Skip to content

Commit 9c675aa

Browse files
authored
chore(deps): fix vulnerabilities (#701)
* chore(deps): Ignore RUSTSEC-2025-0134 * chore(deps): Fix vulnerable cargo crates * chore(deps): Fix vulnerable npm packages * chore(deps): Update Dependabot config
1 parent 672ee6d commit 9c675aa

9 files changed

Lines changed: 2417 additions & 142 deletions

File tree

.github/dependabot.yml

Lines changed: 56 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,6 @@ updates:
1313
patterns:
1414
- '*'
1515
commit-message:
16-
# Prefix all commit messages with "chore(deps): "
1716
prefix: 'chore(deps): '
1817

1918
# Maintain dependencies for cargo
@@ -26,10 +25,64 @@ updates:
2625
update-types:
2726
- version-update:semver-major
2827
commit-message:
29-
# Prefix all commit messages
3028
prefix: 'chore(deps): '
3129
labels:
3230
- dependabot
3331
- dependencies
34-
# Allow up to 10 open pull requests for testing
32+
open-pull-requests-limit: 5
33+
34+
# Maintain dependencies for Docker
35+
- package-ecosystem: docker
36+
directory: /
37+
schedule:
38+
interval: monthly
39+
groups:
40+
docker-deps:
41+
patterns:
42+
- '*'
43+
commit-message:
44+
prefix: 'chore(deps): '
45+
46+
# Maintain dependencies for Docker Compose
47+
- package-ecosystem: docker-compose
48+
directories:
49+
- '**/*'
50+
schedule:
51+
interval: monthly
52+
groups:
53+
docker-compose-deps:
54+
patterns:
55+
- '*'
56+
commit-message:
57+
prefix: 'chore(deps): '
58+
59+
# Maintain dependencies for npm
60+
- package-ecosystem: npm
61+
directories:
62+
- /examples/basic-example-plugin/test-plugin/
63+
- /examples/channels-plugin-example/channel/
64+
- /examples/channels-x402-plugin-example/channel/
65+
- /examples/launchtube-plugin-example/launchtube/
66+
- /examples/x402-facilitator-plugin/x402-facilitator/
67+
- /plugins/
68+
schedule:
69+
interval: monthly
70+
allow:
71+
- dependency-name: '*'
72+
dependency-type: production
73+
ignore:
74+
- dependency-name: '*'
75+
update-types:
76+
- version-update:semver-major
77+
groups:
78+
npm-deps:
79+
patterns:
80+
- '*'
81+
dependency-type: production
82+
group-by: dependency-name
83+
commit-message:
84+
prefix: 'chore(deps): '
85+
labels:
86+
- dependabot
87+
- dependencies
3588
open-pull-requests-limit: 5

Cargo.lock

Lines changed: 20 additions & 67 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)