chore(deps): absorb safe automation updates

This commit is contained in:
xixu-me committed 2026-03-31 02:06:29 +08:00
1 parent 270b0891fa
commit 6ddf1359ba
6 files changed
+26 -23

No files matched your search

+1 -1
View File
@@ -35,7 +35,7 @@ jobs:
steps:
- name: Check out repository
uses: actions/checkout@v5
uses: actions/checkout@v6
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
+1 -1
View File
@@ -38,7 +38,7 @@ jobs:
- name: Upload security audit artifacts
if: always()
uses: actions/upload-artifact@v6
uses: actions/upload-artifact@v7
with:
name: security-audit-report
path: security-reports/
+19 -16
View File
@@ -45,13 +45,13 @@
},
"devDependencies": {
"@types/archiver": "^7.0.0",
"@types/bcrypt": "^5.0.0",
"@types/bcrypt": "^6.0.0",
"@types/busboy": "^1.5.4",
"@types/cors": "^2.8.19",
"@types/koa": "^2.15.0",
"@types/koa-compress": "^4.0.6",
"@types/koa-compress": "^4.0.7",
"@types/lodash": "^4.17.24",
"@types/node": "^20.14.13",
"@types/node": "^25.5.0",
"@types/set-cookie-parser": "^2.4.7",
"@types/xmldom": "^0.1.34",
"@typescript-eslint/eslint-plugin": "^8.57.2",
@@ -980,10 +980,11 @@
}
},
"node_modules/@types/bcrypt": {
"version": "5.0.2",
"resolved": "https://registry.npmjs.org/@types/bcrypt/-/bcrypt-5.0.2.tgz",
"integrity": "sha512-6atioO8Y75fNcbmj0G7UjI9lXN2pQ/IGJ2FWT4a/btd0Lk9lQalHLKhkgKVZ3r+spnmWUKfbMi1GEe9wyHQfNQ==",
"version": "6.0.0",
"resolved": "https://registry.npmjs.org/@types/bcrypt/-/bcrypt-6.0.0.tgz",
"integrity": "sha512-/oJGukuH3D2+D+3H4JWLaAsJ/ji86dhRidzZ/Od7H/i8g+aCmvkeCc6Ni/f9uxGLSQVCRZkX2/lqEFG2BvWtlQ==",
"dev": true,
"license": "MIT",
"dependencies": {
"@types/node": "*"
}
@@ -1149,9 +1150,9 @@
}
},
"node_modules/@types/koa-compress": {
"version": "4.0.6",
"resolved": "https://registry.npmjs.org/@types/koa-compress/-/koa-compress-4.0.6.tgz",
"integrity": "sha512-jJzlsQTeIXRfQzY7y2Dl/syqOxvEaNJzFTJ8ZGaDFWvqgMmCXplfCGjPfHQgU7xYNKq/mCdN3YWus1YOldfIwg==",
"version": "4.0.7",
"resolved": "https://registry.npmjs.org/@types/koa-compress/-/koa-compress-4.0.7.tgz",
"integrity": "sha512-NqP9qCBfXCu2+RYkGzEENBkqXWExOPeBEsvj3F0xtVxKDwwdfRRtVdpxJeTRAq2Ml3qlUnDbK8bKHWwe6V1kkg==",
"dev": true,
"license": "MIT",
"dependencies": {
@@ -1178,11 +1179,12 @@
"integrity": "sha512-nG96G3Wp6acyAgJqGasjODb+acrI7KltPiRxzHPXnP3NgI28bpQDRv53olbqGXbfcgF5aiiHmO3xpwEpS5Ld9g=="
},
"node_modules/@types/node": {
"version": "20.14.13",
"resolved": "https://registry.npmjs.org/@types/node/-/node-20.14.13.tgz",
"integrity": "sha512-+bHoGiZb8UiQ0+WEtmph2IWQCjIqg8MDZMAV+ppRRhUZnquF5mQkP/9vpSwJClEiSM/C7fZZExPzfU0vJTyp8w==",
"version": "25.5.0",
"resolved": "https://registry.npmjs.org/@types/node/-/node-25.5.0.tgz",
"integrity": "sha512-jp2P3tQMSxWugkCUKLRPVUpGaL5MVFwF8RDuSRztfwgN1wmqJeMSbKlnEtQqU8UrhTmzEmZdu2I6v2dpp7XIxw==",
"license": "MIT",
"dependencies": {
"undici-types": "~5.26.4"
"undici-types": "~7.18.0"
}
},
"node_modules/@types/qs": {
@@ -6937,9 +6939,10 @@
}
},
"node_modules/undici-types": {
"version": "5.26.5",
"resolved": "https://registry.npmjs.org/undici-types/-/undici-types-5.26.5.tgz",
"integrity": "sha512-JlCMO+ehdEIKqlFxk6IfVoAUVmgz7cU7zD/h9XZ0qzeosSHmUJVOzSQvvYSYWXkFXC+IfLKSIffhv0sVZup6pA=="
"version": "7.18.2",
"resolved": "https://registry.npmjs.org/undici-types/-/undici-types-7.18.2.tgz",
"integrity": "sha512-AsuCzffGHJybSaRrmr5eHr81mwJU3kjw6M+uprWvCXiNeN9SOGwQ3Jn8jb8m3Z6izVgknn1R0FTCEAP2QrLY/w==",
"license": "MIT"
},
"node_modules/unicode-9.0.0": {
"version": "0.7.0",
+3 -3
View File
@@ -57,13 +57,13 @@
},
"devDependencies": {
"@types/archiver": "^7.0.0",
"@types/bcrypt": "^5.0.0",
"@types/bcrypt": "^6.0.0",
"@types/busboy": "^1.5.4",
"@types/cors": "^2.8.19",
"@types/koa": "^2.15.0",
"@types/koa-compress": "^4.0.6",
"@types/koa-compress": "^4.0.7",
"@types/lodash": "^4.17.24",
"@types/node": "^20.14.13",
"@types/node": "^25.5.0",
"@types/set-cookie-parser": "^2.4.7",
"@types/xmldom": "^0.1.34",
"@typescript-eslint/eslint-plugin": "^8.57.2",
+1 -1
View File
@@ -61,7 +61,7 @@ test('workflows opt into Node 24 for JavaScript-based GitHub Actions', () => {
test('CodeQL workflow uses advanced setup with repository-managed configuration', () => {
const workflow = read('.github/workflows/codeql.yml');
assert.match(workflow, /uses:\s*actions\/checkout@v5/);
assert.match(workflow, /uses:\s*actions\/checkout@v\d+/);
assert.match(workflow, /uses:\s*github\/codeql-action\/init@v4/);
assert.match(workflow, /uses:\s*github\/codeql-action\/analyze@v4/);
assert.match(workflow, /language:\s*actions/);
+1 -1
View File
@@ -28,7 +28,7 @@ test('security governance workflow enforces npm audit policy and uploads reports
assert.match(workflow, /name:\s+Security Governance/);
assert.match(workflow, /run:\s+npm run security:audit/);
assert.match(workflow, /actions\/upload-artifact@v6/);
assert.match(workflow, /actions\/upload-artifact@v\d+/);
assert.match(workflow, /cron:\s+'31 17 \* \* 1'/);
});