages/testing/CHANGELOG.md) - [Commits](https://github.com/open-wc/open-wc/commits/@open-wc/testing@4.0.0/packages/testing) Updates `follow-redirects` from 1.15.4 to 1.15.6 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.15.4...v1.15.6) Updates `tough-cookie` from 4.1.2 to 4.1.4 - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Changelog](https://github.com/salesforce/tough-cookie/blob/master/CHANGELOG.md) - [Commits](salesforce/tough-cookie@v4.1.2...v4.1.4) Updates `ws` from 7.5.9 to 7.5.10 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@7.5.9...7.5.10) --- updated-dependencies: - dependency-name: express dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: postcss dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: ejs dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@open-wc/building-rollup" dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: flat dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@open-wc/testing" dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tough-cookie dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ws dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Thanks for the contribution! Before we can merge this, we need @starlightretailceo to sign the Salesforce Inc. Contributor License Agreement. |
This pull request introduces a new
|
This pull request introduces a new
|
…m_and_yarn-dd4e65e81c build(deps): bump the npm_and_yarn group across 1 directory with 9 updates
This pull request includes updates to the security policy and dependency versions in the project. The most important changes are the addition of a Security Policy:
Dependency Updates:
|
This pull request introduces a
SECURITY.md
file to the project. The file outlines the project's security policy, including the versions of the project that are currently supported with security updates, and instructions on how to report a vulnerability.Main changes:
SECURITY.md
: Added a new file to provide information about the project's security policy. It lists the versions of the project that are currently supported with security updates, and provides instructions on how to report a vulnerability.