Open dependabot[bot] opened 1 year ago
:lock: The security scan detected 2 potential secrets in the code.
path line secret
------------------------------------ ------ ------------------
.github/workflows/api-dotnetcore.yml 132 f5f11ab3c73f737...
.github/workflows/app-react.yml 78 83c8083f22204c5...
Bumps loader-utils to 2.0.4 and updates ancestor dependencies loader-utils, react-scripts and react-styleguidist. These dependencies need to be updated together.
Updates
loader-utils
from 1.4.0 to 2.0.4Release notes
Sourced from loader-utils's releases.
... (truncated)
Changelog
Sourced from loader-utils's changelog.
Commits
6688b50
chore(release): 2.0.4ac09944
fix: ReDoS problem (#225)7162619
chore(release): 2.0.3a93cf6f
fix(security): prototype polution exploit (#217)90c7c4b
chore(release): 2.0.28c2d24e
fix: base64 generation and unicode characters (#197)5fb5562
chore(release): 2.0.11069f61
fix: md4 support on Node.js v17 (#193)d9f4e23
chore(release): 2.0.0865dc03
refactor: switch tomd4
by default (#168)Updates
react-scripts
from 4.0.3 to 5.0.1Commits
19fa58d
Publish9802941
fix: webpack noise printed only if error or warning (#12245)2eef1d0
Update templates to use React 18createRoot
(#12220)221e511
Publish5614c87
Add support for Tailwind (#11717)20edab4
fix(webpackDevServer): disable overlay for warnings (#11413)3afbbc0
Update all dependencies (#11624)f5467d5
feat(eslint-config-react-app): support ESLint 8.x (#11375)c7627ce
Update webpack and dev server (#11646)544befe
Update package.json (#11597)Updates
react-styleguidist
from 11.1.6 to 11.2.0Release notes
Sourced from react-styleguidist's releases.
Commits
92518df
feat: Webpack 5 support (#1903)6415cb6
Build(deps): Bump url-parse from 1.4.7 to 1.5.3 (#1896)6ca3c4c
chore: Add npm 'cache' to 'release' workflow (#1899)7d62618
chore: Add npm 'cache' to 'danger' workflow (#1900)9114b4a
docs: Fix code block formatting in Maintenance.md (#1908)54be33b
chore: Add npm 'cache' to 'release' workflow (#1901)48e98b8
chore: Add npm 'cache' to Node.js workflow (#1898)77a2a2e
fix: Removeis-directory
, usefs
module directly (#1897)0a477a6
docs: Add more funding options33b6796
Build(deps): Bump prismjs from 1.24.0 to 1.25.0 in /examples/webpack (#1892)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/bcgov/ag-pssg-sdlc/network/alerts).