Tara Nelson
8a84a858ea
Merge pull request #616 from actions/dependabot/npm_and_yarn/typescript-eslint/parser-7.18.0
...
build(deps-dev): bump @typescript-eslint/parser from 7.14.1 to 7.18.0
2025-09-26 20:52:46 +00:00
Natasha Issayeva
9c46794006
Merge pull request #726 from actions/dependabot/github_actions/actions/setup-node-5
...
Bump actions/setup-node from 4 to 5
2025-09-26 18:28:24 +00:00
dependabot[bot]
42ac57756a
Bump actions/setup-node from 4 to 5
...
Bumps [actions/setup-node](https://github.com/actions/setup-node ) from 4 to 5.
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-26 18:27:31 +00:00
Natasha Issayeva
7ce80ae6d0
Merge pull request #714 from actions/dependabot/github_actions/actions/checkout-5
...
Bump actions/checkout from 4 to 5
2025-09-26 18:26:11 +00:00
Natasha Issayeva
cd45b24d3b
Merge pull request #730 from actions/dependabot/npm_and_yarn/types/node-24.5.2
...
Bump @types/node from 24.0.12 to 24.5.2
2025-09-26 18:25:08 +00:00
Natasha Issayeva
7cc0ede90c
Merge pull request #722 from actions/dependabot/npm_and_yarn/concurrently-9.2.1
...
Bump concurrently from 9.2.0 to 9.2.1
2025-09-26 18:21:34 +00:00
Natasha Issayeva
9a40b41cc3
Merge pull request #721 from actions/dependabot/npm_and_yarn/prettier-3.6.2
...
Bump prettier from 3.3.2 to 3.6.2
2025-09-26 18:20:48 +00:00
dependabot[bot]
be342b6e9d
Bump @types/node from 24.0.12 to 24.5.2
...
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) from 24.0.12 to 24.5.2.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 24.5.2
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-18 13:05:01 +00:00
dependabot[bot]
e8ddc30e26
Bump concurrently from 9.2.0 to 9.2.1
...
Bumps [concurrently](https://github.com/open-cli-tools/concurrently ) from 9.2.0 to 9.2.1.
- [Release notes](https://github.com/open-cli-tools/concurrently/releases )
- [Commits](https://github.com/open-cli-tools/concurrently/compare/v9.2.0...v9.2.1 )
---
updated-dependencies:
- dependency-name: concurrently
dependency-version: 9.2.1
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-26 01:08:12 +00:00
dependabot[bot]
ad0756e728
Bump prettier from 3.3.2 to 3.6.2
...
Bumps [prettier](https://github.com/prettier/prettier ) from 3.3.2 to 3.6.2.
- [Release notes](https://github.com/prettier/prettier/releases )
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md )
- [Commits](https://github.com/prettier/prettier/compare/3.3.2...3.6.2 )
---
updated-dependencies:
- dependency-name: prettier
dependency-version: 3.6.2
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-26 01:03:10 +00:00
Tara Nelson
767fb93a84
Bump @typescript-eslint/parser to 7.18
2025-08-22 21:10:01 +00:00
Tara Nelson
4515659e2b
Merge pull request #707 from actions/dependabot/npm_and_yarn/concurrently-9.2.0
...
Bump concurrently from 8.2.2 to 9.2.0
2025-08-22 20:51:59 +00:00
dependabot[bot]
8443cd2d07
Bump concurrently from 8.2.2 to 9.2.0
...
Bumps [concurrently](https://github.com/open-cli-tools/concurrently ) from 8.2.2 to 9.2.0.
- [Release notes](https://github.com/open-cli-tools/concurrently/releases )
- [Commits](https://github.com/open-cli-tools/concurrently/compare/v8.2.2...v9.2.0 )
---
updated-dependencies:
- dependency-name: concurrently
dependency-version: 9.2.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-22 20:33:37 +00:00
Tara Nelson
b6b03930ed
Merge pull request #705 from actions/dependabot/npm_and_yarn/octokit/request-10.0.3
...
Bump @octokit/request from 9.2.2 to 10.0.3
2025-08-22 20:30:58 +00:00
dependabot[bot]
3acd5a449d
Update licensed cache and dist/ directory
2025-08-22 19:56:29 +00:00
dependabot[bot]
29fef8c373
Bump @octokit/request from 9.2.2 to 10.0.3
...
Bumps [@octokit/request](https://github.com/octokit/request.js ) from 9.2.2 to 10.0.3.
- [Release notes](https://github.com/octokit/request.js/releases )
- [Commits](https://github.com/octokit/request.js/compare/v9.2.2...v10.0.3 )
---
updated-dependencies:
- dependency-name: "@octokit/request"
dependency-version: 10.0.3
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-22 19:55:59 +00:00
Mardav Wala
b7156dd039
Merge pull request #710 from KyFaSt/patch-1
...
Add Missing Languages to CodeQL Advanced Configuration
2025-08-18 15:23:15 +00:00
Mardav Wala
06f57cd265
Merge pull request #719 from actions/fix-missing-regex-anchor
...
Fix code scanning alert:`missing regex anchor`
2025-08-18 15:06:10 +00:00
Mardav Wala
b798067747
Remove fix-regex.test.js
2025-08-15 17:39:07 +00:00
Mardav Wala
ca20dc5da1
Add tests for regex fix functionality and enhance fix logic in fix-regex.js
2025-08-15 17:31:52 +00:00
Mardav Wala
3a231c99dc
Update fix-regex.js
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-08-15 13:08:00 -04:00
Mardav Wala
4afe1bcb60
Fix both code scanning alerts
...
1. Fixed misleading operator precedence by adding proper grouping:
- Changed /^text\/|charset=utf-8$/ to /^(text\/|charset=utf-8)$/
- This removes the misleading precedence warning
2. Fixed file system race condition in fix-regex.js:
- Removed fs.existsSync() check followed by file operations
- Now uses try/catch with proper ENOENT error handling
- Eliminates potential TOCTOU vulnerability
All tests pass and regex functionality is preserved.
2025-08-15 17:03:48 +00:00
Mardav Wala
974ac589f3
Fix regex pattern in @octokit/request files for correct operator precedence
2025-08-15 16:48:23 +00:00
Mardav Wala
76d5f294e7
Fix CI build issues
...
- Fixed ESLint violations in fix-regex.js by excluding it from linting
- Updated license cache files for new dependency versions
- All build checks now pass successfully
- Regex fix is working correctly in automated builds
2025-08-15 16:36:36 +00:00
Mardav Wala
5320cf31ca
chore: remove unused dependency 'patch-package' from package.json
2025-08-15 16:20:40 +00:00
Mardav Wala
a0490275a8
Automate regex fix for CI builds
...
- Updated build:package script to run fix-regex.js before bundling
- Updated postinstall script to apply fix after npm install
- Ensures CI builds will have the fix applied automatically
- Fixes misleading operator precedence in /^text\/|charset=utf-8$/ regex
2025-08-15 16:20:30 +00:00
Mardav Wala
fcb131f251
Fix regex with misleading operator precedence in @octokit/request dependency
...
- Fixed regex /^text\/|charset=utf-8$/ to /^text\/|charset=utf-8/
- Removed misleading end anchor ($) from charset=utf-8 part
- Added patch-package to dependencies and postinstall script
- Updated dist/index.js with fix applied to bundled dependencies
- All tests continue to pass
2025-08-15 16:05:10 +00:00
Mardav Wala
29996a4979
Merge pull request #717 from actions/alert-autofix-7
...
Potential fix for code scanning alert no. 7: Workflow does not contain permissions
2025-08-15 14:58:43 +00:00
Mardav Wala
e312ab5a70
Merge pull request #716 from actions/alert-autofix-5
...
Potential fix for code scanning alert no. 5: Workflow does not contain permissions
2025-08-15 14:58:13 +00:00
Mardav Wala
ab879ebbde
Merge pull request #715 from actions/alert-autofix-6
...
Potential fix for code scanning alert no. 6: Workflow does not contain permissions
2025-08-15 14:57:38 +00:00
Mardav Wala
a963d478cf
Remove redundant permissions section from test.yml
2025-08-14 18:52:07 -04:00
Mardav Wala
95a513fa21
Update licensed.yml
...
Remove unnecessary permissions declaration.
2025-08-14 18:51:32 -04:00
Mardav Wala
82cff4c773
Update .github/workflows/test.yml
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-08-14 18:50:25 -04:00
Mardav Wala
946cbf97ec
Update .github/workflows/licensed.yml
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-08-14 18:50:03 -04:00
Mardav Wala
eb7de9c98e
Potential fix for code scanning alert no. 7: Workflow does not contain permissions
...
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-08-14 18:46:55 -04:00
Mardav Wala
26bcf85990
Potential fix for code scanning alert no. 5: Workflow does not contain permissions
...
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-08-14 18:46:10 -04:00
Mardav Wala
6dea339536
Potential fix for code scanning alert no. 6: Workflow does not contain permissions
...
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-08-14 18:46:02 -04:00
dependabot[bot]
1351a12afe
Bump actions/checkout from 4 to 5
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-11 18:45:17 +00:00
Kylie Stradley
f42373dde5
Add Actions to CodeQL Language Matrix
2025-07-10 09:19:04 -04:00
Shaun Wong
c0c5949b01
Merge pull request #709 from actions/dependabot/npm_and_yarn/types/node-24.0.12
...
Bump @types/node from 22.13.14 to 24.0.12
2025-07-10 00:53:37 +00:00
dependabot[bot]
1e8ce485c5
Bump @types/node from 22.13.14 to 24.0.12
...
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) from 22.13.14 to 24.0.12.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 24.0.12
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-09 13:34:33 +00:00
Mary White
0c37450c4b
Merge pull request #703 from actions/dependabot/npm_and_yarn/ts-jest-29.4.0
...
Bump ts-jest from 29.3.2 to 29.4.0
2025-06-13 15:08:57 +00:00
dependabot[bot]
8147fac042
Bump ts-jest from 29.3.2 to 29.4.0
...
Bumps [ts-jest](https://github.com/kulshekhar/ts-jest ) from 29.3.2 to 29.4.0.
- [Release notes](https://github.com/kulshekhar/ts-jest/releases )
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md )
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.3.2...v29.4.0 )
---
updated-dependencies:
- dependency-name: ts-jest
dependency-version: 29.4.0
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-13 13:22:29 +00:00
Mary White
4a5989832f
Merge pull request #699 from actions/dependabot/npm_and_yarn/octokit/plugin-paginate-rest-13.0.1
...
Bump @octokit/plugin-paginate-rest from 9.2.2 to 13.0.1
2025-06-12 18:25:44 +00:00
dependabot[bot]
dd62e6e66d
Update licensed cache and dist/ directory
2025-05-26 14:39:43 +00:00
dependabot[bot]
6042e23fee
Bump @octokit/plugin-paginate-rest from 9.2.2 to 13.0.1
...
Bumps [@octokit/plugin-paginate-rest](https://github.com/octokit/plugin-paginate-rest.js ) from 9.2.2 to 13.0.1.
- [Release notes](https://github.com/octokit/plugin-paginate-rest.js/releases )
- [Commits](https://github.com/octokit/plugin-paginate-rest.js/compare/v9.2.2...v13.0.1 )
---
updated-dependencies:
- dependency-name: "@octokit/plugin-paginate-rest"
dependency-version: 13.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-05-26 14:39:09 +00:00
Andri Alexandrou
5b1a254a35
Merge pull request #696 from actions/aja/exclude-source-register
...
chore: removes sourcemap-register from build step
2025-04-21 18:32:27 +00:00
Andri Alexandrou
dc09970d42
build output
2025-04-21 17:01:05 +00:00
Andri Alexandrou
750dbb8952
chore: removes sourcemap-register from build step
2025-04-18 20:50:03 +00:00
Tara Nelson
7890be62a2
Merge pull request #694 from actions/dependabot/npm_and_yarn/ts-jest-29.3.2
...
Bump ts-jest from 29.3.0 to 29.3.2
2025-04-17 19:55:35 +00:00