Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security #1 #250

Open
wants to merge 60 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
60 commits
Select commit Hold shift + click to select a range
a650cd5
Bump minimist, minimist and modernizr
dependabot[bot] Sep 14, 2022
5e5163f
Bump websocket-extensions from 0.1.2 to 0.1.4
dependabot[bot] Sep 14, 2022
49638e5
Bump lodash.merge from 4.6.0 to 4.6.2
dependabot[bot] Sep 14, 2022
e1fb501
minimist 1.2.6
ValentinGratz Sep 14, 2022
7a1585e
Merge pull request #1 from ValentinGratz/dependabot/npm_and_yarn/mini…
ValentinGratz Sep 14, 2022
0ef7bd5
Merge pull request #3 from ValentinGratz/dependabot/npm_and_yarn/loda…
ValentinGratz Sep 14, 2022
031d16e
Merge pull request #2 from ValentinGratz/dependabot/npm_and_yarn/webs…
ValentinGratz Sep 14, 2022
dd3c4a5
Bump got and npm
dependabot[bot] Sep 14, 2022
3a574df
Bump postcss and gulp-autoprefixer
dependabot[bot] Sep 14, 2022
7e51664
Bump shelljs and jshint
dependabot[bot] Sep 14, 2022
5b896b6
Merge pull request #4 from ValentinGratz/dependabot/npm_and_yarn/got-…
ValentinGratz Sep 14, 2022
35cbf70
Merge pull request #5 from ValentinGratz/dependabot/npm_and_yarn/post…
ValentinGratz Sep 14, 2022
60b204f
Merge pull request #6 from ValentinGratz/dependabot/npm_and_yarn/shel…
ValentinGratz Sep 14, 2022
4121f44
Bump concat-with-sourcemaps from 1.0.4 to 1.1.0
dependabot[bot] Sep 14, 2022
ecaafd6
Bump lodash, lodash and gulp
dependabot[bot] Sep 14, 2022
473015c
Bump json-schema from 0.2.3 to 0.4.0
dependabot[bot] Sep 14, 2022
e2c1d02
Create codeql-analysis.yml
ValentinGratz Sep 14, 2022
014005a
Merge pull request #10 from ValentinGratz/dependabot/npm_and_yarn/jso…
ValentinGratz Sep 14, 2022
e184631
Merge pull request #9 from ValentinGratz/dependabot/npm_and_yarn/loda…
ValentinGratz Sep 14, 2022
2d58fe8
Merge pull request #8 from ValentinGratz/dependabot/npm_and_yarn/conc…
ValentinGratz Sep 14, 2022
907f018
Create SECURITY.md
ValentinGratz Sep 14, 2022
19d581d
Update package-lock.json
ValentinGratz Sep 14, 2022
19eed97
Update package-lock.json
ValentinGratz Oct 1, 2022
fbe509c
Update package-lock.json
ValentinGratz Oct 1, 2022
d5dbc5e
Update package-lock.json
ValentinGratz Oct 25, 2022
899c26a
Bump minimatch from 0.2.14 to 3.0.4
dependabot[bot] Oct 25, 2022
3b85a93
Merge pull request #13 from ValentinGratz/dependabot/npm_and_yarn/min…
ValentinGratz Nov 13, 2022
651b879
Bump hawk and node-sass
dependabot[bot] Nov 13, 2022
b53aeec
Merge pull request #12 from ValentinGratz/dependabot/npm_and_yarn/haw…
ValentinGratz Nov 13, 2022
79c6311
Bump lodash.merge from 4.6.0 to 4.6.2
dependabot[bot] Nov 13, 2022
060f671
Add files via upload
ValentinGratz Nov 13, 2022
fd74b17
Merge pull request #14 from ValentinGratz/dependabot/npm_and_yarn/lod…
ValentinGratz Nov 13, 2022
6f9bdc0
Update package-lock.json
ValentinGratz Nov 13, 2022
6e1abee
Update package-lock.json
ValentinGratz Nov 13, 2022
30878be
Update package-lock.json
ValentinGratz Nov 13, 2022
9bf4377
Update package-lock.json
ValentinGratz Nov 14, 2022
2dd8967
scss 0.4.3
ValentinGratz Nov 14, 2022
e5ddf5a
Update package-lock.json
ValentinGratz Nov 14, 2022
6b91d8f
Update package-lock.json
ValentinGratz Nov 15, 2022
4543139
Update package-lock.json
ValentinGratz Nov 15, 2022
724fa88
hawk 9.0.1
ValentinGratz Nov 23, 2022
c25b8b0
Update package-lock.json
ValentinGratz Nov 23, 2022
0e487c5
Create dependabot.yml
ValentinGratz Nov 23, 2022
b47e6d2
update npm
ValentinGratz Nov 25, 2022
77ee39c
Bump hosted-git-info from 2.5.0 to 2.8.9
dependabot[bot] Nov 25, 2022
4021914
Merge pull request #17 from ValentinGratz/dependabot/npm_and_yarn/hos…
ValentinGratz Nov 25, 2022
49584d6
Bump extend from 3.0.1 to 3.0.2
dependabot[bot] Nov 25, 2022
5f0eee9
Bump y18n from 3.2.1 to 3.2.2
dependabot[bot] Nov 25, 2022
f84e870
Bump decode-uri-component from 0.2.0 to 0.2.2
dependabot[bot] Dec 9, 2022
74625b5
Merge pull request #18 from ValentinGratz/dependabot/npm_and_yarn/dec…
ValentinGratz Dec 11, 2022
4d49698
Merge pull request #16 from ValentinGratz/dependabot/npm_and_yarn/ext…
ValentinGratz Dec 11, 2022
c45781e
Merge pull request #15 from ValentinGratz/dependabot/npm_and_yarn/y18…
ValentinGratz Dec 11, 2022
4a2119e
Bump minimatch from 3.0.4 to 3.0.8
dependabot[bot] Dec 11, 2022
8ddeee9
Merge pull request #19 from ValentinGratz/dependabot/npm_and_yarn/min…
ValentinGratz Dec 11, 2022
e4c48ce
Bump concat-with-sourcemaps from 1.0.4 to 1.1.0
dependabot[bot] Dec 11, 2022
6bf6b8f
Merge pull request #20 from ValentinGratz/dependabot/npm_and_yarn/con…
ValentinGratz Dec 11, 2022
2e61b0d
Bump semver and npm
dependabot[bot] Jul 14, 2023
a403bd1
Merge pull request #21 from ValentinGratz/dependabot/npm_and_yarn/sem…
ValentinGratz Aug 1, 2023
e77f4ec
Bump tar and npm
dependabot[bot] Apr 11, 2024
ea20928
Merge pull request #22 from ValentinGratz/dependabot/npm_and_yarn/mul…
ValentinGratz May 4, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
13 changes: 13 additions & 0 deletions .github/dependabot.yml
@@ -0,0 +1,13 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates

version: 2
updates:
- package-ecosystem: "" # See documentation for possible values
directory: "/" # Location of package manifests
schedule:
interval: "weekly"


72 changes: 72 additions & 0 deletions .github/workflows/codeql-analysis.yml
@@ -0,0 +1,72 @@
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL"

on:
push:
branches: [ "master" ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ "master" ]
schedule:
- cron: '33 11 * * 6'

jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [ 'javascript' ]
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ]
# Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support

steps:
- name: Checkout repository
uses: actions/checkout@v3

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v2
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.

# Details on CodeQL's query packs refer to : https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
# queries: security-extended,security-and-quality


# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v2

# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun

# If the Autobuild fails above, remove it and uncomment the following three lines.
# modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.

# - run: |
# echo "Run, Build Application using script"
# ./location_of_script_within_repo/buildscript.sh

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
21 changes: 21 additions & 0 deletions SECURITY.md
@@ -0,0 +1,21 @@
# Security Policy

## Supported Versions

Use this section to tell people about which versions of your project are
currently being supported with security updates.

| Version | Supported |
| ------- | ------------------ |
| 5.1.x | :white_check_mark: |
| 5.0.x | :x: |
| 4.0.x | :white_check_mark: |
| < 4.0 | :x: |

## Reporting a Vulnerability

Use this section to tell people how to report a vulnerability.

Tell them where to go, how often they can expect to get an update on a
reported vulnerability, what to expect if the vulnerability is accepted or
declined, etc.