Closed dependabot[bot] closed 8 months ago
Unable to locate .performanceTestingBot config file
Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information
Processing PR updates...
By adding or modifying attributes of an object prototype, it is possible to create attributes that exist on every object, or replace critical attributes with malicious ones. This can be problematic if the software depends on existence or non-existence of certain attributes, or uses pre-defined attributes of object prototype (such as hasOwnProperty, toString or valueOf).
Check out the playback for this Pull Request here.
Thanks @dependabot[bot] for opening this PR!
For COLLABORATOR only :
To add labels, comment on the issue
/label add label1,label2,label3
To remove labels, comment on the issue
/label remove label1,label2,label3
[!IMPORTANT]
Auto Review Skipped
Bot user detected.
To trigger a single review, invoke the
@coderabbitai review
command.
Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?
First PR by @dependabot[bot]
PR Details of @dependabot[bot] in ahmnouira-pillar-landing : | OPEN | CLOSED | TOTAL |
---|---|---|---|
1 | 0 | 1 |
:warning: We detected 2 security issues in this pull request:
👉 Go to the dashboard for detailed results.
📥 Happy? Share your feedback with us.
Use of vulnerable components will introduce weaknesses into the application. Components with published vulnerabilities will allow easy exploitation as resources will often be available to automate the process.
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
Package | New capabilities | Transitives | Size | Publisher |
---|---|---|---|---|
npm/@next/swc-darwin-arm64@13.5.0 | None | 0 |
108 MB | vercel-release-bot |
npm/@next/swc-darwin-x64@13.5.0 | None | 0 |
104 MB | vercel-release-bot |
npm/@next/swc-linux-arm64-gnu@13.5.0 | None | 0 |
110 MB | vercel-release-bot |
npm/@next/swc-linux-arm64-musl@13.5.0 | None | 0 |
130 MB | vercel-release-bot |
npm/@next/swc-linux-x64-gnu@13.5.0 | None | 0 |
124 MB | vercel-release-bot |
npm/@next/swc-linux-x64-musl@13.5.0 | None | 0 |
144 MB | vercel-release-bot |
npm/@next/swc-win32-arm64-msvc@13.5.0 | None | 0 |
97.9 MB | vercel-release-bot |
npm/@next/swc-win32-ia32-msvc@13.5.0 | None | 0 |
92.4 MB | vercel-release-bot |
npm/@next/swc-win32-x64-msvc@13.5.0 | None | 0 |
123 MB | vercel-release-bot |
npm/source-map-js@1.2.0 | None | 0 |
140 kB | 7rulnik |
🚮 Removed packages: npm/next@12.1.0, npm/source-map-js@1.0.2
Bumps the npm_and_yarn group with 5 updates in the / directory:
12.1.0
13.5.0
1.0.1
1.0.2
1.2.5
1.2.8
6.3.0
6.3.1
1.2.3
1.2.5
Updates
next
from 12.1.0 to 13.5.0Commits
ffafad2
v13.5.04a589ed
v13.4.20-canary.41deb81cf
fix styled-jsx alias (#55581)1a9b0f6
improve internal error logging (#55582)0631549
Fix react packages are not bundled for metadata routes (#55579)bad5365
Update supported config options for Turbopack (#55556)8881c41
Fix useState function initialiser case foroptimize_server_react
transform ...1025011
Add react-icons to optimizePackageImports (#55572)d5c35a1
chore: replace issue triaing actions withnissuer
(#55525)33c561b
Consolidate experimental React opt-in & addppr
flag (#55560)Updates
json5
from 1.0.1 to 1.0.2Release notes
Sourced from json5's releases.
Changelog
Sourced from json5's changelog.
... (truncated)
Commits
a62db1e
1.0.2e0c23fe
docs: update CHANGELOG for v1.0.262a6540
fix: add proto to objects and arraysUpdates
minimist
from 1.2.5 to 1.2.8Changelog
Sourced from minimist's changelog.
... (truncated)
Commits
6901ee2
v1.2.8a026794
Merge tag 'v0.2.3'c0b2661
v0.2.363b8fee
[Fix] Fix long option followed by single dash (#17)72239e6
[Tests] Remove duplicate test (#12)34b0f1c
[eslint] fix indentation3226afa
[Dev Deps] add missingnpmignore
dev dep098873c
[Dev Deps] update@ljharb/eslint-config
,aud
9ec4d27
[Fix] Fix long option followed by single dashba92fe6
[actions] Avoid 0.6 tests due to build failuresMaintainer changes
This version was pushed to npm by ljharb, a new releaser for minimist since your current version.
Updates
postcss
from 8.4.5 to 8.4.14Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
b7d1836
Release 8.4.14 version57006b4
Update dependencies2a97ab8
Merge pull request #1744 from zardoy/patch-16447b55
Merge pull request #1747 from ben-lau/maine36ed17
Update plugins.md24f2efc
Update depedencies9bda624
Try to fix CI7cd8e27
improve warnings count testing2295e28
fix testsfc19f1b
fix: print deprecation warning only when plugin is usedUpdates
semver
from 6.3.0 to 6.3.1Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
... (truncated)
Commits
44d27bc
chore: release 6.3.1928e56d
fix: better handling of whitespace (#591)39f6326
chore:@npmcli/template-oss
@4
.16.0Maintainer changes
This version was pushed to npm by lukekarrys, a new releaser for semver since your current version.
Updates
word-wrap
from 1.2.3 to 1.2.5Release notes
Sourced from word-wrap's releases.
Commits
207044e
1.2.59894315
revert default indentf64b188
run verb to generate README03ea082
Merge pull request #42 from jonschlinkert/chore/publish-workflow420dce9
Merge pull request #41 from jonschlinkert/fix/CVE-2023-26115-2bfa694e
Update .github/workflows/publish.ymlace0b3c
chore: bump version to 1.2.46fd7275
chore: add publish workflow30d6daf
chore: fix test655929c
chore: remove package-lockDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show