diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 771ee21e..716adeae 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -29,12 +29,12 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10 + uses: github/codeql-action/init@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11 with: languages: ${{ matrix.language }} queries: security-extended,security-and-quality - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10 + uses: github/codeql-action/analyze@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11 with: category: '/language:${{matrix.language}}' diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index d015fc56..8eaee510 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -16,7 +16,7 @@ jobs: env: SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }} container: - image: returntocorp/semgrep@sha256:664850c7788f22af8194baab646b3290943f3fec7a00220786496a08f3eb5e34 # latest + image: returntocorp/semgrep@sha256:a147965cd455dd773f639b09c53b1428aa2d24f1c3459ca203a8ce84845e8f18 # latest steps: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - run: semgrep ci diff --git a/package.json b/package.json index 115ec6dd..459ee6cf 100644 --- a/package.json +++ b/package.json @@ -3,10 +3,10 @@ "author": "The OpenINF Authors & Friends", "private": "true", "description": "The OpenINF portal, other static resources, and more static electricity", - "packageManager": "pnpm@10.5.2", + "packageManager": "pnpm@10.6.2", "engines": { "node": "22.14.0", - "pnpm": "10.5.2" + "pnpm": "10.6.2" }, "exports": { "./build/constants": "./build/shared/constants.mjs", @@ -29,14 +29,14 @@ "@cspell/dict-lorem-ipsum": "4.0.4", "@isaacs/catcher": "1.0.4", "@openinf/gh-file-importer": "2.0.1", - "@shopify/prettier-plugin-liquid": "1.8.3", + "@shopify/prettier-plugin-liquid": "1.9.0", "@tsconfig/node-lts": "22.0.1", "@types/console-log-level": "1.4.5", "@types/gulp": "4.0.17", "@types/js-yaml": "4.0.9", - "@types/node": "22.13.8", + "@types/node": "22.13.10", "@yarnpkg/shell": "4.1.2", - "autoprefixer": "10.4.20", + "autoprefixer": "10.4.21", "bootstrap": "5.3.3", "browser-sync": "3.0.3", "browserslist-lint": "0.3.3", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 44c92402..efbeefef 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -24,8 +24,8 @@ importers: specifier: 2.0.1 version: 2.0.1 '@shopify/prettier-plugin-liquid': - specifier: 1.8.3 - version: 1.8.3(prettier@3.5.3) + specifier: 1.9.0 + version: 1.9.0(prettier@3.5.3) '@tsconfig/node-lts': specifier: 22.0.1 version: 22.0.1 @@ -39,14 +39,14 @@ importers: specifier: 4.0.9 version: 4.0.9 '@types/node': - specifier: 22.13.8 - version: 22.13.8 + specifier: 22.13.10 + version: 22.13.10 '@yarnpkg/shell': specifier: 4.1.2 version: 4.1.2(typanion@3.14.0) autoprefixer: - specifier: 10.4.20 - version: 10.4.20(postcss@8.5.2) + specifier: 10.4.21 + version: 10.4.21(postcss@8.5.2) bootstrap: specifier: 5.3.3 version: 5.3.3(@popperjs/core@2.11.8) @@ -1023,11 +1023,11 @@ packages: '@popperjs/core@2.11.8': resolution: {integrity: sha512-P1st0aksCrn9sGZhp8GMYwBnQsbvAWsZAX44oXNNvLHGqAOcoVxmjZiohstwQ7SqKnbR47akdNi+uleWD8+g6A==} - '@shopify/liquid-html-parser@2.6.0': - resolution: {integrity: sha512-vNU6vEpTRYwKGo77dEC1bt6SaUr0naZ0DFlhIvnkOlbo+6/Xfi/Ke4FZ+yFLrFy4/FNtzl8qmVFlo7bsvWnVBA==} + '@shopify/liquid-html-parser@2.7.0': + resolution: {integrity: sha512-DIkG3cs9vpIRpbaoU/Bv1TNnGXKiJTdCuJeiJlGhADcF4Ic4Da6ZsLI+/z1CoNn/fS59z0wOI/p2NsFWr6XJ8w==} - '@shopify/prettier-plugin-liquid@1.8.3': - resolution: {integrity: sha512-4ntAaEPaZl4BXhPly199befcv/yPhLXxt8toNS1OJvqUYrh8g9R8ZPBAT9jRPrHulce3xx/itqFaxirrcduXnA==} + '@shopify/prettier-plugin-liquid@1.9.0': + resolution: {integrity: sha512-79y7ZgaZcTTe9ODQN7QYnqZvj1BlaRt5wyxr4U6uYPaOPoTjRPLpvLkvnFUv9XoiPSlYwECk00vQCsYjPcO1nQ==} peerDependencies: prettier: ^2.0.0 || ^3.0.0 @@ -1113,8 +1113,8 @@ packages: '@types/nlcst@2.0.3': resolution: {integrity: sha512-vSYNSDe6Ix3q+6Z7ri9lyWqgGhJTmzRjZRqyq15N0Z/1/UnVsno9G/N40NBijoYx2seFDIl0+B2mgAb9mezUCA==} - '@types/node@22.13.8': - resolution: {integrity: sha512-G3EfaZS+iOGYWLLRCEAXdWK9my08oHNZ+FHluRiggIYJPOXzhOiDgpVCUHaUvyIC5/fj7C/p637jdzC666AOKQ==} + '@types/node@22.13.10': + resolution: {integrity: sha512-I6LPUvlRH+O6VRUqYOcMudhaIdUVWfsjnZavnsraHvpBwaEyMN29ry+0UVJhImYL16xsscu0aske3yA+uPOWfw==} '@types/picomatch@3.0.2': resolution: {integrity: sha512-n0i8TD3UDB7paoMMxA3Y65vUncFJXjcUf7lQY7YyKGl6031FNjfsLs6pdLFCy2GNFxItPJG8GvvpbZc2skH7WA==} @@ -1319,8 +1319,8 @@ packages: automated-readability@2.0.1: resolution: {integrity: sha512-/csT54oO/8qjtqaCZoNqA0srbHv3z1YAxj0ee4UQkYC7x6lb6jU0f9LIo7DLJKHWSEI4nsvnFyy34vILDqA7xw==} - autoprefixer@10.4.20: - resolution: {integrity: sha512-XY25y5xSv/wEoqzDyXXME4AFfkZI0P23z6Fs3YgymDnKJkCGOnkL0iTxCa85UTqaSgfcqyf3UA6+c7wUvx/16g==} + autoprefixer@10.4.21: + resolution: {integrity: sha512-O+A6LWV5LDHSJD3LjHYoNi4VLsj/Whi7k6zG12xTYaU4cQ8oxQGckXNX8cRHK5yOZ/ppVHe0ZBXGzSV9jXdVbQ==} engines: {node: ^10 || ^12 || >=14} hasBin: true peerDependencies: @@ -1443,6 +1443,9 @@ packages: caniuse-lite@1.0.30001699: resolution: {integrity: sha512-b+uH5BakXZ9Do9iK+CkDmctUSEqZl+SP056vc5usa0PL+ev5OHw003rZXcnjNDv3L8P5j6rwT6C0BPKSikW08w==} + caniuse-lite@1.0.30001703: + resolution: {integrity: sha512-kRlAGTRWgPsOj7oARC9m1okJEXdL/8fekFVcxA8Hl7GH4r/sN4OJn/i6Flde373T50KS7Y37oFbMwlE8+F42kQ==} + ccount@2.0.1: resolution: {integrity: sha512-eyrF0jiFpY+3drT6383f1qhkbGsLSifNAjA61IUjZjmLCWjItY6LB9ft9YhoDgwfmclB2zhu51Lc7+95b8NRAg==} @@ -5479,14 +5482,14 @@ snapshots: '@popperjs/core@2.11.8': {} - '@shopify/liquid-html-parser@2.6.0': + '@shopify/liquid-html-parser@2.7.0': dependencies: line-column: 1.0.2 ohm-js: 16.6.0 - '@shopify/prettier-plugin-liquid@1.8.3(prettier@3.5.3)': + '@shopify/prettier-plugin-liquid@1.9.0(prettier@3.5.3)': dependencies: - '@shopify/liquid-html-parser': 2.6.0 + '@shopify/liquid-html-parser': 2.7.0 html-styles: 1.0.0 prettier: 3.5.3 @@ -5509,13 +5512,13 @@ snapshots: '@types/concat-stream@2.0.3': dependencies: - '@types/node': 22.13.8 + '@types/node': 22.13.10 '@types/console-log-level@1.4.5': {} '@types/cors@2.8.17': dependencies: - '@types/node': 22.13.8 + '@types/node': 22.13.10 '@types/debug@4.1.12': dependencies: @@ -5531,13 +5534,13 @@ snapshots: '@types/glob-stream@8.0.2': dependencies: - '@types/node': 22.13.8 + '@types/node': 22.13.10 '@types/picomatch': 3.0.2 '@types/streamx': 2.9.5 '@types/gulp@4.0.17': dependencies: - '@types/node': 22.13.8 + '@types/node': 22.13.10 '@types/undertaker': 1.2.11 '@types/vinyl-fs': 3.0.5 chokidar: 3.6.0 @@ -5573,7 +5576,7 @@ snapshots: dependencies: '@types/unist': 3.0.3 - '@types/node@22.13.8': + '@types/node@22.13.10': dependencies: undici-types: 6.20.0 @@ -5583,7 +5586,7 @@ snapshots: '@types/streamx@2.9.5': dependencies: - '@types/node': 22.13.8 + '@types/node': 22.13.10 '@types/supports-color@8.1.3': {} @@ -5593,7 +5596,7 @@ snapshots: '@types/undertaker@1.2.11': dependencies: - '@types/node': 22.13.8 + '@types/node': 22.13.10 '@types/undertaker-registry': 1.0.4 async-done: 1.3.2 @@ -5604,13 +5607,13 @@ snapshots: '@types/vinyl-fs@3.0.5': dependencies: '@types/glob-stream': 8.0.2 - '@types/node': 22.13.8 + '@types/node': 22.13.10 '@types/vinyl': 2.0.12 '@types/vinyl@2.0.12': dependencies: '@types/expect': 1.20.4 - '@types/node': 22.13.8 + '@types/node': 22.13.10 '@ungap/structured-clone@1.3.0': {} @@ -5752,10 +5755,10 @@ snapshots: automated-readability@2.0.1: {} - autoprefixer@10.4.20(postcss@8.5.2): + autoprefixer@10.4.21(postcss@8.5.2): dependencies: browserslist: 4.24.4 - caniuse-lite: 1.0.30001699 + caniuse-lite: 1.0.30001703 fraction.js: 4.3.7 normalize-range: 0.1.2 picocolors: 1.1.1 @@ -5924,6 +5927,8 @@ snapshots: caniuse-lite@1.0.30001699: {} + caniuse-lite@1.0.30001703: {} + ccount@2.0.1: {} chalk-template@1.1.0: @@ -6466,7 +6471,7 @@ snapshots: engine.io@6.6.4: dependencies: '@types/cors': 2.8.17 - '@types/node': 22.13.8 + '@types/node': 22.13.10 accepts: 1.3.8 base64id: 2.0.0 cookie: 0.7.2 @@ -9910,7 +9915,7 @@ snapshots: '@types/concat-stream': 2.0.3 '@types/debug': 4.1.12 '@types/is-empty': 1.2.3 - '@types/node': 22.13.8 + '@types/node': 22.13.10 '@types/unist': 3.0.3 concat-stream: 2.0.0 debug: 4.4.0