Jim Kane
902c3ad313
Bump eslint from ^8.56.0 to ^8.57.0 to satisfy @typescript-eslint peer deps
2026-03-13 14:35:20 -05:00
Jim Kane
bf00a58d83
Upgrade eslint toolchain to fix minimatch vulnerabilities
...
Upgrade @typescript-eslint/* (6.x→8.x), eslint-plugin-github (4.x→5.x),
and eslint-plugin-jest (27.x→28.x) to resolve minimatch 9.0.0–9.0.6
ReDoS vulnerabilities. Remove deprecated eslint rules that were moved to
@stylistic in @typescript-eslint v8 (func-call-spacing, semi,
type-annotation-spacing, camelcase) and rename no-empty-interface to
no-empty-object-type. Resolves all remaining npm audit vulnerabilities.
2026-03-13 13:26:50 -05:00
Jim Kane
ed72718963
Upgrade @actions/* packages to fix undici vulnerability
...
Upgrade @actions/core (1.x→2.x), @actions/exec (1.x→2.x), and
@actions/github (6.0.0→8.0.1) to resolve undici <6.23.0 unbounded
decompression chain vulnerability. Add skipLibCheck to tsconfig.json
for compatibility with @octokit/core@7 type declarations.
2026-03-13 13:19:08 -05:00
dependabot[bot]
ecb2e254c2
Bump prettier from 2.8.8 to 3.8.1
...
Bumps [prettier](https://github.com/prettier/prettier ) from 2.8.8 to 3.8.1.
- [Release notes](https://github.com/prettier/prettier/releases )
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md )
- [Commits](https://github.com/prettier/prettier/compare/2.8.8...3.8.1 )
---
updated-dependencies:
- dependency-name: prettier
dependency-version: 3.8.1
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-13 12:31:40 -05:00
dependabot[bot]
e61913c25f
Bump @vercel/ncc from 0.38.1 to 0.38.4
...
Bumps [@vercel/ncc](https://github.com/vercel/ncc ) from 0.38.1 to 0.38.4.
- [Release notes](https://github.com/vercel/ncc/releases )
- [Commits](https://github.com/vercel/ncc/compare/0.38.1...0.38.4 )
---
updated-dependencies:
- dependency-name: "@vercel/ncc"
dependency-version: 0.38.4
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-13 12:16:40 -05:00
dependabot[bot]
9540bef0d9
Bump jest-circus from 29.7.0 to 30.2.0
...
Bumps [jest-circus](https://github.com/jestjs/jest/tree/HEAD/packages/jest-circus ) from 29.7.0 to 30.2.0.
- [Release notes](https://github.com/jestjs/jest/releases )
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jestjs/jest/commits/v30.2.0/packages/jest-circus )
---
updated-dependencies:
- dependency-name: jest-circus
dependency-version: 30.2.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-13 12:07:32 -05:00
dependabot[bot]
77d41cf00c
Bump jest and @types/jest
...
Bumps [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest ) and [@types/jest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/jest ). These dependencies needed to be updated together.
Updates `jest` from 29.7.0 to 30.2.0
- [Release notes](https://github.com/jestjs/jest/releases )
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jestjs/jest/commits/v30.2.0/packages/jest )
Updates `@types/jest` from 29.5.11 to 30.0.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/jest )
---
updated-dependencies:
- dependency-name: jest
dependency-version: 30.2.0
dependency-type: direct:development
update-type: version-update:semver-major
- dependency-name: "@types/jest"
dependency-version: 30.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-13 12:01:52 -05:00
dependabot[bot]
8cfe3ef770
Bump ts-jest from 29.1.2 to 29.4.6
...
Bumps [ts-jest](https://github.com/kulshekhar/ts-jest ) from 29.1.2 to 29.4.6.
- [Release notes](https://github.com/kulshekhar/ts-jest/releases )
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md )
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.1.2...v29.4.6 )
---
updated-dependencies:
- dependency-name: ts-jest
dependency-version: 29.4.6
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-13 11:54:18 -05:00
dependabot[bot]
e4202729dc
Bump @types/node from 24.12.0 to 25.3.5
...
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) from 24.12.0 to 25.3.5.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.3.5
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-13 11:46:56 -05:00
Jim Kane
574b2dd533
Update undici to 5.29
...
Apply a minor update for some security fixes.
2026-03-13 11:04:49 -05:00
Jim Kane
100f86e19c
Update minimatch to 3.1.5
2026-03-13 11:04:49 -05:00
Sascha Bratton
3ff8f27d73
feat: update action runtime to node24
2026-03-13 10:34:06 -05:00
Jim Kane
35e46e8bd7
Revert "Bump js-yaml"
...
This reverts commit b5fede031a .
2026-03-13 10:34:06 -05:00
Jim Kane
a9a7242588
Revert "Bump the npm_and_yarn group across 1 directory with 4 updates"
...
This reverts commit 830398a356 .
2026-03-13 10:34:06 -05:00
Jim Kane
8ae120554f
Revert "Bump ts-jest from 29.1.2 to 29.4.6"
...
This reverts commit 70697a7a15 .
2026-03-13 10:34:06 -05:00
Jim Kane
ff146a16a3
Revert "Bump @types/node from 20.11.6 to 25.3.3"
...
This reverts commit 6db5b1d3ff .
2026-03-13 10:34:06 -05:00
Jim Kane
2afba9d1bc
Revert "Bump @actions/core from 1.10.1 to 3.0.0"
...
This reverts commit c39dd878c0 .
2026-03-13 10:34:06 -05:00
dependabot[bot]
c39dd878c0
Bump @actions/core from 1.10.1 to 3.0.0
...
Bumps [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core ) from 1.10.1 to 3.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core )
---
updated-dependencies:
- dependency-name: "@actions/core"
dependency-version: 3.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-10 16:04:37 -05:00
dependabot[bot]
6db5b1d3ff
Bump @types/node from 20.11.6 to 25.3.3
...
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) from 20.11.6 to 25.3.3.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.3.3
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-10 14:57:58 -05:00
dependabot[bot]
70697a7a15
Bump ts-jest from 29.1.2 to 29.4.6
...
Bumps [ts-jest](https://github.com/kulshekhar/ts-jest ) from 29.1.2 to 29.4.6.
- [Release notes](https://github.com/kulshekhar/ts-jest/releases )
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md )
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.1.2...v29.4.6 )
---
updated-dependencies:
- dependency-name: ts-jest
dependency-version: 29.4.6
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-10 14:52:18 -05:00
dependabot[bot]
830398a356
Bump the npm_and_yarn group across 1 directory with 4 updates
...
Bumps the npm_and_yarn group with 3 updates in the / directory: [@octokit/plugin-paginate-rest](https://github.com/octokit/plugin-paginate-rest.js ), [@octokit/request](https://github.com/octokit/request.js ) and [braces](https://github.com/micromatch/braces ).
Updates `@octokit/plugin-paginate-rest` from 9.1.5 to 9.2.2
- [Release notes](https://github.com/octokit/plugin-paginate-rest.js/releases )
- [Commits](https://github.com/octokit/plugin-paginate-rest.js/compare/v9.1.5...v9.2.2 )
Updates `@octokit/request` from 8.1.6 to 8.4.1
- [Release notes](https://github.com/octokit/request.js/releases )
- [Commits](https://github.com/octokit/request.js/compare/v8.1.6...v8.4.1 )
Updates `@octokit/request-error` from 5.0.1 to 5.1.1
- [Release notes](https://github.com/octokit/request-error.js/releases )
- [Commits](https://github.com/octokit/request-error.js/compare/v5.0.1...v5.1.1 )
Updates `braces` from 3.0.2 to 3.0.3
- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md )
- [Commits](https://github.com/micromatch/braces/compare/3.0.2...3.0.3 )
---
updated-dependencies:
- dependency-name: "@octokit/plugin-paginate-rest"
dependency-version: 9.2.2
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: "@octokit/request"
dependency-version: 8.4.1
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: "@octokit/request-error"
dependency-version: 5.1.1
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: braces
dependency-version: 3.0.3
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-10 13:44:51 -05:00
dependabot[bot]
b5fede031a
Bump js-yaml
...
Bumps [js-yaml](https://github.com/nodeca/js-yaml ) to 4.1.1 and updates ancestor dependency . These dependencies need to be updated together.
Updates `js-yaml` from 4.1.0 to 4.1.1
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md )
- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.0...4.1.1 )
Updates `js-yaml` from 3.14.1 to 3.14.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md )
- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.0...4.1.1 )
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.1.1
dependency-type: direct:development
- dependency-name: js-yaml
dependency-version: 3.14.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-03-10 13:38:31 -05:00
Michal Dorner
2f74457227
Update all dependencies
2024-01-24 22:50:18 +01:00
Michal Dorner
8ec7be4734
Update to nodejs 20
2023-12-04 20:54:44 +01:00
Michal Dorner
513ea69ce3
Update @actions/core to v1.10.0
...
See https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
2022-10-12 21:15:02 +02:00
Michal Dorner
ce8f47aa7f
Fix incorrect handling of Unicode characters in exec()
2022-10-11 23:01:54 +02:00
Michal Dorner
17e486d015
Update eslint package
2022-06-09 22:36:15 +02:00
JJ Merelo
38e0a049f6
⬆️ in a number of deps
...
To take care of deprecated upstream deps and somesuch
2022-02-01 07:55:41 +01:00
JJ Merelo
b55f63c13c
Fix resulting dep errors 🐛
2022-02-01 07:48:18 +01:00
JJ Merelo
816eb040ab
Run audit fix with --force
2022-02-01 07:38:06 +01:00
Michal Dorner
b4eabb6049
Use picomatch + impl followups from #48
2020-11-09 00:45:53 +01:00
Michal Dorner
b37d4e9e86
Use micromatch instead of minimatch ( #46 )
...
* Use micromatch instead of minimatch
micromatch claims to support full Bash 4.3 spec and it actually passes all the tests.
For example this fixes processing of '!(**/*.tsx|**/*.less)' pattern - needed by #45
* Update CHANGELOG.md
2020-10-23 12:33:44 +02:00
Michal Dorner
7d201829e2
Support reusable paths blocks via yaml anchors ( #13 )
...
* Add support for nested arrays of path expressions
* Remove pull_request trigger type options
Default value is fine: opened, synchronize, reopened
* Add CHANGELOG
* Update README
2020-06-19 23:39:06 +02:00
Michal Dorner
1cbb925a17
Change detection via git + rename githubToken to token ( #9 )
2020-05-26 17:16:09 +02:00
Michal Dorner
0c9e16cc6d
Update dependencies ( #6 )
2020-05-23 14:23:31 +02:00
Michal Dorner
29d498d99d
Fix globbing, update metadata, update ncc ( #4 )
...
* Enable minimatch dot option
It's not a default globbing behavior, however for our use-case is much more convenient to match those files.
* Update README and package.json
2020-05-21 13:46:48 +02:00
Michal Dorner
4e726dd036
Implement fetching, filtering and tests
2020-05-21 00:31:16 +02:00
dependabot[bot]
d475d5da26
Bump acorn from 5.7.3 to 5.7.4 ( #1 )
...
Bumps [acorn](https://github.com/acornjs/acorn ) from 5.7.3 to 5.7.4.
- [Release notes](https://github.com/acornjs/acorn/releases )
- [Commits](https://github.com/acornjs/acorn/compare/5.7.3...5.7.4 )
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2020-05-20 17:05:57 +02:00
Michal Dorner
b78de5e86b
Initial commit
2020-05-20 17:03:08 +02:00