Closed dependabot[bot] closed 2 months ago
Unable to locate .performanceTestingBot config file
Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information
Processing PR updates...
Thanks @dependabot[bot] for opening this PR!
For COLLABORATOR only :
To add labels, comment on the issue
/label add label1,label2,label3
To remove labels, comment on the issue
/label remove label1,label2,label3
My review is in progress :book: - I will have feedback for you in a few minutes!
[!WARNING]
Rate limit exceeded
@labels-and-badges[bot] has exceeded the limit for the number of commits or files that can be reviewed per hour. Please wait 15 minutes and 35 seconds before requesting another review.
How to resolve this issue?
After the wait time has elapsed, a review can be triggered using the `@coderabbitai review` command as a PR comment. Alternatively, push new commits to this PR. We recommend that you space out your commits to avoid hitting the rate limit.How do rate limits work?
CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our [FAQ](https://coderabbit.ai/docs/faq) for further information.Commits
Files that changed from the base of the PR and between aab10b84421943a86db40628b61e23b2d5609c39 and 2550fddbc4f125d9af4c2e91261c601c17d227cf.
Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?
PR Details of @dependabot[bot] in CycloneDX-cyclonedx-webpack-plugin : | OPEN | CLOSED | TOTAL |
---|---|---|---|
1 | 22 | 23 |
Description has been updated!
:warning: We detected 4 security issues in this pull request:
👉 Go to the dashboard for detailed results.
📥 Happy? Share your feedback with us.
Use of vulnerable components will introduce weaknesses into the application. Components with published vulnerabilities will allow easy exploitation as resources will often be available to automate the process.
Description
In this pull request, the versions of PostCSS and its dependencies are being updated in the
package.json
andpackage-lock.json
files for better compatibility and security.^8.4.38
to^8.4.39
inpackage.json
.8.4.38
to8.4.39
in the dependency section ofpackage-lock.json
.picocolors
dependency from^1.0.0
to^1.0.1
in thepackage-lock.json
file.picocolors
dependency from^1.0.0
to^1.0.1
in the dependency section ofpackage-lock.json
.^8.4.38
to^8.4.39
in thepackage-lock.json
file.