diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index ab73c1ae..440cdaa6 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -29,12 +29,12 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@df559355d593797519d70b90fc8edd5db049e7a2 # v3.29.9 + uses: github/codeql-action/init@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11 with: languages: ${{ matrix.language }} queries: security-extended,security-and-quality - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@df559355d593797519d70b90fc8edd5db049e7a2 # v3.29.9 + uses: github/codeql-action/analyze@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11 with: category: '/language:${{matrix.language}}' diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index abec042a..b296cc82 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -16,7 +16,7 @@ jobs: env: SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }} container: - image: returntocorp/semgrep@sha256:6bd07d7b166b097e1384f41b94a62d8c8a26a4fff8713992c296e053310da01f # latest + image: returntocorp/semgrep@sha256:392824c9cff5fb434198992a5f05c5d4c658a99af3fa9a965f750bf50bee84af # latest steps: - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 - run: semgrep ci diff --git a/package.json b/package.json index 45ccd8dc..bd305f7d 100644 --- a/package.json +++ b/package.json @@ -3,10 +3,10 @@ "author": "The OpenINF Authors & Friends", "private": "true", "description": "The OpenINF portal, other static resources, and more static electricity", - "packageManager": "pnpm@10.14.0", + "packageManager": "pnpm@10.15.0", "engines": { "node": "22.18.0", - "pnpm": "10.14.0" + "pnpm": "10.15.0" }, "exports": { "./build/constants": "./build/shared/constants.mjs", @@ -29,7 +29,7 @@ "@cspell/dict-lorem-ipsum": "4.0.5", "@isaacs/catcher": "1.0.4", "@openinf/gh-file-importer": "2.0.1", - "@shopify/prettier-plugin-liquid": "1.9.3", + "@shopify/prettier-plugin-liquid": "1.9.4", "@tsconfig/node-lts": "22.0.2", "@types/console-log-level": "1.4.5", "@types/gulp": "4.0.17", @@ -42,7 +42,7 @@ "browserslist-lint": "0.3.3", "console-log-level": "1.4.1", "cspell": "9.2.0", - "cssnano": "7.1.0", + "cssnano": "7.1.1", "dictionary-en": "4.0.0", "dprint": "0.50.1", "editorconfig-checker": "6.1.0", @@ -106,7 +106,7 @@ "stylelint": "16.23.1", "stylelint-config-recess-order": "6.1.0", "stylelint-config-standard-scss": "14.0.0", - "tsx": "4.20.4", + "tsx": "4.20.5", "typescript": "5.9.2", "unified": "11.0.5", "vnu-jar": "24.10.17", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 2ede5370..1606b37c 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -24,8 +24,8 @@ importers: specifier: 2.0.1 version: 2.0.1 '@shopify/prettier-plugin-liquid': - specifier: 1.9.3 - version: 1.9.3(prettier@3.6.2) + specifier: 1.9.4 + version: 1.9.4(prettier@3.6.2) '@tsconfig/node-lts': specifier: 22.0.2 version: 22.0.2 @@ -63,8 +63,8 @@ importers: specifier: 9.2.0 version: 9.2.0 cssnano: - specifier: 7.1.0 - version: 7.1.0(postcss@8.5.6) + specifier: 7.1.1 + version: 7.1.1(postcss@8.5.6) dictionary-en: specifier: 4.0.0 version: 4.0.0 @@ -85,7 +85,7 @@ importers: version: 1.1.0 gulp-postcss: specifier: 10.0.0 - version: 10.0.0(postcss@8.5.6)(tsx@4.20.4) + version: 10.0.0(postcss@8.5.6)(tsx@4.20.5) gulp-rename: specifier: 2.1.0 version: 2.1.0 @@ -255,8 +255,8 @@ importers: specifier: 14.0.0 version: 14.0.0(postcss@8.5.6)(stylelint@16.23.1(typescript@5.9.2)) tsx: - specifier: 4.20.4 - version: 4.20.4 + specifier: 4.20.5 + version: 4.20.5 typescript: specifier: 5.9.2 version: 5.9.2 @@ -1029,8 +1029,8 @@ packages: '@shopify/liquid-html-parser@2.8.2': resolution: {integrity: sha512-g8DRcz4wUj4Ttxm+rK1qPuvIV2/ZqlyGRcVytVMbUkrr/+eVL2yQI/jRGDMeOamkRqB3InuoOjF7nARH+o9UYQ==} - '@shopify/prettier-plugin-liquid@1.9.3': - resolution: {integrity: sha512-XRRnwfONrzjW8AY/l39szH9OgCCg5Xx61QxxdrC3BT2RAqo229jomjhCEszGIUJ5YZYq1ewdyBwbvUVTUSTcTg==} + '@shopify/prettier-plugin-liquid@1.9.4': + resolution: {integrity: sha512-Xo4KC44jzyEl2FeBJUOS6mvNbfhhgCxtPH3185wYv9f88TwnSQE2LuyI93B8UuMBfjjQ+4+mzjcL+/92Ldfa2g==} peerDependencies: prettier: ^2.0.0 || ^3.0.0 @@ -1696,8 +1696,8 @@ packages: engines: {node: '>=4'} hasBin: true - cssnano-preset-default@7.0.8: - resolution: {integrity: sha512-d+3R2qwrUV3g4LEMOjnndognKirBZISylDZAF/TPeCWVjEwlXS2e4eN4ICkoobRe7pD3H6lltinKVyS1AJhdjQ==} + cssnano-preset-default@7.0.9: + resolution: {integrity: sha512-tCD6AAFgYBOVpMBX41KjbvRh9c2uUjLXRyV7KHSIrwHiq5Z9o0TFfUCoM3TwVrRsRteN3sVXGNvjVNxYzkpTsA==} engines: {node: ^18.12.0 || ^20.9.0 || >=22.0} peerDependencies: postcss: ^8.4.32 @@ -1708,8 +1708,8 @@ packages: peerDependencies: postcss: ^8.4.32 - cssnano@7.1.0: - resolution: {integrity: sha512-Pu3rlKkd0ZtlCUzBrKL1Z4YmhKppjC1H9jo7u1o4qaKqyhvixFgu5qLyNIAOjSTg9DjVPtUqdROq2EfpVMEe+w==} + cssnano@7.1.1: + resolution: {integrity: sha512-fm4D8ti0dQmFPeF8DXSAA//btEmqCOgAc/9Oa3C1LW94h5usNrJEfrON7b4FkPZgnDEn6OUs5NdxiJZmAtGOpQ==} engines: {node: ^18.12.0 || ^20.9.0 || >=22.0} peerDependencies: postcss: ^8.4.32 @@ -3293,8 +3293,8 @@ packages: peerDependencies: postcss: ^8.4.32 - postcss-convert-values@7.0.6: - resolution: {integrity: sha512-MD/eb39Mr60hvgrqpXsgbiqluawYg/8K4nKsqRsuDX9f+xN1j6awZCUv/5tLH8ak3vYp/EMXwdcnXvfZYiejCQ==} + postcss-convert-values@7.0.7: + resolution: {integrity: sha512-HR9DZLN04Xbe6xugRH6lS4ZQH2zm/bFh/ZyRkpedZozhvh+awAfbA0P36InO4fZfDhvYfNJeNvlTf1sjwGbw/A==} engines: {node: ^18.12.0 || ^20.9.0 || >=22.0} peerDependencies: postcss: ^8.4.32 @@ -4341,8 +4341,8 @@ packages: tslib@2.8.1: resolution: {integrity: sha512-oJFu94HQb+KVduSUQL7wnpmqnfmLsOA/nAh6b6EH0wCEoK0/mPeXU6c3wKDV83MkOuHPRHtSXKKU99IBazS/2w==} - tsx@4.20.4: - resolution: {integrity: sha512-yyxBKfORQ7LuRt/BQKBXrpcq59ZvSW0XxwfjAt3w2/8PmdxaFzijtMhTawprSHhpzeM5BgU2hXHG3lklIERZXg==} + tsx@4.20.5: + resolution: {integrity: sha512-+wKjMNU9w/EaQayHXb7WA7ZaHY6hN8WgfvHNQ3t1PnU91/7O8TcTnIhCDYTZwnt8JsO9IBqZ30Ln1r7pPF52Aw==} engines: {node: '>=18.0.0'} hasBin: true @@ -5415,7 +5415,7 @@ snapshots: line-column: 1.0.2 ohm-js: 16.6.0 - '@shopify/prettier-plugin-liquid@1.9.3(prettier@3.6.2)': + '@shopify/prettier-plugin-liquid@1.9.4(prettier@3.6.2)': dependencies: '@shopify/liquid-html-parser': 2.8.2 html-styles: 1.0.0 @@ -6157,7 +6157,7 @@ snapshots: cssesc@3.0.0: {} - cssnano-preset-default@7.0.8(postcss@8.5.6): + cssnano-preset-default@7.0.9(postcss@8.5.6): dependencies: browserslist: 4.25.2 css-declaration-sorter: 7.2.0(postcss@8.5.6) @@ -6165,7 +6165,7 @@ snapshots: postcss: 8.5.6 postcss-calc: 10.1.1(postcss@8.5.6) postcss-colormin: 7.0.4(postcss@8.5.6) - postcss-convert-values: 7.0.6(postcss@8.5.6) + postcss-convert-values: 7.0.7(postcss@8.5.6) postcss-discard-comments: 7.0.4(postcss@8.5.6) postcss-discard-duplicates: 7.0.2(postcss@8.5.6) postcss-discard-empty: 7.0.1(postcss@8.5.6) @@ -6195,9 +6195,9 @@ snapshots: dependencies: postcss: 8.5.6 - cssnano@7.1.0(postcss@8.5.6): + cssnano@7.1.1(postcss@8.5.6): dependencies: - cssnano-preset-default: 7.0.8(postcss@8.5.6) + cssnano-preset-default: 7.0.9(postcss@8.5.6) lilconfig: 3.1.3 postcss: 8.5.6 @@ -6809,12 +6809,12 @@ snapshots: through2: 2.0.5 vinyl-sourcemaps-apply: 0.2.1 - gulp-postcss@10.0.0(postcss@8.5.6)(tsx@4.20.4): + gulp-postcss@10.0.0(postcss@8.5.6)(tsx@4.20.5): dependencies: fancy-log: 2.0.0 plugin-error: 2.0.1 postcss: 8.5.6 - postcss-load-config: 5.1.0(postcss@8.5.6)(tsx@4.20.4) + postcss-load-config: 5.1.0(postcss@8.5.6)(tsx@4.20.5) vinyl-sourcemaps-apply: 0.2.1 transitivePeerDependencies: - jiti @@ -8070,7 +8070,7 @@ snapshots: postcss: 8.5.6 postcss-value-parser: 4.2.0 - postcss-convert-values@7.0.6(postcss@8.5.6): + postcss-convert-values@7.0.7(postcss@8.5.6): dependencies: browserslist: 4.25.2 postcss: 8.5.6 @@ -8093,13 +8093,13 @@ snapshots: dependencies: postcss: 8.5.6 - postcss-load-config@5.1.0(postcss@8.5.6)(tsx@4.20.4): + postcss-load-config@5.1.0(postcss@8.5.6)(tsx@4.20.5): dependencies: lilconfig: 3.1.3 yaml: 2.8.1 optionalDependencies: postcss: 8.5.6 - tsx: 4.20.4 + tsx: 4.20.5 postcss-media-query-parser@0.2.3: {} @@ -9716,7 +9716,7 @@ snapshots: tslib@2.8.1: {} - tsx@4.20.4: + tsx@4.20.5: dependencies: esbuild: 0.25.9 get-tsconfig: 4.10.1