Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update actions/checkout action to v4 #45

Open
wants to merge 57 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
57 commits
Select commit Hold shift + click to select a range
c517b33
Bump lodash from 4.17.15 to 4.17.19
dependabot[bot] Jul 20, 2020
36a3553
Bump ini from 1.3.5 to 1.3.8
dependabot[bot] Dec 12, 2020
ca69f7f
fix: package.json, yarn.lock & .snyk to reduce vulnerabilities
snyk-bot Apr 3, 2021
873ec6a
Merge pull request #3 from laugustofrontend/snyk-fix-f92076309b104948…
lucasaugustodeveloper Apr 3, 2021
428f744
Merge pull request #2 from laugustofrontend/dependabot/npm_and_yarn/i…
lucasaugustodeveloper Apr 3, 2021
a7105eb
Merge pull request #1 from laugustofrontend/dependabot/npm_and_yarn/l…
lucasaugustodeveloper Apr 3, 2021
fe61bbf
Create codeql-analysis.yml
lucasaugustodeveloper Apr 3, 2021
797c495
fix: upgrade @adonisjs/bodyparser from 2.0.9 to 2.2.5
snyk-bot Apr 3, 2021
ae622b3
fix: upgrade @adonisjs/fold from 4.0.9 to 4.1.0
snyk-bot Apr 17, 2021
a596981
fix: upgrade @adonisjs/session from 1.0.29 to 1.1.0
snyk-bot Apr 17, 2021
9037a05
fix: upgrade @adonisjs/shield from 1.0.8 to 1.1.0
snyk-bot Apr 17, 2021
7bafe6c
fix: upgrade @adonisjs/auth from 3.1.0 to 3.2.0
snyk-bot Apr 18, 2021
deef067
fix: package.json & yarn.lock to reduce vulnerabilities
snyk-bot Jul 28, 2021
17c5979
fix: package.json & yarn.lock to reduce vulnerabilities
snyk-bot Sep 12, 2021
92353ef
fix: package.json & yarn.lock to reduce vulnerabilities
snyk-bot Sep 22, 2021
8032ae6
fix: package.json & yarn.lock to reduce vulnerabilities
snyk-bot Dec 21, 2021
1118b29
Merge pull request #18 from laugustofrontend/snyk-fix-80e8fc1027c9dcb…
lucasaugustodeveloper Dec 26, 2021
848129c
Bump dot-prop from 4.2.0 to 4.2.1
dependabot[bot] Dec 26, 2021
6cb9fc9
Bump lodash from 4.17.19 to 4.17.21
dependabot[bot] Dec 26, 2021
34de821
Merge branch 'master' into snyk-fix-f2df3cd3828c00911180dd9de58553ed
lucasaugustodeveloper Dec 26, 2021
2e789e9
Bump color-string from 1.5.3 to 1.9.0
dependabot[bot] Dec 26, 2021
868857f
Merge pull request #17 from laugustofrontend/snyk-fix-f2df3cd3828c009…
lucasaugustodeveloper Dec 26, 2021
7d06a1c
Merge pull request #21 from laugustofrontend/dependabot/npm_and_yarn/…
lucasaugustodeveloper Dec 26, 2021
692f3ad
Merge pull request #20 from laugustofrontend/dependabot/npm_and_yarn/…
lucasaugustodeveloper Dec 26, 2021
0468569
Merge pull request #19 from laugustofrontend/dependabot/npm_and_yarn/…
lucasaugustodeveloper Dec 26, 2021
abff90e
Bump path-parse from 1.0.6 to 1.0.7
dependabot[bot] Dec 26, 2021
7f8291a
Bump set-getter from 0.1.0 to 0.1.1
dependabot[bot] Dec 26, 2021
eca90c2
Merge branch 'master' into snyk-upgrade-eb9839ff3a4117bbe68cb4832a2607f4
lucasaugustodeveloper Dec 26, 2021
e2941f8
Merge pull request #4 from laugustofrontend/snyk-upgrade-eb9839ff3a41…
lucasaugustodeveloper Dec 26, 2021
07ced51
Merge branch 'master' into snyk-fix-4775216ca78f35f5fa6eb1d90e9c892d
lucasaugustodeveloper Dec 26, 2021
92a192f
Merge pull request #16 from laugustofrontend/snyk-fix-4775216ca78f35f…
lucasaugustodeveloper Dec 26, 2021
dcf3428
Merge pull request #14 from laugustofrontend/dependabot/npm_and_yarn/…
lucasaugustodeveloper Dec 26, 2021
825a9c1
Merge pull request #11 from laugustofrontend/dependabot/npm_and_yarn/…
lucasaugustodeveloper Dec 26, 2021
9824004
Merge branch 'master' into snyk-upgrade-285bac180375a428d72761ab06a8e2f7
lucasaugustodeveloper Dec 26, 2021
238dcb4
Merge pull request #9 from laugustofrontend/snyk-upgrade-285bac180375…
lucasaugustodeveloper Dec 26, 2021
10a1fb7
Add renovate.json
renovate-bot Dec 26, 2021
b2af9a9
Merge pull request #5 from laugustofrontend/renovate/configure
lucasaugustodeveloper Dec 26, 2021
9a52375
Merge branch 'master' into snyk-upgrade-c342a4da01a9b6ae301005755de163f0
lucasaugustodeveloper Dec 26, 2021
14e5306
Update dependency @adonisjs/cli to v4.0.13
renovate-bot Dec 26, 2021
a1e91fc
Merge pull request #23 from laugustofrontend/renovate/adonisjs-cli-4.x
lucasaugustodeveloper Dec 26, 2021
08a6d91
Merge branch 'master' into snyk-upgrade-c342a4da01a9b6ae301005755de163f0
lucasaugustodeveloper Dec 26, 2021
2cedab6
Merge pull request #6 from laugustofrontend/snyk-upgrade-c342a4da01a9…
lucasaugustodeveloper Dec 26, 2021
60e2765
Merge branch 'master' into snyk-upgrade-844c74e2c57c6f0ba3062d37634b1a7c
lucasaugustodeveloper Dec 26, 2021
12a45c7
Merge pull request #7 from laugustofrontend/snyk-upgrade-844c74e2c57c…
lucasaugustodeveloper Dec 26, 2021
d3da968
Merge branch 'master' into snyk-upgrade-95c7d7e39e64ebadc78457efb5088764
lucasaugustodeveloper Dec 26, 2021
cb912bc
Merge pull request #8 from laugustofrontend/snyk-upgrade-95c7d7e39e64…
lucasaugustodeveloper Dec 26, 2021
8e95fe6
build(deps): bump lodash from 4.17.19 to 4.17.21
dependabot[bot] Dec 26, 2021
f0445e4
Merge branch 'master' into snyk-fix-ccf043e62e48f0b85d11c666ceb683ca
lucasaugustodeveloper Dec 26, 2021
58ff00f
Merge pull request #12 from laugustofrontend/snyk-fix-ccf043e62e48f0b…
lucasaugustodeveloper Dec 26, 2021
1aa2dc0
Merge pull request #25 from laugustofrontend/dependabot/npm_and_yarn/…
lucasaugustodeveloper Dec 26, 2021
a16cfd1
Pin dependencies
renovate-bot Dec 26, 2021
ef4e60b
Update Node.js to v17
renovate-bot Dec 26, 2021
bcc3cc6
Merge pull request #22 from laugustofrontend/renovate/pin-dependencies
lucasaugustodeveloper Dec 26, 2021
fd9b8bc
Update dependency @adonisjs/ace to v11
renovate-bot Dec 26, 2021
330d000
Merge pull request #26 from laugustofrontend/renovate/node-17.x
lucasaugustodeveloper Dec 26, 2021
c0ff5e0
Merge pull request #27 from laugustofrontend/renovate/adonisjs-ace-11.x
lucasaugustodeveloper Dec 26, 2021
da08807
chore(deps): update actions/checkout action to v4
renovate[bot] Oct 19, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
67 changes: 67 additions & 0 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL"

on:
push:
branches: [ master ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ master ]
schedule:
- cron: '32 16 * * 0'

jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest

strategy:
fail-fast: false
matrix:
language: [ 'javascript' ]
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python' ]
# Learn more:
# https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#changing-the-languages-that-are-analyzed

steps:
- name: Checkout repository
uses: actions/checkout@v4

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v1
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.
# queries: ./path/to/local/query, your-org/your-repo/queries@main

# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v1

# ℹ️ Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl

# ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
# and modify them (or add more) to build your code if your project
# uses a compiled language

#- run: |
# make bootstrap
# make release

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v1
28 changes: 28 additions & 0 deletions .snyk
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
version: v1.19.0
ignore: {}
# patches apply the minimum changes required to fix a vulnerability
patch:
SNYK-JS-LODASH-567746:
- '@adonisjs/ace > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/auth > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/bodyparser > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/fold > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/framework > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/lucid > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/session > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/framework > @adonisjs/middleware-base > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/framework > edge.js > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/lucid > knex > lodash':
patched: '2021-04-03T01:45:38.124Z'
- '@adonisjs/framework > winston > async > lodash':
patched: '2021-04-03T01:45:38.124Z'
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM node:12
FROM node:17

WORKDIR /app

Expand Down
32 changes: 18 additions & 14 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,9 @@
"migrate:status": "adonis migration:status",
"seed": "adonis seed",
"start": "node server.js",
"test": "node ace test"
"test": "node ace test",
"snyk-protect": "snyk protect",
"prepare": "yarn run snyk-protect"
},
"keywords": [
"adonisjs",
Expand All @@ -20,22 +22,24 @@
"license": "UNLICENSED",
"private": true,
"dependencies": {
"@adonisjs/ace": "^5.0.8",
"@adonisjs/auth": "^3.0.7",
"@adonisjs/bodyparser": "^2.0.5",
"@adonisjs/cors": "^1.0.7",
"@adonisjs/fold": "^4.0.9",
"@adonisjs/framework": "^5.0.9",
"@adonisjs/ignitor": "^2.0.8",
"@adonisjs/lucid": "^6.1.3",
"@adonisjs/session": "^1.0.27",
"@adonisjs/shield": "^1.0.8",
"mysql": "^2.16.0"
"@adonisjs/ace": "11.0.5",
"@adonisjs/auth": "3.2.0",
"@adonisjs/bodyparser": "2.3.0",
"@adonisjs/cors": "1.0.7",
"@adonisjs/fold": "4.1.0",
"@adonisjs/framework": "5.0.13",
"@adonisjs/ignitor": "2.0.8",
"@adonisjs/lucid": "6.3.0",
"@adonisjs/session": "1.1.0",
"@adonisjs/shield": "1.1.0",
"mysql": "2.18.1",
"snyk": "1.809.0"
},
"devDependencies": {
"@adonisjs/cli": "^4.0.12"
"@adonisjs/cli": "4.0.13"
},
"autoload": {
"App": "./app"
}
},
"snyk": true
}
5 changes: 5 additions & 0 deletions renovate.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
{
"extends": [
"config:base"
]
}
Loading