weareinreach / InReach

InReach is the worldโ€™s first open source platform matching LGBTQ+ people facing persecution or discrimination with safe, independently verified resources.
https://app.inreach.org
GNU General Public License v3.0
42 stars 4 forks source link

fix(auth): update all non-major dependencies #1430

Closed renovate[bot] closed 3 weeks ago

renovate[bot] commented 3 weeks ago

This PR contains the following updates:

Package Type Update Change OpenSSF
@aws-sdk/client-cognito-identity-provider (source) dependencies minor 3.677.0 -> 3.679.0 OpenSSF Scorecard
i18next (source) peerDependencies patch 23.16.2 -> 23.16.3 OpenSSF Scorecard
i18next (source) devDependencies patch 23.16.2 -> 23.16.3 OpenSSF Scorecard
i18next (source) dependencies patch 23.16.2 -> 23.16.3 OpenSSF Scorecard
knip (source) devDependencies minor 5.33.3 -> 5.34.0 OpenSSF Scorecard
msw (source) devDependencies patch 2.5.0 -> 2.5.1 OpenSSF Scorecard
next-auth (source) peerDependencies patch 4.24.8 -> 4.24.10 OpenSSF Scorecard
next-auth (source) devDependencies patch 4.24.8 -> 4.24.10 OpenSSF Scorecard
next-auth (source) dependencies patch 4.24.8 -> 4.24.10 OpenSSF Scorecard
pg (source) dependencies patch 8.13.0 -> 8.13.1 OpenSSF Scorecard
typesync devDependencies patch 0.13.0 -> 0.13.2 OpenSSF Scorecard
zod-to-json-schema devDependencies patch 3.23.3 -> 3.23.5 OpenSSF Scorecard

Release Notes

aws/aws-sdk-js-v3 (@​aws-sdk/client-cognito-identity-provider) ### [`v3.679.0`](https://redirect.github.com/aws/aws-sdk-js-v3/blob/HEAD/clients/client-cognito-identity-provider/CHANGELOG.md#36790-2024-10-24) [Compare Source](https://redirect.github.com/aws/aws-sdk-js-v3/compare/v3.678.0...v3.679.0) **Note:** Version bump only for package [@​aws-sdk/client-cognito-identity-provider](https://redirect.github.com/aws-sdk/client-cognito-identity-provider) ### [`v3.678.0`](https://redirect.github.com/aws/aws-sdk-js-v3/blob/HEAD/clients/client-cognito-identity-provider/CHANGELOG.md#36780-2024-10-23) [Compare Source](https://redirect.github.com/aws/aws-sdk-js-v3/compare/v3.677.0...v3.678.0) **Note:** Version bump only for package [@​aws-sdk/client-cognito-identity-provider](https://redirect.github.com/aws-sdk/client-cognito-identity-provider)
i18next/i18next (i18next) ### [`v23.16.3`](https://redirect.github.com/i18next/i18next/blob/HEAD/CHANGELOG.md#23163) [Compare Source](https://redirect.github.com/i18next/i18next/compare/v23.16.2...v23.16.3) - fix utils imports for Deno
webpro-nl/knip (knip) ### [`v5.34.0`](https://redirect.github.com/webpro-nl/knip/releases/tag/5.34.0) [Compare Source](https://redirect.github.com/webpro-nl/knip/compare/5.33.3...5.34.0) - Don't use `path` if step also has `repository` in github-action plugin ([`c6e4d31`](https://redirect.github.com/webpro-nl/knip/commit/c6e4d310)) - Give plugins a chance to prep config args ([`a2217a2`](https://redirect.github.com/webpro-nl/knip/commit/a2217a28)) - Let's start out conservatively ([`a2e83f8`](https://redirect.github.com/webpro-nl/knip/commit/a2e83f88)) - More consistent naming ([`bae87d9`](https://redirect.github.com/webpro-nl/knip/commit/bae87d96)) - Optimize a bit after the dust has settled ([`31f1e7e`](https://redirect.github.com/webpro-nl/knip/commit/31f1e7ee)) - Cherry on the pie ([`617e067`](https://redirect.github.com/webpro-nl/knip/commit/617e067e)) - Handle config files only once across workspaces ([`939f511`](https://redirect.github.com/webpro-nl/knip/commit/939f5110)) - Improve naming and simplify a few things ([`f4db204`](https://redirect.github.com/webpro-nl/knip/commit/f4db2047)) - Add coverage for unused files with compiler extension ([`c2e2712`](https://redirect.github.com/webpro-nl/knip/commit/c2e27127)) - Ignore `virtual:` imports, don't report as unlisted dependencies ([`2ef75cc`](https://redirect.github.com/webpro-nl/knip/commit/2ef75ccf)) - Remove module resolving from plugins ([`53839e0`](https://redirect.github.com/webpro-nl/knip/commit/53839e08)) - Temp use Bun for in this integration test for green lights ([`98c1ff7`](https://redirect.github.com/webpro-nl/knip/commit/98c1ff7a)) - Add ability to add unresolved imports to `ignoreDependencies` ([`b8875be`](https://redirect.github.com/webpro-nl/knip/commit/b8875be3)) - Let's start out a tad more conservative ([`58ba79f`](https://redirect.github.com/webpro-nl/knip/commit/58ba79f9)) - Update dependencies ([`f4dc1e1`](https://redirect.github.com/webpro-nl/knip/commit/f4dc1e11)) - Optimize referenced dependency handling ([`a413ad8`](https://redirect.github.com/webpro-nl/knip/commit/a413ad84)) - Resolve config file paths and parse recursively ([`c03f963`](https://redirect.github.com/webpro-nl/knip/commit/c03f9630)) - Exclude empty config file path arrays from debug output ([`d288779`](https://redirect.github.com/webpro-nl/knip/commit/d288779e)) - Extend typedoc plugin ([`f2732fa`](https://redirect.github.com/webpro-nl/knip/commit/f2732fad)) - Presets are extended by local config in jest plugin ([`4973a9d`](https://redirect.github.com/webpro-nl/knip/commit/4973a9dc)) - Add test case to get refs from scripts ([`6115107`](https://redirect.github.com/webpro-nl/knip/commit/61151070)) - Refactor binary resolver & referenced dependency handling ([`f1349c2`](https://redirect.github.com/webpro-nl/knip/commit/f1349c23))
mswjs/msw (msw) ### [`v2.5.1`](https://redirect.github.com/mswjs/msw/releases/tag/v2.5.1) [Compare Source](https://redirect.github.com/mswjs/msw/compare/v2.5.0...v2.5.1) #### v2.5.1 (2024-10-24) ##### Bug Fixes - update`@inquirer/confirm` requirement to 5.0.0 ([#​2325](https://redirect.github.com/mswjs/msw/issues/2325)) ([`b65c0a8`](https://redirect.github.com/mswjs/msw/commit/b65c0a8ffac0a72b7d9980768f8c73e2d763f863)) [@​greysteil](https://redirect.github.com/greysteil) [@​kettanaito](https://redirect.github.com/kettanaito)
nextauthjs/next-auth (next-auth) ### [`v4.24.10`](https://redirect.github.com/nextauthjs/next-auth/releases/tag/next-auth%404.24.10) [Compare Source](https://redirect.github.com/nextauthjs/next-auth/compare/next-auth@4.24.9...next-auth@4.24.10) #### What's Changed - fix: functions that return promises must be async by [@​thomaslindstrom](https://redirect.github.com/thomaslindstrom) in [https://github.com/nextauthjs/next-auth/pull/12105](https://redirect.github.com/nextauthjs/next-auth/pull/12105) - fix: support AUTH_SECRET for compat with npx auth secret by [@​balazsorban44](https://redirect.github.com/balazsorban44) in https://github.com/nextauthjs/next-auth/commit/490a033cf0396fa634bf6636402624643babef5d **Full Changelog**: https://github.com/nextauthjs/next-auth/compare/next-auth@4.24.9...next-auth@4.24.10 ### [`v4.24.9`](https://redirect.github.com/nextauthjs/next-auth/releases/tag/next-auth%404.24.9) [Compare Source](https://redirect.github.com/nextauthjs/next-auth/compare/next-auth@4.24.8...next-auth@4.24.9) #### What's Changed - chore(docs): fix typo in WorkOS documentation by [@​outofgamut](https://redirect.github.com/outofgamut) in [https://github.com/nextauthjs/next-auth/pull/11959](https://redirect.github.com/nextauthjs/next-auth/pull/11959) - chore(v4): add neon sponsor by [@​ndom91](https://redirect.github.com/ndom91) in [https://github.com/nextauthjs/next-auth/pull/12008](https://redirect.github.com/nextauthjs/next-auth/pull/12008) - cookie package upgraded by [@​talyuk](https://redirect.github.com/talyuk) in [https://github.com/nextauthjs/next-auth/pull/12046](https://redirect.github.com/nextauthjs/next-auth/pull/12046) - Allow Next.js v15 peer dependency by [@​thomaslindstrom](https://redirect.github.com/thomaslindstrom) in [https://github.com/nextauthjs/next-auth/pull/12098](https://redirect.github.com/nextauthjs/next-auth/pull/12098) - `await` dynamic APIs as per Next.js 15 changes by [@​balazsorban44](https://redirect.github.com/balazsorban44) in https://github.com/nextauthjs/next-auth/commit/4d143c51999e96f39b3fe9e0c7da2b070639253c #### New Contributors - [@​outofgamut](https://redirect.github.com/outofgamut) made their first contribution in [https://github.com/nextauthjs/next-auth/pull/11959](https://redirect.github.com/nextauthjs/next-auth/pull/11959) - [@​talyuk](https://redirect.github.com/talyuk) made their first contribution in [https://github.com/nextauthjs/next-auth/pull/12046](https://redirect.github.com/nextauthjs/next-auth/pull/12046) - [@​thomaslindstrom](https://redirect.github.com/thomaslindstrom) made their first contribution in [https://github.com/nextauthjs/next-auth/pull/12098](https://redirect.github.com/nextauthjs/next-auth/pull/12098) **Full Changelog**: https://github.com/nextauthjs/next-auth/compare/next-auth@4.24.8...next-auth@4.24.9
brianc/node-postgres (pg) ### [`v8.13.1`](https://redirect.github.com/brianc/node-postgres/compare/pg@8.13.0...95d7e620ef8b51743b4cbca05dd3c3ce858ecea7) [Compare Source](https://redirect.github.com/brianc/node-postgres/compare/pg@8.13.0...pg@8.13.1)
jeffijoe/typesync (typesync) ### [`v0.13.2`](https://redirect.github.com/jeffijoe/typesync/blob/HEAD/CHANGELOG.md#v0132) [Compare Source](https://redirect.github.com/jeffijoe/typesync/compare/v0.13.1...v0.13.2) - [#​127](https://redirect.github.com/jeffijoe/typesync/pull/127): Show dependencies on `--dry` failure, [@​Benjamin-Frost](https://redirect.github.com/Benjamin-Frost) ### [`v0.13.1`](https://redirect.github.com/jeffijoe/typesync/blob/HEAD/CHANGELOG.md#v0131) [Compare Source](https://redirect.github.com/jeffijoe/typesync/compare/v0.13.0...v0.13.1) - [#​126](https://redirect.github.com/jeffijoe/typesync/pull/126): Allow ignoring workspace members, [@​lishaduck](https://redirect.github.com/lishaduck)
StefanTerdell/zod-to-json-schema (zod-to-json-schema) ### [`v3.23.5`](https://redirect.github.com/StefanTerdell/zod-to-json-schema/compare/308bdf638646d1db53b955a9572ca64c155367df...819447de70076ad106a9a4b911adcb27c3e04ec0) [Compare Source](https://redirect.github.com/StefanTerdell/zod-to-json-schema/compare/308bdf638646d1db53b955a9572ca64c155367df...819447de70076ad106a9a4b911adcb27c3e04ec0) ### [`v3.23.4`](https://redirect.github.com/StefanTerdell/zod-to-json-schema/compare/a211356d22ebffef91049ed276d1fb8eb50771f8...308bdf638646d1db53b955a9572ca64c155367df) [Compare Source](https://redirect.github.com/StefanTerdell/zod-to-json-schema/compare/a211356d22ebffef91049ed276d1fb8eb50771f8...308bdf638646d1db53b955a9572ca64c155367df)

Configuration

๐Ÿ“… Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

๐Ÿšฆ Automerge: Disabled by config. Please merge this manually once you are satisfied.

โ™ป Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

๐Ÿ‘ป Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.



This PR was generated by Mend Renovate. View the repository job log.

vercel[bot] commented 3 weeks ago

The latest updates on your projects. Learn more about Vercel for Git โ†—๏ธŽ

Name Status Preview Comments Updated (UTC)
inreach-app โœ… Ready (Inspect) Visit Preview ๐Ÿ’ฌ Add feedback Oct 24, 2024 10:31pm
coderabbitai[bot] commented 3 weeks ago

[!IMPORTANT]

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


๐Ÿชง Tips ### Chat There are 3 ways to chat with [CodeRabbit](https://coderabbit.ai): - Review comments: Directly reply to a review comment made by CodeRabbit. Example: - `I pushed a fix in commit , please review it.` - `Generate unit testing code for this file.` - `Open a follow-up GitHub issue for this discussion.` - Files and specific lines of code (under the "Files changed" tab): Tag `@coderabbitai` in a new review comment at the desired location with your query. Examples: - `@coderabbitai generate unit testing code for this file.` - `@coderabbitai modularize this function.` - PR comments: Tag `@coderabbitai` in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples: - `@coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.` - `@coderabbitai read src/utils.ts and generate unit testing code.` - `@coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.` - `@coderabbitai help me debug CodeRabbit configuration file.` Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. ### CodeRabbit Commands (Invoked using PR comments) - `@coderabbitai pause` to pause the reviews on a PR. - `@coderabbitai resume` to resume the paused reviews. - `@coderabbitai review` to trigger an incremental review. This is useful when automatic reviews are disabled for the repository. - `@coderabbitai full review` to do a full review from scratch and review all the files again. - `@coderabbitai summary` to regenerate the summary of the PR. - `@coderabbitai resolve` resolve all the CodeRabbit review comments. - `@coderabbitai configuration` to show the current CodeRabbit configuration for the repository. - `@coderabbitai help` to get help. ### Other keywords and placeholders - Add `@coderabbitai ignore` anywhere in the PR description to prevent this PR from being reviewed. - Add `@coderabbitai summary` or `` to generate the high-level summary at a specific location in the PR description. - Add `@coderabbitai` or `@coderabbitai title` anywhere in the PR title to generate the title automatically. ### CodeRabbit Configuration File (`.coderabbit.yaml`) - You can programmatically configure CodeRabbit by adding a `.coderabbit.yaml` file to the root of your repository. - Please see the [configuration documentation](https://docs.coderabbit.ai/guides/configure-coderabbit) for more information. - If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: `# yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json` ### Documentation and Community - Visit our [Documentation](https://coderabbit.ai/docs) for detailed information on how to use CodeRabbit. - Join our [Discord Community](http://discord.gg/coderabbit) to get help, request features, and share feedback. - Follow us on [X/Twitter](https://twitter.com/coderabbitai) for updates and announcements.
socket-security[bot] commented 3 weeks ago

New and removed dependencies detected. Learn more about Socket for GitHub โ†—๏ธŽ

Package New capabilities Transitives Size Publisher
npm/@aws-sdk/client-cognito-identity-provider@3.679.0 Transitive: environment, filesystem, network, shell +69 6.14 MB aws-sdk-bot

๐Ÿšฎ Removed packages: npm/@aws-sdk/client-cognito-identity-provider@3.677.0

View full reportโ†—๏ธŽ

github-actions[bot] commented 3 weeks ago

๐Ÿ“ฆ Next.js Bundle Analysis for @weareinreach/app

This analysis was generated by the Next.js Bundle Analysis action. ๐Ÿค–

This PR introduced no changes to the JavaScript bundle! ๐Ÿ™Œ

relativeci[bot] commented 3 weeks ago

#1686 Bundle Size โ€” 5.64MiB (~+0.01%).

1af0fc1(current) vs b4e70e6 dev#1677(baseline)

[!WARNING] Bundle contains 5 duplicate packages โ€“ View duplicate packages

Bundle metrics  Change 2 changes Regression 1 regression
โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒ โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒCurrent
#1686
โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒBaseline
#1677
Regression  Initial JS 3.05MiB(+0.01%) 3.05MiB
No change  Initial CSS 9.7KiB 9.7KiB
Change  Cache Invalidation 30.48% 28.33%
No change  Chunks 67 67
No change  Assets 80 80
No change  Modules 2016 2016
No change  Duplicate Modules 361 361
No change  Duplicate Code 10% 10%
No change  Packages 159 159
No change  Duplicate Packages 5 5

Bundle size by type  Change 1 change Regression 1 regression
| โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒ | โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒโ€ƒCurrent
[#1686](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1686-BaUwNxahYODFUUqqWyLD?utm_source=github&utm_content=totals&utm_campaign=pr-report "View bundle analysis report") | โ€ƒโ€ƒโ€ƒโ€ƒโ€ƒBaseline
[#1677](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1677-G0Wnryd3m9KRWUQWpwFf?utm_source=github&utm_content=totals&utm_campaign=pr-report "View baseline bundle analysis report") | |:--|--:|--:| | Regression  [JS](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1686-BaUwNxahYODFUUqqWyLD/assets?ba=%7B%22filters%22%3A%22ft.CSS-0_ft.JS-1_ft.IMG-0_ft.MEDIA-0_ft.FONT-0_ft.HTML-0_ft.OTHER-0%22%7D&utm_source=github&utm_content=totals&utm_campaign=pr-report "View JS assets") | `4.4MiB` (`~+0.01%`) | `4.4MiB` | | No change  [Other](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1686-BaUwNxahYODFUUqqWyLD/assets?ba=%7B%22filters%22%3A%22ft.CSS-0_ft.JS-0_ft.IMG-0_ft.MEDIA-0_ft.FONT-0_ft.HTML-0_ft.OTHER-1%22%7D&utm_source=github&utm_content=totals&utm_campaign=pr-report "View Other assets") | `1.13MiB` | `1.13MiB` | | No change  [Fonts](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1686-BaUwNxahYODFUUqqWyLD/assets?ba=%7B%22filters%22%3A%22ft.CSS-0_ft.JS-0_ft.IMG-0_ft.MEDIA-0_ft.FONT-1_ft.HTML-0_ft.OTHER-0%22%7D&utm_source=github&utm_content=totals&utm_campaign=pr-report "View Fonts assets") | `94.54KiB` | `94.54KiB` | | No change  [CSS](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1686-BaUwNxahYODFUUqqWyLD/assets?ba=%7B%22filters%22%3A%22ft.CSS-1_ft.JS-0_ft.IMG-0_ft.MEDIA-0_ft.FONT-0_ft.HTML-0_ft.OTHER-0%22%7D&utm_source=github&utm_content=totals&utm_campaign=pr-report "View CSS assets") | `9.7KiB` | `9.7KiB` | | No change  [IMG](https://app.relative-ci.com/projects/lv8Dwq77xc3pShDq86Dg/jobs/1686-BaUwNxahYODFUUqqWyLD/assets?ba=%7B%22filters%22%3A%22ft.CSS-0_ft.JS-0_ft.IMG-1_ft.MEDIA-0_ft.FONT-0_ft.HTML-0_ft.OTHER-0%22%7D&utm_source=github&utm_content=totals&utm_campaign=pr-report "View IMG assets") | `8.57KiB` | `8.57KiB` |

Bundle analysis reportโ€ƒBranch renovate/all-minor-patchโ€ƒProject dashboard


Generated by RelativeCIโ€ƒDocumentationโ€ƒReport issue

alwaysmeticulous[bot] commented 3 weeks ago

๐Ÿค– No test run has been triggered as your Meticulous project has been deactivated (since you haven't viewed any test results in a while). Click here to reactivate.

Last updated for commit 1af0fc1. This comment will update as new commits are pushed.

sonarcloud[bot] commented 3 weeks ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarCloud