godaddy / datastar

A robust and feature rich ODM for Cassandra.
MIT License
40 stars 12 forks source link

Configure Renovate #57

Open renovate[bot] opened 2 years ago

renovate[bot] commented 2 years ago

Mend Renovate

Welcome to Renovate! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin.

🚊 To activate Renovate, merge this Pull Request. To disable Renovate, simply close this Pull Request unmerged.


Detected Package Files

Configuration Summary

Based on the default config's presets, Renovate will:

🔡 Would you like to change the way Renovate is upgrading your dependencies? Simply edit the renovate.json in this branch with your custom config and the list of Pull Requests in the "What to Expect" section below will be updated the next time Renovate runs.


What to Expect

With your current configuration, Renovate will create 13 Pull Requests:

fix(deps): update dependency joi-of-cql to v2.0.3 - Schedule: ["at any time"] - Branch name: `renovate/joi-of-cql-2.x-lockfile` - Merge into: `master` - Upgrade [joi-of-cql](https://togithub.com/godaddy/joi-of-cql) to `2.0.3`
chore(deps): update dependency assume to v2.3.0 - Schedule: ["at any time"] - Branch name: `renovate/assume-2.x-lockfile` - Merge into: `master` - Upgrade [assume](https://togithub.com/bigpipe/assume) to `2.3.0`
chore(deps): update dependency assume-sinon to v1.1.0 - Schedule: ["at any time"] - Branch name: `renovate/assume-sinon-1.x-lockfile` - Merge into: `master` - Upgrade [assume-sinon](https://togithub.com/terinjokes/assume-sinon) to `1.1.0`
chore(deps): update dependency cassandra-driver to v4.6.4 - Schedule: ["at any time"] - Branch name: `renovate/cassandra-driver-4.x-lockfile` - Merge into: `master` - Upgrade [cassandra-driver](https://togithub.com/datastax/nodejs-driver) to `4.6.4`
chore(deps): update dependency eslint to v8.37.0 - Schedule: ["at any time"] - Branch name: `renovate/eslint-8.x-lockfile` - Merge into: `master` - Upgrade [eslint](https://togithub.com/eslint/eslint) to `8.37.0`
chore(deps): update node.js to 10.24 - Schedule: ["at any time"] - Branch name: `renovate/node-10.x` - Merge into: `master` - Upgrade [node](https://togithub.com/nodejs/node) to `10.24`
chore(deps): update node.js to 12.22 - Schedule: ["at any time"] - Branch name: `renovate/node-12.x` - Merge into: `master` - Upgrade [node](https://togithub.com/nodejs/node) to `12.22`
fix(deps): update dependency priam to v4.1.0 - Schedule: ["at any time"] - Branch name: `renovate/priam-4.x-lockfile` - Merge into: `master` - Upgrade [priam](https://togithub.com/godaddy/node-priam) to `4.1.0`
chore(deps): update dependency nyc to v15 - Schedule: ["at any time"] - Branch name: `renovate/nyc-15.x` - Merge into: `master` - Upgrade [nyc](https://togithub.com/istanbuljs/nyc) to `^15.0.0`
chore(deps): update dependency proxyquire to v2 - Schedule: ["at any time"] - Branch name: `renovate/proxyquire-2.x` - Merge into: `master` - Upgrade [proxyquire](https://togithub.com/thlorenz/proxyquire) to `^2.0.0`
chore(deps): update dependency sinon to v15 - Schedule: ["at any time"] - Branch name: `renovate/sinon-15.x` - Merge into: `master` - Upgrade [sinon](https://togithub.com/sinonjs/sinon) to `^15.0.0`
fix(deps): update dependency clone to v2 - Schedule: ["at any time"] - Branch name: `renovate/clone-2.x` - Merge into: `master` - Upgrade [clone](https://togithub.com/pvorb/node-clone) to `^2.0.0`
fix(deps): update dependency uuid to v9 - Schedule: ["at any time"] - Branch name: `renovate/uuid-9.x` - Merge into: `master` - Upgrade [uuid](https://togithub.com/uuidjs/uuid) to `^9.0.0`


🚞 Branch creation will be limited to maximum 2 per hour, so it doesn't swamp any CI resources or overwhelm the project. See docs for prhourlylimit for details.


❓ Got questions? Check out Renovate's Docs, particularly the Getting Started section. If you need any further assistance then you can also request help here.


This PR has been generated by Mend Renovate. View repository job log here.

rmarkins-godaddy commented 1 year ago

Logo Checkmarx One – Scan Summary & Details – 54dd5d3c-b17a-4ffb-bee5-a3a74f7f7126

New Issues

Severity Issue Source File / Package Checkmarx Insight
LOW JSON_Hijacking /examples/music/index.js: 60 Attack Vector
LOW Password_Weak_Encryption /test/helpers/index.js: 64 Attack Vector
LOW Password_Weak_Encryption /test/helpers/index.js: 64 Attack Vector
LOW Password_Weak_Encryption /test/helpers/index.js: 64 Attack Vector
LOW Password_Weak_Encryption /test/helpers/index.js: 64 Attack Vector
LOW Password_Weak_Encryption /test/helpers/index.js: 64 Attack Vector
LOW Password_Weak_Encryption /test/helpers/index.js: 2 Attack Vector
LOW Password_Weak_Encryption /test/helpers/index.js: 64 Attack Vector
LOW Password_Weak_Encryption /test/helpers/index.js: 66 Attack Vector
LOW Password_Weak_Encryption /test/helpers/index.js: 2 Attack Vector
LOW Potentially_Vulnerable_To_CSRF /examples/music/index.js: 21 Attack Vector
LOW Use_Of_HTTP_Sensitive_Data_Exposure /examples/music/index.js: 21 Attack Vector