Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update all non-major dependencies #325

Merged
merged 1 commit into from
Nov 3, 2023

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 6, 2023

Mend Renovate

This PR contains the following updates:

Package Type Update Change
actions/checkout action digest 8ade135 -> b4ffde6
github.com/microcosm-cc/bluemonday require patch v1.0.25 -> v1.0.26
github/codeql-action action digest ddccb87 -> 74483a3
reviewdog/action-golangci-lint action digest 24d4af2 -> 94d61e3

Release Notes

microcosm-cc/bluemonday (github.com/microcosm-cc/bluemonday)

v1.0.26: Update golang.org/x/net to latest and force latest version

Compare Source

Bumping version and ensuring latest golang.org/x/net as the HTTP rapid reset is triggering primitive vuln scanners, we do not implement a HTTP2 server and are not vulnerable but a minor bump can still help reduce noise for those searching for what they need to upgrade and patch.

Nothing else is in this release aside from the dependency updates and some staticcheck messages being resolved that should not modify behaviour.


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot requested a review from a team as a code owner October 6, 2023 12:24
@renovate renovate bot added the dependencies Indicates a change to dependencies label Oct 6, 2023
@codecov
Copy link

codecov bot commented Oct 6, 2023

Codecov Report

Merging #325 (def88dc) into main (19101a5) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##             main     #325   +/-   ##
=======================================
  Coverage   96.35%   96.35%           
=======================================
  Files          62       62           
  Lines        6858     6858           
=======================================
  Hits         6608     6608           
  Misses        181      181           
  Partials       69       69           

@renovate renovate bot changed the title chore(deps): update github/codeql-action digest to 2cb752a chore(deps): update github/codeql-action digest to fdcae64 Oct 9, 2023
@renovate renovate bot force-pushed the renovate/all-minor-patch-digest-pin branch 2 times, most recently from 8022cf0 to 29b0154 Compare October 9, 2023 19:35
@renovate renovate bot changed the title chore(deps): update github/codeql-action digest to fdcae64 fix(deps): update all non-major dependencies Oct 12, 2023
@renovate renovate bot force-pushed the renovate/all-minor-patch-digest-pin branch 5 times, most recently from 0aad4e9 to 381cacc Compare October 18, 2023 07:08
@renovate renovate bot changed the title fix(deps): update all non-major dependencies chore(deps): update all non-major dependencies Oct 19, 2023
@renovate renovate bot force-pushed the renovate/all-minor-patch-digest-pin branch 3 times, most recently from de21788 to 87b6450 Compare October 24, 2023 20:11
@renovate renovate bot force-pushed the renovate/all-minor-patch-digest-pin branch from 87b6450 to def88dc Compare October 27, 2023 11:10
@plyr4 plyr4 merged commit ffb16ee into main Nov 3, 2023
10 checks passed
@plyr4 plyr4 deleted the renovate/all-minor-patch-digest-pin branch November 3, 2023 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Indicates a change to dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants