From 9cc77005e1f261d112ceb279ec62cfb217ceb05e Mon Sep 17 00:00:00 2001 From: Bobby Galli Date: Tue, 26 Nov 2024 19:24:50 -0500 Subject: [PATCH] fix: npm audit --- .github/dependabot.yml | 20 ++++++++++++++++++++ package-lock.json | 12 ++++++------ 2 files changed, 26 insertions(+), 6 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..bb1fc75 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,20 @@ +# .github/dependabot.yml +version: 2 +updates: + - package-ecosystem: "npm" + directory: "/" + schedule: + interval: "monthly" + target-branch: "main" + versioning-strategy: "auto" + allow: + - dependency-type: "all" + ignore: + - dependency-type: "dev" + update-types: ["version-update:semver-major"] + labels: + - "dependencies" + - "npm" + commit-message: + prefix: "chore" + include: "scope" \ No newline at end of file diff --git a/package-lock.json b/package-lock.json index 194f9f8..465a530 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1136,9 +1136,9 @@ "license": "MIT" }, "node_modules/cross-spawn": { - "version": "7.0.3", - "resolved": "https://registry.npmjs.org/cross-spawn/-/cross-spawn-7.0.3.tgz", - "integrity": "sha512-iRDPJKUPVEND7dHPO8rkbOnPpyDygcDFtWjpeWNCgy8WP2rXcxXL8TskReQl6OrB2G7+UJrags1q15Fudc7G6w==", + "version": "7.0.6", + "resolved": "https://registry.npmjs.org/cross-spawn/-/cross-spawn-7.0.6.tgz", + "integrity": "sha512-uV2QOWP2nWzsy2aMp8aRibhi9dlzF5Hgh5SHaB9OiTGEyDTiJJyx0uy51QXdyWbtAHNua4XJzUKca3OzKUd3vA==", "license": "MIT", "dependencies": { "path-key": "^3.1.0", @@ -2850,9 +2850,9 @@ } }, "node_modules/npm-run-all/node_modules/cross-spawn": { - "version": "6.0.5", - "resolved": "https://registry.npmjs.org/cross-spawn/-/cross-spawn-6.0.5.tgz", - "integrity": "sha512-eTVLrBSt7fjbDygz805pMnstIs2VTBNkRm0qxZd+M7A5XDdxVRWO5MxGBXZhjY4cqLYLdtrGqRf8mBPmzwSpWQ==", + "version": "6.0.6", + "resolved": "https://registry.npmjs.org/cross-spawn/-/cross-spawn-6.0.6.tgz", + "integrity": "sha512-VqCUuhcd1iB+dsv8gxPttb5iZh/D0iubSP21g36KXdEuf6I5JiioesUVjpCdHV9MZRUfVFlvwtIUyPfxo5trtw==", "dev": true, "license": "MIT", "dependencies": {