Skip to content

Commit 8076182

Browse files
authored
Edge Library Updates (#308)
* Edge Library Updates - updated cookiejar to 2.1.4 - updated json5 to 2.2.3 Signed-off-by: David Deal <[email protected]> * CI/CD - Added Edge Folder Scanning Signed-off-by: David Deal <[email protected]> Signed-off-by: David Deal <[email protected]>
1 parent f8f5572 commit 8076182

File tree

4 files changed

+84
-12
lines changed

4 files changed

+84
-12
lines changed
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
---
2+
# Copyright The Linux Foundation and each contributor to CommunityBridge.
3+
# SPDX-License-Identifier: MI
4+
5+
name: Snyk Scan Edge NPM Dependencies
6+
7+
on:
8+
# https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions
9+
pull_request:
10+
branches:
11+
- main
12+
13+
jobs:
14+
snyk-scan-edge-npm-pr:
15+
runs-on: ubuntu-latest
16+
environment: dev
17+
steps:
18+
- uses: actions/checkout@v3
19+
- uses: snyk/actions/setup@master
20+
id: snyk
21+
- name: Setup Node
22+
uses: actions/setup-node@v3
23+
with:
24+
node-version: '14'
25+
- name: Yarn Version
26+
run: yarn --version
27+
- name: Yarn Install
28+
working-directory: src
29+
run: yarn install
30+
- name: Snyk version
31+
run: echo "${{ steps.snyk.outputs.version }}"
32+
- name: Scan for NPM Vulnerabilities
33+
working-directory: src
34+
run: |
35+
snyk test --org=${{ secrets.SNYK_ORG }} --file=package.json
36+
env:
37+
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
38+
continue-on-error: true
39+
- name: Monitor for NPM Vulnerabilities
40+
working-directory: src
41+
run: snyk monitor --org=${{ secrets.SNYK_ORG }} --file=package.json
42+
env:
43+
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
44+
continue-on-error: true
Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
---
2+
# Copyright The Linux Foundation and each contributor to CommunityBridge.
3+
# SPDX-License-Identifier: MI
4+
5+
name: Yarn Edge Dependency Audit
6+
7+
on:
8+
# https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions
9+
pull_request:
10+
branches:
11+
- main
12+
13+
jobs:
14+
yarn-scan-edge-pr:
15+
runs-on: ubuntu-latest
16+
environment: dev
17+
steps:
18+
- uses: actions/checkout@v3
19+
- name: Setup Node
20+
uses: actions/setup-node@v3
21+
with:
22+
node-version: '14'
23+
- name: Setup
24+
run: yarn install
25+
- name: Yarn Audit
26+
working-directory: src
27+
run: |
28+
yarn audit

edge/package.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,10 +25,12 @@
2525
"resolutions": {
2626
"ansi-regex": "^5.0.1",
2727
"browserslist": "^4.16.5",
28+
"cookiejar": "^2.1.4",
2829
"dns-packet": "^5.2.2",
2930
"hosted-git-info": "^3.0.8",
3031
"ini": "^1.3.7",
3132
"glob-parent": "^5.1.2",
33+
"json5": "^2.2.3",
3234
"jszip": "^3.7.0",
3335
"netmask": "^2.0.1",
3436
"minimatch": "^3.0.5",

edge/yarn.lock

Lines changed: 10 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -922,6 +922,11 @@ convert-source-map@^1.5.1:
922922
dependencies:
923923
safe-buffer "~5.1.1"
924924

925+
cookiejar@^2.1.4:
926+
version "2.1.4"
927+
resolved "https://registry.yarnpkg.com/cookiejar/-/cookiejar-2.1.4.tgz#ee669c1fea2cf42dc31585469d193fef0d65771b"
928+
integrity sha512-LDx6oHrK+PhzLKJU9j5S7/Y3jM/mUHvD/DeI1WQmJn652iPC5Y4TBzC9l+5OMOXlyTTA+SmVUPm0HQUwpD5Jqw==
929+
925930
copy-concurrently@^1.0.0:
926931
version "1.0.5"
927932
resolved "https://registry.yarnpkg.com/copy-concurrently/-/copy-concurrently-1.0.5.tgz#92297398cae34937fcafd6ec8139c18051f0b5e0"
@@ -2055,17 +2060,10 @@ json-stable-stringify-without-jsonify@^1.0.1:
20552060
resolved "https://registry.yarnpkg.com/json-stable-stringify-without-jsonify/-/json-stable-stringify-without-jsonify-1.0.1.tgz#9db7b59496ad3f3cfef30a75142d2d930ad72651"
20562061
integrity sha1-nbe1lJatPzz+8wp1FC0tkwrXJlE=
20572062

2058-
json5@^0.5.1:
2059-
version "0.5.1"
2060-
resolved "https://registry.yarnpkg.com/json5/-/json5-0.5.1.tgz#1eade7acc012034ad84e2396767ead9fa5495821"
2061-
integrity sha1-Hq3nrMASA0rYTiOWdn6tn6VJWCE=
2062-
2063-
json5@^1.0.1:
2064-
version "1.0.1"
2065-
resolved "https://registry.yarnpkg.com/json5/-/json5-1.0.1.tgz#779fb0018604fa854eacbf6252180d83543e3dbe"
2066-
integrity sha512-aKS4WQjPenRxiQsC93MNfjx+nbF4PAdYzmd/1JIj8HYzqfbu86beTuNgXDzPknWk0n0uARlyewZo4s++ES36Ow==
2067-
dependencies:
2068-
minimist "^1.2.0"
2063+
json5@^0.5.1, json5@^1.0.1, json5@^2.2.3:
2064+
version "2.2.3"
2065+
resolved "https://registry.yarnpkg.com/json5/-/json5-2.2.3.tgz#78cd6f1a19bdc12b73db5ad0c61efd66c1e29283"
2066+
integrity sha512-XmOWe7eyHYH14cLdVPoyg+GOH3rYX++KpzrylJwSW98t3Nk+U8XOl8FWKOgwtzdb8lXGf6zYwDUzeHMWfxasyg==
20692067

20702068
jszip@^3.7.0:
20712069
version "3.7.1"
@@ -2276,7 +2274,7 @@ minimatch@^3.0.4, minimatch@^3.0.5:
22762274
dependencies:
22772275
brace-expansion "^1.1.7"
22782276

2279-
minimist@^1.2.0, minimist@^1.2.5:
2277+
minimist@^1.2.5:
22802278
version "1.2.7"
22812279
resolved "https://registry.yarnpkg.com/minimist/-/minimist-1.2.7.tgz#daa1c4d91f507390437c6a8bc01078e7000c4d18"
22822280
integrity sha512-bzfL1YUZsP41gmu/qjrEk0Q6i2ix/cVeAhbCbqH9u3zYutS1cLg00qhrD0M2MVdCcx4Sc0UpP2eBWo9rotpq6g==

0 commit comments

Comments
 (0)