From 01d54889e209ca7afd58f7203f1b572948d439f0 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 04:14:14 +0000 Subject: [PATCH] chore(deps): bump the github-actions-dependencies group across 1 directory with 2 updates Bumps the github-actions-dependencies group with 2 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.38.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-dependencies - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-dependencies ... Signed-off-by: dependabot[bot] Signed-off-by: Emilien Escalle --- .github/workflows/__shared-ci.yml | 4 --- .github/workflows/continuous-integration.yml | 4 +-- tests/pnpm/pnpm-lock.yaml | 31 +++++++++++++------- 3 files changed, 23 insertions(+), 16 deletions(-) diff --git a/.github/workflows/__shared-ci.yml b/.github/workflows/__shared-ci.yml index 59c09a5..3167ff0 100644 --- a/.github/workflows/__shared-ci.yml +++ b/.github/workflows/__shared-ci.yml @@ -16,10 +16,6 @@ jobs: pull-requests: write security-events: write statuses: write - with: - # FIXME: Remove this once JS deps will be updated to versions that do not trigger Trivy vulnerabilities - linter-env: | - VALIDATE_TRIVY=false test-action-dependencies-cache: name: Test action "dependencies-cache" diff --git a/.github/workflows/continuous-integration.yml b/.github/workflows/continuous-integration.yml index 0b095d6..227fcfd 100644 --- a/.github/workflows/continuous-integration.yml +++ b/.github/workflows/continuous-integration.yml @@ -294,10 +294,10 @@ jobs: runs-on: *ci-runner steps: - uses: hoverkraft-tech/ci-github-common/actions/checkout@3a27d31e9ccefbe9609cc9165017ed100ff34a22 # 0.38.0 - - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + - uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: ${{ inputs.code-ql }} - - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + - uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 dependency-review: name: 🛡️ Dependency Review diff --git a/tests/pnpm/pnpm-lock.yaml b/tests/pnpm/pnpm-lock.yaml index d3a4391..4bcf592 100644 --- a/tests/pnpm/pnpm-lock.yaml +++ b/tests/pnpm/pnpm-lock.yaml @@ -3524,6 +3524,10 @@ packages: resolution: {integrity: sha512-yki5XnKuf750l50uGTllt6kKILY4nQ1eNIQatoXEByZ5dWgnKqbnqmTrBE5B4N7lrMJKQ2ytWMiTO2o0v6Ew/w==} engines: {node: '>= 0.6'} + cookie@2.0.1: + resolution: {integrity: sha512-yuToqVvRrj6pfDXREyQAAv8SkAEk/8GS3jQRTiUMm66TVtBYmqQeoEjL2Lmq8Rpo6271vH76InTChTitEAm65w==} + engines: {node: '>=22'} + core-js-compat@3.31.0: resolution: {integrity: sha512-hM7YCu1cU6Opx7MXNu0NuumM0ezNeAeRKadixyiQELWY3vT3De9S4J5ZBMraWV2vZnrE1Cirl0GtFtDtMUXzPw==} @@ -3876,8 +3880,8 @@ packages: engines: {node: '>=0.12.18'} hasBin: true - electron-to-chromium@1.5.442: - resolution: {integrity: sha512-najZYZ3+ZpjN1z3VOsrBiv5ej18vQgfV2lvEmxWzfmKrk4bdm3Owseyud4yGU6DfFn9pyunoAHDDyM4KmP78Ew==} + electron-to-chromium@1.5.443: + resolution: {integrity: sha512-TDJG36L9A3CWWwZ97HKaE+Iz1sW80pNp6sAU0owzCIV3Zc9eVyRqZK8Vz6NKuMIU8WjP0pIkoqCa0VRf/yFD0Q==} emittery@0.13.1: resolution: {integrity: sha512-DeWwawk6r5yR9jFgnDKYt4sLS0LmHJJi3ZOnb5/JdbYwj3nW+FxQnHIjhBKz8YLC7oRNPVM9NQ47I3CVx34eqQ==} @@ -5962,6 +5966,9 @@ packages: path-to-regexp@0.1.13: resolution: {integrity: sha512-A/AGNMFN3c8bOlvV9RreMdrv7jsmF9XIfDeCd87+I8RNg6s78BhJxMu69NEMHBSJFxKidViTEdruRwEk/WIKqA==} + path-to-regexp@8.4.2: + resolution: {integrity: sha512-qRcuIdP69NPm4qbACK+aDogI5CBDMi1jKe0ry5rSQJz8JVLsC7jV8XpiJjGRLLol3N+R5ihGYcrPLTno6pAdBA==} + path-type@4.0.0: resolution: {integrity: sha512-gDKb8aZMDeD/tZWs9P6+q0J9Mwkdl6xMV8TjnGP3qJVJ06bdMgkbBlLU8IdfOsIsFz2BW1rNVT3XuNEl8zPAvw==} engines: {node: '>=8'} @@ -6715,8 +6722,8 @@ packages: source-list-map@2.0.1: resolution: {integrity: sha512-qnQ7gVMxGNxsiL4lEuJwe/To8UnK7fAnmbGEEH8RpLouuKbeEm0lhbQVFIrNSuB+G7tVrAlVsZgETT5nljf+Iw==} - source-map-js@1.2.1: - resolution: {integrity: sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==} + source-map-js@1.2.2: + resolution: {integrity: sha512-KGj/8Y43x35aZVDtt+J4mK1hoLGHULMYfSkODJNQjNDC3oW1PqPoxMwo0pLUsWM/UEGzON/NxeHywEfNXNP3Vw==} engines: {node: '>=0.10.0'} source-map-support@0.5.21: @@ -11003,7 +11010,7 @@ snapshots: dependencies: baseline-browser-mapping: 2.11.26 caniuse-lite: 1.0.30001814 - electron-to-chromium: 1.5.442 + electron-to-chromium: 1.5.443 node-releases: 2.0.57 update-browserslist-db: 1.3.3(browserslist@4.29.3) @@ -11320,6 +11327,8 @@ snapshots: cookie@0.7.2: {} + cookie@2.0.1: {} + core-js-compat@3.31.0: dependencies: browserslist: 4.29.3 @@ -11677,7 +11686,7 @@ snapshots: ejs@5.0.1: {} - electron-to-chromium@1.5.442: {} + electron-to-chromium@1.5.443: {} emittery@0.13.1: {} @@ -12703,7 +12712,7 @@ snapshots: chokidar: 3.6.0 common-tags: 1.8.2 compression: 1.8.2(supports-color@7.2.0) - cookie: 0.7.2 + cookie: 2.0.1 core-js: 3.50.0 cors: 2.8.6 css-loader: 5.2.7(webpack@5.111.1(cssnano@5.1.15(postcss@8.5.28))(csso@4.2.0)(esbuild@0.28.2)(postcss@8.5.28)(sharp@0.35.5(@types/node@26.6.3))(svgo@2.8.4)) @@ -12779,7 +12788,7 @@ snapshots: opentracing: 0.14.7 p-defer: 3.0.0 parseurl: 1.3.3 - path-to-regexp: 0.1.13 + path-to-regexp: 8.4.2 physical-cpu-count: 2.0.0 platform: 1.3.6 postcss: 8.5.28 @@ -14635,6 +14644,8 @@ snapshots: path-to-regexp@0.1.13: {} + path-to-regexp@8.4.2: {} + path-type@4.0.0: {} pathval@2.0.1: {} @@ -14858,7 +14869,7 @@ snapshots: dependencies: nanoid: 3.3.19 picocolors: 1.1.1 - source-map-js: 1.2.1 + source-map-js: 1.2.2 prelude-ls@1.2.1: {} @@ -15478,7 +15489,7 @@ snapshots: source-list-map@2.0.1: {} - source-map-js@1.2.1: {} + source-map-js@1.2.2: {} source-map-support@0.5.21: dependencies: