Commit Graph

876 Commits

Author SHA1 Message Date
Tara Nelson
8a84a858ea Merge pull request #616 from actions/dependabot/npm_and_yarn/typescript-eslint/parser-7.18.0
build(deps-dev): bump @typescript-eslint/parser from 7.14.1 to 7.18.0
2025-09-26 20:52:46 +00:00
Natasha Issayeva
9c46794006 Merge pull request #726 from actions/dependabot/github_actions/actions/setup-node-5
Bump actions/setup-node from 4 to 5
2025-09-26 18:28:24 +00:00
dependabot[bot]
42ac57756a Bump actions/setup-node from 4 to 5
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 5.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v4...v5)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-26 18:27:31 +00:00
Natasha Issayeva
7ce80ae6d0 Merge pull request #714 from actions/dependabot/github_actions/actions/checkout-5
Bump actions/checkout from 4 to 5
2025-09-26 18:26:11 +00:00
Natasha Issayeva
cd45b24d3b Merge pull request #730 from actions/dependabot/npm_and_yarn/types/node-24.5.2
Bump @types/node from 24.0.12 to 24.5.2
2025-09-26 18:25:08 +00:00
Natasha Issayeva
7cc0ede90c Merge pull request #722 from actions/dependabot/npm_and_yarn/concurrently-9.2.1
Bump concurrently from 9.2.0 to 9.2.1
2025-09-26 18:21:34 +00:00
Natasha Issayeva
9a40b41cc3 Merge pull request #721 from actions/dependabot/npm_and_yarn/prettier-3.6.2
Bump prettier from 3.3.2 to 3.6.2
2025-09-26 18:20:48 +00:00
dependabot[bot]
be342b6e9d Bump @types/node from 24.0.12 to 24.5.2
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 24.0.12 to 24.5.2.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 24.5.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-18 13:05:01 +00:00
dependabot[bot]
e8ddc30e26 Bump concurrently from 9.2.0 to 9.2.1
Bumps [concurrently](https://github.com/open-cli-tools/concurrently) from 9.2.0 to 9.2.1.
- [Release notes](https://github.com/open-cli-tools/concurrently/releases)
- [Commits](https://github.com/open-cli-tools/concurrently/compare/v9.2.0...v9.2.1)

---
updated-dependencies:
- dependency-name: concurrently
  dependency-version: 9.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-26 01:08:12 +00:00
dependabot[bot]
ad0756e728 Bump prettier from 3.3.2 to 3.6.2
Bumps [prettier](https://github.com/prettier/prettier) from 3.3.2 to 3.6.2.
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](https://github.com/prettier/prettier/compare/3.3.2...3.6.2)

---
updated-dependencies:
- dependency-name: prettier
  dependency-version: 3.6.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-26 01:03:10 +00:00
Tara Nelson
767fb93a84 Bump @typescript-eslint/parser to 7.18 2025-08-22 21:10:01 +00:00
Tara Nelson
4515659e2b Merge pull request #707 from actions/dependabot/npm_and_yarn/concurrently-9.2.0
Bump concurrently from 8.2.2 to 9.2.0
2025-08-22 20:51:59 +00:00
dependabot[bot]
8443cd2d07 Bump concurrently from 8.2.2 to 9.2.0
Bumps [concurrently](https://github.com/open-cli-tools/concurrently) from 8.2.2 to 9.2.0.
- [Release notes](https://github.com/open-cli-tools/concurrently/releases)
- [Commits](https://github.com/open-cli-tools/concurrently/compare/v8.2.2...v9.2.0)

---
updated-dependencies:
- dependency-name: concurrently
  dependency-version: 9.2.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-22 20:33:37 +00:00
Tara Nelson
b6b03930ed Merge pull request #705 from actions/dependabot/npm_and_yarn/octokit/request-10.0.3
Bump @octokit/request from 9.2.2 to 10.0.3
2025-08-22 20:30:58 +00:00
dependabot[bot]
3acd5a449d Update licensed cache and dist/ directory 2025-08-22 19:56:29 +00:00
dependabot[bot]
29fef8c373 Bump @octokit/request from 9.2.2 to 10.0.3
Bumps [@octokit/request](https://github.com/octokit/request.js) from 9.2.2 to 10.0.3.
- [Release notes](https://github.com/octokit/request.js/releases)
- [Commits](https://github.com/octokit/request.js/compare/v9.2.2...v10.0.3)

---
updated-dependencies:
- dependency-name: "@octokit/request"
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-22 19:55:59 +00:00
Mardav Wala
b7156dd039 Merge pull request #710 from KyFaSt/patch-1
Add Missing Languages to CodeQL Advanced Configuration
2025-08-18 15:23:15 +00:00
Mardav Wala
06f57cd265 Merge pull request #719 from actions/fix-missing-regex-anchor
Fix code scanning alert:`missing regex anchor`
2025-08-18 15:06:10 +00:00
Mardav Wala
b798067747 Remove fix-regex.test.js 2025-08-15 17:39:07 +00:00
Mardav Wala
ca20dc5da1 Add tests for regex fix functionality and enhance fix logic in fix-regex.js 2025-08-15 17:31:52 +00:00
Mardav Wala
3a231c99dc Update fix-regex.js
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-08-15 13:08:00 -04:00
Mardav Wala
4afe1bcb60 Fix both code scanning alerts
1. Fixed misleading operator precedence by adding proper grouping:
   - Changed /^text\/|charset=utf-8$/ to /^(text\/|charset=utf-8)$/
   - This removes the misleading precedence warning

2. Fixed file system race condition in fix-regex.js:
   - Removed fs.existsSync() check followed by file operations
   - Now uses try/catch with proper ENOENT error handling
   - Eliminates potential TOCTOU vulnerability

All tests pass and regex functionality is preserved.
2025-08-15 17:03:48 +00:00
Mardav Wala
974ac589f3 Fix regex pattern in @octokit/request files for correct operator precedence 2025-08-15 16:48:23 +00:00
Mardav Wala
76d5f294e7 Fix CI build issues
- Fixed ESLint violations in fix-regex.js by excluding it from linting
- Updated license cache files for new dependency versions
- All build checks now pass successfully
- Regex fix is working correctly in automated builds
2025-08-15 16:36:36 +00:00
Mardav Wala
5320cf31ca chore: remove unused dependency 'patch-package' from package.json 2025-08-15 16:20:40 +00:00
Mardav Wala
a0490275a8 Automate regex fix for CI builds
- Updated build:package script to run fix-regex.js before bundling
- Updated postinstall script to apply fix after npm install
- Ensures CI builds will have the fix applied automatically
- Fixes misleading operator precedence in /^text\/|charset=utf-8$/ regex
2025-08-15 16:20:30 +00:00
Mardav Wala
fcb131f251 Fix regex with misleading operator precedence in @octokit/request dependency
- Fixed regex /^text\/|charset=utf-8$/ to /^text\/|charset=utf-8/
- Removed misleading end anchor ($) from charset=utf-8 part
- Added patch-package to dependencies and postinstall script
- Updated dist/index.js with fix applied to bundled dependencies
- All tests continue to pass
2025-08-15 16:05:10 +00:00
Mardav Wala
29996a4979 Merge pull request #717 from actions/alert-autofix-7
Potential fix for code scanning alert no. 7: Workflow does not contain permissions
2025-08-15 14:58:43 +00:00
Mardav Wala
e312ab5a70 Merge pull request #716 from actions/alert-autofix-5
Potential fix for code scanning alert no. 5: Workflow does not contain permissions
2025-08-15 14:58:13 +00:00
Mardav Wala
ab879ebbde Merge pull request #715 from actions/alert-autofix-6
Potential fix for code scanning alert no. 6: Workflow does not contain permissions
2025-08-15 14:57:38 +00:00
Mardav Wala
a963d478cf Remove redundant permissions section from test.yml 2025-08-14 18:52:07 -04:00
Mardav Wala
95a513fa21 Update licensed.yml
Remove unnecessary permissions declaration.
2025-08-14 18:51:32 -04:00
Mardav Wala
82cff4c773 Update .github/workflows/test.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-08-14 18:50:25 -04:00
Mardav Wala
946cbf97ec Update .github/workflows/licensed.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-08-14 18:50:03 -04:00
Mardav Wala
eb7de9c98e Potential fix for code scanning alert no. 7: Workflow does not contain permissions
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-08-14 18:46:55 -04:00
Mardav Wala
26bcf85990 Potential fix for code scanning alert no. 5: Workflow does not contain permissions
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-08-14 18:46:10 -04:00
Mardav Wala
6dea339536 Potential fix for code scanning alert no. 6: Workflow does not contain permissions
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-08-14 18:46:02 -04:00
dependabot[bot]
1351a12afe Bump actions/checkout from 4 to 5
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v5)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-11 18:45:17 +00:00
Kylie Stradley
f42373dde5 Add Actions to CodeQL Language Matrix 2025-07-10 09:19:04 -04:00
Shaun Wong
c0c5949b01 Merge pull request #709 from actions/dependabot/npm_and_yarn/types/node-24.0.12
Bump @types/node from 22.13.14 to 24.0.12
2025-07-10 00:53:37 +00:00
dependabot[bot]
1e8ce485c5 Bump @types/node from 22.13.14 to 24.0.12
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 22.13.14 to 24.0.12.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 24.0.12
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-07-09 13:34:33 +00:00
Mary White
0c37450c4b Merge pull request #703 from actions/dependabot/npm_and_yarn/ts-jest-29.4.0
Bump ts-jest from 29.3.2 to 29.4.0
2025-06-13 15:08:57 +00:00
dependabot[bot]
8147fac042 Bump ts-jest from 29.3.2 to 29.4.0
Bumps [ts-jest](https://github.com/kulshekhar/ts-jest) from 29.3.2 to 29.4.0.
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.3.2...v29.4.0)

---
updated-dependencies:
- dependency-name: ts-jest
  dependency-version: 29.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-06-13 13:22:29 +00:00
Mary White
4a5989832f Merge pull request #699 from actions/dependabot/npm_and_yarn/octokit/plugin-paginate-rest-13.0.1
Bump @octokit/plugin-paginate-rest from 9.2.2 to 13.0.1
2025-06-12 18:25:44 +00:00
dependabot[bot]
dd62e6e66d Update licensed cache and dist/ directory 2025-05-26 14:39:43 +00:00
dependabot[bot]
6042e23fee Bump @octokit/plugin-paginate-rest from 9.2.2 to 13.0.1
Bumps [@octokit/plugin-paginate-rest](https://github.com/octokit/plugin-paginate-rest.js) from 9.2.2 to 13.0.1.
- [Release notes](https://github.com/octokit/plugin-paginate-rest.js/releases)
- [Commits](https://github.com/octokit/plugin-paginate-rest.js/compare/v9.2.2...v13.0.1)

---
updated-dependencies:
- dependency-name: "@octokit/plugin-paginate-rest"
  dependency-version: 13.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-05-26 14:39:09 +00:00
Andri Alexandrou
5b1a254a35 Merge pull request #696 from actions/aja/exclude-source-register
chore: removes sourcemap-register from build step
2025-04-21 18:32:27 +00:00
Andri Alexandrou
dc09970d42 build output 2025-04-21 17:01:05 +00:00
Andri Alexandrou
750dbb8952 chore: removes sourcemap-register from build step 2025-04-18 20:50:03 +00:00
Tara Nelson
7890be62a2 Merge pull request #694 from actions/dependabot/npm_and_yarn/ts-jest-29.3.2
Bump ts-jest from 29.3.0 to 29.3.2
2025-04-17 19:55:35 +00:00