SocialGouv / dashlord-actions

GitHub actions for DashLord
Apache License 2.0
2 stars 13 forks source link

fix(header): fix exception with neutral theme #302

Closed revolunet closed 6 months ago

revolunet commented 6 months ago

correction d'une regression sur le theme "neutre"

fix https://github.com/SocialGouv/dashlord/issues/91

socket-security[bot] commented 6 months ago

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@codegouvfr/react-dsfr@1.7.2 Transitive: environment, filesystem +2 75.1 MB codegouv-owner, emilerolley, garronej, ...1 more
npm/internal-slot@1.0.6 Transitive: eval +13 338 kB ljharb
npm/internmap@1.0.1 None 0 10.3 kB mbostock
npm/is-core-module@2.13.1 None +2 72.5 kB ljharb
npm/is-map@2.0.2 None 0 12.7 kB ljharb
npm/is-set@2.0.2 None 0 12.3 kB ljharb
npm/is-typed-array@1.1.12 Transitive: eval +16 326 kB ljharb
npm/jsx-ast-utils@3.3.5 Transitive: eval +63 3.53 MB ljharb
npm/lodash.orderby@4.6.0 None 0 71.5 kB jdalton
npm/lodash.uniq@4.5.0 None 0 25 kB jdalton
npm/lodash.uniqby@4.7.0 None 0 67.9 kB jdalton
npm/loose-envify@1.4.0 environment +1 20.9 kB zertosh
npm/loupe@2.3.7 None +1 66.8 kB keithamus
npm/merge2@1.4.1 None 0 8.9 kB zensh
npm/mlly@1.5.0 None +5 1.04 MB pi0
npm/nanoid@3.3.7 None 0 24.4 kB ai
npm/next-router-mock@0.9.11 environment Transitive: filesystem, network, shell, unsafe +44 1.12 GB scott-rippey
npm/next@14.1.0 environment, filesystem, network, shell, unsafe +43 1.12 GB vercel-release-bot
npm/object-assign@4.1.1 None 0 5.49 kB sindresorhus
npm/object-inspect@1.13.1 None 0 97.2 kB ljharb
npm/object.assign@4.1.5 Transitive: eval +13 318 kB ljharb
npm/object.entries@1.1.7 Transitive: eval +58 3.24 MB ljharb
npm/object.fromentries@2.0.7 Transitive: eval +58 3.22 MB ljharb
npm/object.values@1.1.7 Transitive: eval +58 3.24 MB ljharb
npm/pathe@1.1.2 None 0 30.8 kB pi0
npm/postcss@8.4.31 environment, filesystem +3 374 kB ai
npm/prop-types@15.8.1 environment +4 145 kB ljharb
npm/rc-tooltip@5.1.1 Transitive: environment +15 7.41 MB zombiej
npm/rc-util@5.21.5 Transitive: environment +7 5.27 MB zombiej
npm/react-d3-speedometer@1.1.0 Transitive: environment, eval, filesystem, network, shell +48 8.11 MB palerdot
npm/react-dom@18.2.0 environment +3 4.84 MB gnoff
npm/react-feather@2.0.9 Transitive: environment +6 1.44 MB carmelo
npm/react-markdown@9.0.1 Transitive: environment +88 4.43 MB wooorm
npm/react-test-renderer@18.2.0 environment +7 2.08 MB gnoff
npm/react-vertical-timeline-component@3.6.0 environment, filesystem, shell +8 716 kB stephane-monnot
npm/react@18.2.0 environment +2 337 kB gnoff
npm/readable-stream@1.0.34 environment +4 79.5 kB cwmma
npm/recharts@2.11.0 environment +44 14.6 MB ckifer
npm/regexp.prototype.flags@1.5.1 Transitive: eval +15 312 kB ljharb
npm/resolve@1.22.8 environment, filesystem +5 232 kB ljharb
npm/safe-buffer@5.1.2 None 0 31.7 kB feross
npm/sass@1.70.0 filesystem Transitive: environment +17 6.54 MB sassbot
npm/set-function-name@2.0.1 Transitive: eval +9 183 kB ljharb
npm/signal-exit@4.1.0 None 0 77 kB isaacs
npm/source-map-js@1.0.2 None 0 148 kB 7rulnik
npm/string-width@5.1.2 None +4 127 kB sindresorhus
npm/string.prototype.trimend@1.0.7 Transitive: eval +57 3.21 MB ljharb
npm/string.prototype.trimstart@1.0.7 Transitive: eval +57 3.21 MB ljharb
npm/tss-react@4.9.3 environment Transitive: filesystem, unsafe +105 33.2 MB garronej
npm/typescript@5.3.3 None 0 32 MB typescript-bot
npm/vite-tsconfig-paths@4.3.1 filesystem Transitive: environment, network, shell +67 305 MB aleclarson
npm/vite@5.1.4 Transitive: environment, filesystem, network, shell +61 273 MB antfu, patak, soda, ...2 more
npm/vitest@1.2.2 environment, eval Transitive: filesystem, network, shell, unsafe +138 280 MB oreanno
npm/which-typed-array@1.1.13 Transitive: eval +15 308 kB ljharb

🚮 Removed packages: npm/@codegouvfr/react-dsfr@1.2.2, npm/define-properties@1.2.0, npm/es-abstract@1.21.2, npm/eslint-utils@2.1.0, npm/eslint@8.37.0, npm/expect@29.5.0, npm/get-intrinsic@1.2.0, npm/is-core-module@2.11.0, npm/is-typed-array@1.1.10, npm/istanbul-lib-coverage@3.2.0, npm/istanbul-lib-instrument@5.2.1, npm/jest@29.5.0, npm/object-inspect@1.12.3, npm/prettier@2.8.7, npm/pretty-format@29.5.0, npm/resolve@1.22.1, npm/semver@7.6.0, npm/signal-exit@3.0.7, npm/source-map@0.6.1, npm/typescript@5.0.3

View full report↗︎

socket-security[bot] commented 6 months ago

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: npm/next@14.1.0, npm/react-vertical-timeline-component@3.6.0

View full report↗︎

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

sonarcloud[bot] commented 6 months ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud

revolunet commented 6 months ago

@SocketSecurity ignore npm/react-vertical-timeline-component@3.6.0 @SocketSecurity ignore npm/next@14.1.0

github-actions[bot] commented 6 months ago

:tada: This PR is included in version 1.37.3 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket: