weareinreach / InReach

InReach is the worldโ€™s first open source platform matching LGBTQ+ people facing persecution or discrimination with safe, independently verified resources.
https://app.inreach.org
GNU General Public License v3.0
42 stars 4 forks source link

fix(auth): update all non-major dependencies #1420

Closed renovate[bot] closed 1 month ago

renovate[bot] commented 1 month ago

This PR contains the following updates:

Package Type Update Change OpenSSF Age Adoption Passing Confidence
@aws-sdk/client-cognito-identity-provider (source) dependencies minor 3.662.0 -> 3.670.0 OpenSSF Scorecard age adoption passing confidence
@changesets/cli (source) devDependencies patch 2.27.8 -> 2.27.9 OpenSSF Scorecard age adoption passing confidence
@iconify-json/carbon devDependencies patch 1.2.1 -> 1.2.3 age adoption passing confidence
@iconify-json/mdi devDependencies patch 1.2.0 -> 1.2.1 age adoption passing confidence
@iconify-json/ph devDependencies patch 1.2.0 -> 1.2.1 age adoption passing confidence
@iconify-json/simple-icons devDependencies patch 1.2.5 -> 1.2.7 age adoption passing confidence
@playwright/test (source) devDependencies minor 1.47.2 -> 1.48.0 OpenSSF Scorecard age adoption passing confidence
@relative-ci/agent (source) devDependencies patch 4.2.11 -> 4.2.12 OpenSSF Scorecard age adoption passing confidence
@sentry/nextjs (source) dependencies minor 8.32.0 -> 8.34.0 OpenSSF Scorecard age adoption passing confidence
@sentry/node (source) dependencies minor 8.32.0 -> 8.34.0 OpenSSF Scorecard age adoption passing confidence
@sentry/opentelemetry (source) dependencies minor 8.32.0 -> 8.34.0 OpenSSF Scorecard age adoption passing confidence
@sentry/profiling-node (source) dependencies minor 8.32.0 -> 8.34.0 OpenSSF Scorecard age adoption passing confidence
@snaplet/copycat devDependencies minor 5.0.0 -> 5.1.0 OpenSSF Scorecard age adoption passing confidence
@storybook/addon-a11y (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/addon-actions (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/addon-essentials (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/addon-interactions (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/addon-links (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/addon-mdx-gfm (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/addon-viewport (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/components (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/core-events (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/manager-api (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/nextjs (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/preview-api (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/react (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/test (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/theming (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@storybook/types (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
@swc/core (source) devDependencies patch 1.7.26 -> 1.7.35 OpenSSF Scorecard age adoption passing confidence
@types/node (source) devDependencies patch 20.16.10 -> 20.16.11 OpenSSF Scorecard age adoption passing confidence
@types/react-dom (source) devDependencies patch 18.3.0 -> 18.3.1 OpenSSF Scorecard age adoption passing confidence
chromatic (source) devDependencies minor 11.11.0 -> 11.12.5 OpenSSF Scorecard age adoption passing confidence
chromatic (source) dependencies minor 11.11.0 -> 11.12.5 OpenSSF Scorecard age adoption passing confidence
cookies-next dependencies minor 4.2.1 -> 4.3.0 OpenSSF Scorecard age adoption passing confidence
geo-tz dependencies patch 8.1.1 -> 8.1.2 OpenSSF Scorecard age adoption passing confidence
google-auth-library devDependencies patch 9.14.1 -> 9.14.2 OpenSSF Scorecard age adoption passing confidence
i18next (source) peerDependencies patch 23.15.1 -> 23.15.2 OpenSSF Scorecard age adoption passing confidence
i18next (source) devDependencies patch 23.15.1 -> 23.15.2 OpenSSF Scorecard age adoption passing confidence
i18next (source) dependencies patch 23.15.1 -> 23.15.2 OpenSSF Scorecard age adoption passing confidence
i18next-http-backend peerDependencies patch 2.6.1 -> 2.6.2 OpenSSF Scorecard age adoption passing confidence
i18next-http-backend devDependencies patch 2.6.1 -> 2.6.2 OpenSSF Scorecard age adoption passing confidence
i18next-http-backend dependencies patch 2.6.1 -> 2.6.2 OpenSSF Scorecard age adoption passing confidence
knip (source) devDependencies minor 5.30.6 -> 5.33.3 OpenSSF Scorecard age adoption passing confidence
libphonenumber-js dependencies patch 1.11.10 -> 1.11.11 age adoption passing confidence
libphonenumber-js devDependencies patch 1.11.10 -> 1.11.11 age adoption passing confidence
listr2 devDependencies patch 8.2.4 -> 8.2.5 OpenSSF Scorecard age adoption passing confidence
msw (source) devDependencies patch 2.4.9 -> 2.4.10 OpenSSF Scorecard age adoption passing confidence
nextjs-routes dependencies patch 2.2.2 -> 2.2.3 OpenSSF Scorecard age adoption passing confidence
node (source) minor 20.17.0 -> 20.18.0 OpenSSF Scorecard age adoption passing confidence
pnpm (source) packageManager patch 9.12.0 -> 9.12.1 OpenSSF Scorecard age adoption passing confidence
prettier-plugin-packagejson devDependencies patch 2.5.2 -> 2.5.3 OpenSSF Scorecard age adoption passing confidence
remeda (source) dependencies minor 2.14.0 -> 2.15.0 OpenSSF Scorecard age adoption passing confidence
storybook (source) devDependencies patch 8.3.4 -> 8.3.5 OpenSSF Scorecard age adoption passing confidence
typescript (source) devDependencies patch 5.6.2 -> 5.6.3 OpenSSF Scorecard age adoption passing confidence

Release Notes

aws/aws-sdk-js-v3 (@​aws-sdk/client-cognito-identity-provider) ### [`v3.670.0`](https://redirect.github.com/aws/aws-sdk-js-v3/blob/HEAD/clients/client-cognito-identity-provider/CHANGELOG.md#36700-2024-10-11) [Compare Source](https://redirect.github.com/aws/aws-sdk-js-v3/compare/v3.669.0...v3.670.0) **Note:** Version bump only for package [@​aws-sdk/client-cognito-identity-provider](https://redirect.github.com/aws-sdk/client-cognito-identity-provider) ### [`v3.669.0`](https://redirect.github.com/aws/aws-sdk-js-v3/blob/HEAD/clients/client-cognito-identity-provider/CHANGELOG.md#36690-2024-10-10) [Compare Source](https://redirect.github.com/aws/aws-sdk-js-v3/compare/v3.668.0...v3.669.0) **Note:** Version bump only for package [@​aws-sdk/client-cognito-identity-provider](https://redirect.github.com/aws-sdk/client-cognito-identity-provider) ### [`v3.668.0`](https://redirect.github.com/aws/aws-sdk-js-v3/blob/HEAD/clients/client-cognito-identity-provider/CHANGELOG.md#36680-2024-10-09) [Compare Source](https://redirect.github.com/aws/aws-sdk-js-v3/compare/v3.667.0...v3.668.0) **Note:** Version bump only for package [@​aws-sdk/client-cognito-identity-provider](https://redirect.github.com/aws-sdk/client-cognito-identity-provider) ### [`v3.667.0`](https://redirect.github.com/aws/aws-sdk-js-v3/blob/HEAD/clients/client-cognito-identity-provider/CHANGELOG.md#36670-2024-10-08) [Compare Source](https://redirect.github.com/aws/aws-sdk-js-v3/compare/v3.666.0...v3.667.0) **Note:** Version bump

Configuration

๐Ÿ“… Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

๐Ÿšฆ Automerge: Disabled by config. Please merge this manually once you are satisfied.

โ™ป Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

๐Ÿ‘ป Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.



This PR was generated by Mend Renovate. View the repository job log.

vercel[bot] commented 1 month ago

The latest updates on your projects. Learn more about Vercel for Git โ†—๏ธŽ

Name Status Preview Comments Updated (UTC)
inreach-app โœ… Ready (Inspect) Visit Preview ๐Ÿ’ฌ Add feedback Oct 11, 2024 10:25pm
coderabbitai[bot] commented 1 month ago

[!IMPORTANT]

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


๐Ÿชง Tips ### Chat There are 3 ways to chat with [CodeRabbit](https://coderabbit.ai): - Review comments: Directly reply to a review comment made by CodeRabbit. Example: - `I pushed a fix in commit , please review it.` - `Generate unit testing code for this file.` - `Open a follow-up GitHub issue for this discussion.` - Files and specific lines of code (under the "Files changed" tab): Tag `@coderabbitai` in a new review comment at the desired location with your query. Examples: - `@coderabbitai generate unit testing code for this file.` - `@coderabbitai modularize this function.` - PR comments: Tag `@coderabbitai` in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples: - `@coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.` - `@coderabbitai read src/utils.ts and generate unit testing code.` - `@coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.` - `@coderabbitai help me debug CodeRabbit configuration file.` Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. ### CodeRabbit Commands (Invoked using PR comments) - `@coderabbitai pause` to pause the reviews on a PR. - `@coderabbitai resume` to resume the paused reviews. - `@coderabbitai review` to trigger an incremental review. This is useful when automatic reviews are disabled for the repository. - `@coderabbitai full review` to do a full review from scratch and review all the files again. - `@coderabbitai summary` to regenerate the summary of the PR. - `@coderabbitai resolve` resolve all the CodeRabbit review comments. - `@coderabbitai configuration` to show the current CodeRabbit configuration for the repository. - `@coderabbitai help` to get help. ### Other keywords and placeholders - Add `@coderabbitai ignore` anywhere in the PR description to prevent this PR from being reviewed. - Add `@coderabbitai summary` or `` to generate the high-level summary at a specific location in the PR description. - Add `@coderabbitai` or `@coderabbitai title` anywhere in the PR title to generate the title automatically. ### CodeRabbit Configuration File (`.coderabbit.yaml`) - You can programmatically configure CodeRabbit by adding a `.coderabbit.yaml` file to the root of your repository. - Please see the [configuration documentation](https://docs.coderabbit.ai/guides/configure-coderabbit) for more information. - If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: `# yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json` ### Documentation and Community - Visit our [Documentation](https://coderabbit.ai/docs) for detailed information on how to use CodeRabbit. - Join our [Discord Community](http://discord.gg/coderabbit) to get help, request features, and share feedback. - Follow us on [X/Twitter](https://twitter.com/coderabbitai) for updates and announcements.
socket-security[bot] commented 1 month ago

New and removed dependencies detected. Learn more about Socket for GitHub โ†—๏ธŽ

Package New capabilities Transitives Size Publisher
npm/@aws-sdk/client-cognito-identity-provider@3.670.0 Transitive: environment, filesystem, network +68 6.08 MB amzn-oss, aws-sdk-bot, kuhe, ...2 more
npm/@changesets/cli@2.27.9 Transitive: environment, filesystem +22 1.91 MB changesets-release-bot
npm/@iconify-json/carbon@1.2.3 None 0 1.05 MB cyberalien
npm/@iconify-json/mdi@1.2.1 None 0 3.47 MB cyberalien
npm/@iconify-json/ph@1.2.1 None 0 4.57 MB cyberalien
npm/@iconify-json/simple-icons@1.2.7 None 0 4.61 MB cyberalien
npm/@playwright/test@1.48.0 None 0 25.5 kB yurys
npm/@relative-ci/agent@4.2.12 environment, filesystem, shell +2 73 kB relativeci-bot
npm/@sentry/nextjs@8.34.0 Transitive: environment, filesystem, network, shell, unsafe +40 24.5 MB benvinegar, billyvg, evanpurkhiser, ...8 more
npm/@sentry/node@8.34.0 Transitive: environment, filesystem, unsafe +37 10.7 MB benvinegar, billyvg, evanpurkhiser, ...8 more
npm/@sentry/opentelemetry@8.34.0 None +3 4.45 MB benvinegar, billyvg, evanpurkhiser, ...8 more
npm/@sentry/profiling-node@8.34.0 environment, filesystem, shell +3 6.6 MB sentry-bot
npm/@snaplet/copycat@5.1.0 None 0 1.89 MB justinvdm
npm/@storybook/addon-a11y@8.3.5 None +2 57.4 kB shilman
npm/@storybook/addon-actions@8.3.5 None +2 70 kB domyen, ghengeveld, jreinhold, ...8 more
npm/@storybook/addon-essentials@8.3.5 Transitive: eval, filesystem +16 5.06 MB domyen, ghengeveld, jreinhold, ...8 more
npm/@storybook/addon-interactions@8.3.5 None +4 550 kB shilman
npm/@storybook/addon-links@8.3.5 None +2 71 kB shilman
npm/@storybook/addon-mdx-gfm@8.3.5 None 0 4.08 kB shilman
npm/@storybook/addon-viewport@8.3.5 None 0 20.6 kB shilman
npm/@storybook/components@8.3.5 None 0 1.24 kB shilman
npm/@storybook/core-events@8.3.5 None 0 3.82 kB shilman
npm/@storybook/manager-api@8.3.5 None 0 1.22 kB shilman
npm/@storybook/nextjs@8.3.5 Transitive: environment, filesystem, unsafe +125 18.1 MB shilman
npm/@storybook/preview-api@8.3.5 None 0 1.24 kB shilman
npm/@storybook/react@8.3.5 None +8 3.71 MB shilman
npm/@storybook/test@8.3.5 Transitive: environment +19 4.73 MB
npm/@storybook/theming@8.3.5 None 0 1.53 kB domyen, ghengeveld, jreinhold, ...8 more
npm/@storybook/types@8.3.5 None 0 1.19 kB shilman
npm/@swc/core@1.7.35 environment, filesystem, shell +2 208 kB kdy1
npm/@types/node@20.16.11 None 0 2.21 MB types
npm/@types/react-dom@18.3.1 None 0 0 B

๐Ÿšฎ Removed packages: npm/@aws-sdk/client-cognito-identity-provider@3.662.0, npm/@changesets/cli@2.27.8, npm/@iconify-json/carbon@1.2.1, npm/@iconify-json/mdi@1.2.0, npm/@iconify-json/ph@1.2.0, npm/@iconify-json/simple-icons@1.2.5, npm/@playwright/test@1.47.2, npm/@relative-ci/agent@4.2.11, npm/@sentry/nextjs@8.32.0, npm/@sentry/node@8.32.0, npm/@sentry/opentelemetry@8.32.0, npm/@sentry/profiling-node@8.32.0, npm/@storybook/addon-a11y@8.3.4, npm/@storybook/addon-actions@8.3.4, npm/@storybook/addon-essentials@8.3.4, npm/@storybook/addon-interactions@8.3.4, npm/@storybook/addon-links@8.3.4, npm/@storybook/addon-mdx-gfm@8.3.4, npm/@storybook/addon-viewport@8.3.4, npm/@storybook/components@8.3.4, npm/@storybook/core-events@8.3.4, npm/@storybook/manager-api@8.3.4, npm/@storybook/nextjs@8.3.4, npm/@storybook/preview-api@8.3.4, npm/@storybook/react@8.3.4, npm/@storybook/test@8.3.4, npm/@storybook/theming@8.3.4, npm/@storybook/types@8.3.4, npm/@swc/core@1.7.26, npm/@types/node@20.16.10, npm/@types/react-dom@18.3.0

View full reportโ†—๏ธŽ

github-actions[bot] commented 1 month ago

๐Ÿ“ฆ Next.js Bundle Analysis for @weareinreach/app

This analysis was generated by the Next.js Bundle Analysis action. ๐Ÿค–

This PR introduced no changes to the JavaScript bundle! ๐Ÿ™Œ

relativeci[bot] commented 1 month ago

#1569 Bundle Size โ€” 3.51MiB (+0.02%).

882d62c(current) vs 0e25835 dev#1525(baseline)

[!WARNING] Bundle contains 5 duplicate packages โ€“ View duplicate packages

Bundle metrics  Change 3 changes Regression 1 regression
โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒ โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒCurrent
#1569
โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒBaseline
#1525
Regression  Initial JS 3.05MiB(+0.02%) 3.05MiB
No change  Initial CSS 9.54KiB 9.54KiB
Change  Cache Invalidation 65.85% 45.52%
No change  Chunks 67 67
No change  Assets 80 80
No change  Modules 2016 2016
No change  Duplicate Modules 361 361
Change  Duplicate Code 10.01%(-0.1%) 10.02%
No change  Packages 159 159
No change  Duplicate Packages 5 5

Bundle size by type  Change 1 change Regression 1 regression
| โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒ | โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒCurrent
[#1569](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1569-CJCRjsGqq0KcKnwCkJK2?utm_source=github&utm_medium=pr-report "View bundle analysis report") | โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒBaseline
[#1525](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1525-aZWujTgClQJlNfwpsHEy?utm_source=github&utm_medium=pr-report "View baseline bundle analysis report") | |:--|--:|--:| | Regression  [JS](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1569-CJCRjsGqq0KcKnwCkJK2/assets?ba=%7B%22filters%22%3A%22ft.CSS-0_ft.JS-1_ft.IMG-0_ft.MEDIA-0_ft.FONT-0_ft.HTML-0_ft.OTHER-0%22%7D "View JS assets") | `3.39MiB` (`+0.02%`) | `3.39MiB` | | No change  [Fonts](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1569-CJCRjsGqq0KcKnwCkJK2/assets?ba=%7B%22filters%22%3A%22ft.CSS-0_ft.JS-0_ft.IMG-0_ft.MEDIA-0_ft.FONT-1_ft.HTML-0_ft.OTHER-0%22%7D "View Fonts assets") | `94.54KiB` | `94.54KiB` | | No change  [CSS](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1569-CJCRjsGqq0KcKnwCkJK2/assets?ba=%7B%22filters%22%3A%22ft.CSS-1_ft.JS-0_ft.IMG-0_ft.MEDIA-0_ft.FONT-0_ft.HTML-0_ft.OTHER-0%22%7D "View CSS assets") | `9.54KiB` | `9.54KiB` | | No change  [Other](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1569-CJCRjsGqq0KcKnwCkJK2/assets?ba=%7B%22filters%22%3A%22ft.CSS-0_ft.JS-0_ft.IMG-0_ft.MEDIA-0_ft.FONT-0_ft.HTML-0_ft.OTHER-1%22%7D "View Other assets") | `8.69KiB` | `8.69KiB` | | No change  [IMG](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1569-CJCRjsGqq0KcKnwCkJK2/assets?ba=%7B%22filters%22%3A%22ft.CSS-0_ft.JS-0_ft.IMG-1_ft.MEDIA-0_ft.FONT-0_ft.HTML-0_ft.OTHER-0%22%7D "View IMG assets") | `8.57KiB` | `8.57KiB` |

Bundle analysis reportโ€ƒBranch renovate/all-minor-patchโ€ƒProject dashboard


Generated by RelativeCIโ€ƒDocumentationโ€ƒReport issue

alwaysmeticulous[bot] commented 1 month ago

๐Ÿค– No test run has been triggered as your Meticulous project has been deactivated (since you haven't viewed any test results in a while). Click here to reactivate.

Last updated for commit 882d62c. This comment will update as new commits are pushed.

sonarcloud[bot] commented 1 month ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarCloud