Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps) Updated packages for security vulnerabilities #4035

Closed
wants to merge 61 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
bf13bdb
:arrow_up: Bump pymdown-extensions from 9.9 to 10.0 in /docs/mkdocs
dependabot[bot] May 15, 2023
362aded
Merge pull request #5 from sarvex/dependabot/pip/docs/mkdocs/pymdown-…
sarvex May 19, 2023
0e93717
:arrow_up: Bump gitpython from 3.1.29 to 3.1.30 in /docs/mkdocs
dependabot[bot] May 19, 2023
ceab478
Create renovate.json
sarvex May 19, 2023
68b684e
Merge pull request #6 from sarvex/dependabot/pip/docs/mkdocs/gitpytho…
sarvex May 19, 2023
0deb90c
Create codeql.yml
sarvex May 19, 2023
dc1797e
:arrow_up: Bump requests from 2.28.1 to 2.31.0 in /docs/mkdocs
dependabot[bot] May 23, 2023
8a1756f
Merge pull request #7 from sarvex/dependabot/pip/docs/mkdocs/requests…
sarvex May 25, 2023
f618d33
Merge branch 'nlohmann:develop' into main
sarvex May 25, 2023
84c2895
:arrow_up: Bump tornado from 6.2 to 6.3.2 in /docs/mkdocs
dependabot[bot] May 25, 2023
d9a6945
Merge pull request #8 from sarvex/dependabot/pip/docs/mkdocs/tornado-…
sarvex May 26, 2023
4bcd79d
Merge branch 'nlohmann:develop' into main
sarvex Jul 17, 2023
7a3cf57
:arrow_up: Bump pygments from 2.13.0 to 2.15.0 in /docs/mkdocs
dependabot[bot] Jul 20, 2023
d588e54
:arrow_up: Bump certifi from 2022.12.7 to 2023.7.22 in /docs/mkdocs
dependabot[bot] Jul 25, 2023
1c5414a
:arrow_up: Bump gitpython from 3.1.30 to 3.1.32 in /docs/mkdocs
dependabot[bot] Aug 11, 2023
dc055b0
Merge pull request #11 from sarvex/dependabot/pip/docs/mkdocs/gitpyth…
sarvex Aug 14, 2023
3d654aa
:arrow_up: Bump tornado from 6.3.2 to 6.3.3 in /docs/mkdocs
dependabot[bot] Aug 14, 2023
b79118a
Merge pull request #12 from sarvex/dependabot/pip/docs/mkdocs/tornado…
sarvex Aug 20, 2023
980bcb4
Merge pull request #10 from sarvex/dependabot/pip/docs/mkdocs/certifi…
sarvex Aug 30, 2023
b977b84
Merge pull request #9 from sarvex/dependabot/pip/docs/mkdocs/pygments…
sarvex Aug 30, 2023
604d094
Merge branch 'nlohmann:develop' into main
sarvex Aug 30, 2023
12cbe05
Bump gitpython from 3.1.32 to 3.1.34 in /docs/mkdocs
dependabot[bot] Sep 6, 2023
9da1f5d
Merge pull request #13 from sarvex/dependabot/pip/docs/mkdocs/gitpyth…
sarvex Sep 10, 2023
1f1dae0
Bump gitpython from 3.1.34 to 3.1.35 in /docs/mkdocs
dependabot[bot] Sep 10, 2023
b01443e
Merge pull request #14 from sarvex/dependabot/pip/docs/mkdocs/gitpyth…
sarvex Sep 10, 2023
bc1ad98
Bump urllib3 from 1.26.13 to 1.26.17 in /docs/mkdocs
dependabot[bot] Oct 3, 2023
57456b9
Merge pull request #15 from sarvex/dependabot/pip/docs/mkdocs/urllib3…
sarvex Oct 8, 2023
a9e8503
Merge branch 'nlohmann:develop' into main
sarvex Oct 10, 2023
8f9b9a8
Bump gitpython from 3.1.35 to 3.1.37 in /docs/mkdocs
dependabot[bot] Oct 10, 2023
40a3d0a
Merge pull request #16 from sarvex/dependabot/pip/docs/mkdocs/gitpyth…
sarvex Oct 11, 2023
d6a84e6
Bump urllib3 from 1.26.17 to 1.26.18 in /docs/mkdocs
dependabot[bot] Oct 18, 2023
80e260c
Merge pull request #17 from sarvex/dependabot/pip/docs/mkdocs/urllib3…
sarvex Oct 19, 2023
eb0b67b
Merge branch 'nlohmann:develop' into main
sarvex Oct 29, 2023
f83849e
Update dependency GitPython to v3.1.40
renovate[bot] Oct 29, 2023
634bbb1
Merge pull request #19 from sarvex/renovate/gitpython-3.x
sarvex Oct 29, 2023
fbca2cf
Update actions/github-script action to v6.4.1
renovate[bot] Oct 29, 2023
e402c98
Update dependency PyYAML to v6.0.1
renovate[bot] Oct 29, 2023
012b533
Merge pull request #18 from sarvex/renovate/actions-github-script-6.x
sarvex Oct 29, 2023
733987f
Merge pull request #22 from sarvex/renovate/pyyaml-6.x
sarvex Oct 29, 2023
a3af52b
Update dependency MarkupSafe to v2.1.3
renovate[bot] Oct 29, 2023
44702e5
Merge pull request #21 from sarvex/renovate/markupsafe-2.x
sarvex Oct 29, 2023
b563f99
Update dependency mkdocs-redirects to v1.2.1
renovate[bot] Oct 29, 2023
d4440f6
Merge pull request #26 from sarvex/renovate/mkdocs-redirects-1.x
sarvex Oct 29, 2023
e9c07ce
Update dependency gitdb to v4.0.11
renovate[bot] Oct 29, 2023
a36b7bf
Update dependency pytz to v2022.7.1
renovate[bot] Oct 29, 2023
78f6e40
Merge pull request #24 from sarvex/renovate/gitdb-4.x
sarvex Oct 29, 2023
28188b7
Merge pull request #28 from sarvex/renovate/pytz-2022.x
sarvex Oct 29, 2023
6634bb8
Update dependency nltk to v3.8.1
renovate[bot] Oct 29, 2023
6cb61d8
Merge pull request #27 from sarvex/renovate/nltk-3.x
sarvex Oct 29, 2023
f2a2a14
Update dependency markdown-include to v0.8.1
renovate[bot] Oct 29, 2023
60d1139
Merge pull request #25 from sarvex/renovate/markdown-include-0.x
sarvex Oct 29, 2023
9f2d53e
Update dependency smmap to v5.0.1
renovate[bot] Oct 29, 2023
ddda0db
Update dependency Babel to v2.13.1
renovate[bot] Oct 29, 2023
e1ece30
Merge pull request #30 from sarvex/renovate/babel-2.x
sarvex Oct 29, 2023
bc8f4f8
Merge pull request #29 from sarvex/renovate/smmap-5.x
sarvex Oct 29, 2023
7b311cf
Update dependency click to v8.1.7
renovate[bot] Oct 29, 2023
42e72f0
Merge pull request #23 from sarvex/renovate/click-8.x
sarvex Oct 29, 2023
e798e18
Bump gitpython from 3.1.40 to 3.1.41 in /docs/mkdocs
dependabot[bot] Jan 10, 2024
fad57ee
Bump jinja2 from 3.1.2 to 3.1.3 in /docs/mkdocs
dependabot[bot] Jan 11, 2024
697567b
Merge pull request #38 from sarvex/dependabot/pip/docs/mkdocs/jinja2-…
sarvex Jan 12, 2024
1e00c62
Merge pull request #37 from sarvex/dependabot/pip/docs/mkdocs/gitpyth…
sarvex Jan 12, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
76 changes: 76 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL"

on:
push:
branches: [ "main" ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ "main" ]
schedule:
- cron: '40 20 * * 1'

jobs:
analyze:
name: Analyze
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
permissions:
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [ 'cpp', 'python' ]
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ]
# Use only 'java' to analyze code written in Java, Kotlin or both
# Use only 'javascript' to analyze code written in JavaScript, TypeScript or both
# Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support

steps:
- name: Checkout repository
uses: actions/checkout@v3

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v2
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.

# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
# queries: security-extended,security-and-quality


# Autobuild attempts to build any compiled languages (C/C++, C#, Go, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v2

# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun

# If the Autobuild fails above, remove it and uncomment the following three lines.
# modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.

# - run: |
# echo "Run, Build Application using script"
# ./location_of_script_within_repo/buildscript.sh

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
with:
category: "/language:${{matrix.language}}"
4 changes: 2 additions & 2 deletions .github/workflows/comment_check_amalgamation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
pull-requests: write
steps:
- name: 'Download artifact'
uses: actions/github-script@98814c53be79b1d30f795b907e553d8679345975 # v6.4.0
uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6.4.1
with:
script: |
var artifacts = await github.rest.actions.listWorkflowRunArtifacts({
Expand All @@ -40,7 +40,7 @@ jobs:
- run: unzip pr.zip

- name: 'Comment on PR'
uses: actions/github-script@98814c53be79b1d30f795b907e553d8679345975 # v6.4.0
uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6.4.1
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
Expand Down
36 changes: 18 additions & 18 deletions docs/mkdocs/requirements.txt
Original file line number Diff line number Diff line change
@@ -1,49 +1,49 @@
Babel==2.11.0
certifi==2022.12.7
Babel==2.13.1
certifi==2023.7.22
charset-normalizer==2.1.1
click==8.1.3
click==8.1.7
csscompressor==0.9.5
future==0.18.3
ghp-import==2.1.0
gitdb==4.0.10
GitPython==3.1.29
gitdb==4.0.11
GitPython==3.1.41
htmlmin==0.1.12
httplib2==0.21.0
idna==3.4
importlib-metadata==5.1.0
Jinja2==3.1.2
Jinja2==3.1.3
joblib==1.2.0
jsmin==3.0.1
livereload==2.6.3
lunr==0.6.2
Markdown==3.3.7 # we cannot install a more recent version yet as mkdocs 1.4.2 depends on markdown<3.4
markdown-include==0.8.0
MarkupSafe==2.1.1
markdown-include==0.8.1
MarkupSafe==2.1.3
mergedeep==1.3.4
mkdocs==1.4.2
mkdocs-git-revision-date-localized-plugin==1.1.0
mkdocs-material==8.5.11
mkdocs-material-extensions==1.1.1
mkdocs-minify-plugin==0.6.2
mkdocs-redirects==1.2.0
mkdocs-redirects==1.2.1
mkdocs-simple-hooks==0.1.5
nltk==3.8
nltk==3.8.1
packaging==22.0
plantuml==0.3.0
plantuml-markdown==3.7.3
Pygments==2.13.0
pymdown-extensions==9.9
Pygments==2.15.0
pymdown-extensions==10.0
pyparsing==3.0.9
python-dateutil==2.8.2
pytz==2022.7
PyYAML==6.0
pytz==2022.7.1
PyYAML==6.0.1
pyyaml_env_tag==0.1
regex==2022.10.31
requests==2.28.1
requests==2.31.0
six==1.16.0
smmap==5.0.0
tornado==6.2
smmap==5.0.1
tornado==6.3.3
tqdm==4.64.1
urllib3==1.26.13
urllib3==1.26.18
watchdog==2.2.0
zipp==3.11.0
3 changes: 3 additions & 0 deletions renovate.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"extends": ["github>sarvex/renovate-configs:cpp"]
}
2 changes: 1 addition & 1 deletion tools/serve_header/requirements.txt
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
PyYAML==6.0
PyYAML==6.0.1
watchdog==2.1.7