Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency Dashboard #1148

Open
25 tasks
renovate bot opened this issue Jan 26, 2022 · 2 comments
Open
25 tasks

Dependency Dashboard #1148

renovate bot opened this issue Jan 26, 2022 · 2 comments

Comments

@renovate
Copy link

renovate bot commented Jan 26, 2022

This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.

Rate-Limited

These updates are currently rate-limited. Click on a checkbox below to force their creation now.

  • fix(deps): update dependency websocket to v1.0.35
  • chore(deps): update dependency snyk to v1.1291.0
  • chore(deps): update dependency eslint to v9
  • chore(deps): update dependency installed-check to v9
  • chore(deps): update dependency jsdoc to v4
  • chore(deps): update dependency lint-staged to v15
  • chore(deps): update dependency prettier to v3
  • chore(deps): update dependency typescript to v5
  • chore(deps): update node.js to v20 (node, @types/node)
  • chore(deps): update semantic-release monorepo (major) (@semantic-release/changelog, @semantic-release/git)
  • chore(deps): update voxmedia/github-action-slack-notify-build action to v2
  • fix(deps): update dependency camelcase to v8
  • 🔐 Create all rate-limited PRs at once 🔐

Open

These updates have all been created already. Click a checkbox below to force a retry/rebase of any.

Detected dependencies

dockerfile
docker/Dockerfile
  • node 12-slim
github-actions
.github/workflows/build-test.yml
  • actions/checkout v2
  • actions/setup-node v2
.github/workflows/deploy.yml
  • actions/checkout v2
  • actions/setup-node v2
.github/workflows/integration-test.yml
  • actions/checkout v2
  • actions/setup-node v2
  • voxmedia/github-action-slack-notify-build v1
  • voxmedia/github-action-slack-notify-build v1
npm
package.json
  • @types/async ^3.2.5
  • @types/extend ^3.0.1
  • @types/isstream ^0.1.0
  • @types/node ^13.13.39
  • @types/websocket ^1.0.1
  • async ^3.2.0
  • camelcase ^6.2.0
  • extend ~3.0.2
  • ibm-cloud-sdk-core ^4.2.3
  • isstream ~0.1.2
  • websocket ^1.0.33
  • @semantic-release/changelog ^5.0.1
  • @semantic-release/git ^9.0.0
  • axios ^0.21.4
  • codecov ^3.8.1
  • concat-stream ^2.0.0
  • cz-conventional-changelog ^3.3.0
  • eslint ^6.8.0
  • eslint-config-google ^0.14.0
  • eslint-config-prettier ^6.15.0
  • eslint-plugin-node ^11.1.0
  • eslint-plugin-prettier ^3.3.1
  • installed-check ^3.0.0
  • jest ^28.1.3
  • jsdoc ^3.6.6
  • lint-staged ^10.5.3
  • prettier ^2.2.1
  • semantic-release ^17.3.1
  • snyk ^1.437.3
  • tsc-publish ^0.5.1
  • tslint ^6.1.3
  • tslint-config-prettier ^1.18.0
  • typedoc ^0.17.8
  • typescript ^4.9.4
  • wav ~1.0.2
  • node >=16.0.0
travis
.travis.yml
  • node 10
  • node 12

  • Check this box to trigger a request for Renovate to run again on this repository
@EgleHelms
Copy link

High vulnerabilities in:
Vulnerability in axios@1.4.0:
https://www.cve.org/CVERecord?id=CVE-2023-45857
Should be updated to axios@1.6.0

Vulnerability in semver@6.3.0: https://www.cve.org/CVERecord?id=CVE-2022-25883
Should be fixed in semver@5.7.2, @6.3.1, @7.5.2

Please update this package.

@apaparazzi0329
Copy link
Contributor

axios version has been updated in the dependent package ibm-cloud-sdk-core. semver@6.3.0 is only used in the dev dependency commitlint and poses no security risks. We will likely remove commitlint anyways as it is no longer used for development purposes.

@renovate renovate bot reopened this Feb 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants