dependabot[bot]
cf7e407386
chore(deps): bump the minor-and-patch group with 4 updates ( #43 )
...
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 4 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml](https://github.com/sea-haven-industries/.github ), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github ), [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github ) and [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github ).
Updates `Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 13:28:31 -04:00
dependabot[bot]
f24af4e790
chore(deps): bump the minor-and-patch group with 4 updates ( #39 )
...
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 4 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml](https://github.com/sea-haven-industries/.github ), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github ), [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github ) and [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github ).
Updates `Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](3f74677422...7ac3528750 )
Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](3f74677422...7ac3528750 )
Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](3f74677422...7ac3528750 )
Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.5 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](9c1ecf9428...7ac3528750 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml
dependency-version: 1.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
dependency-version: 1.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
dependency-version: 1.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
dependency-version: 1.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-11 13:59:07 -04:00
dependabot[bot]
a5b9716c31
chore(deps): bump the minor-and-patch group with 3 updates ( #35 )
...
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 3 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml](https://github.com/sea-haven-industries/.github ), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github ) and [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github ).
Updates `Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](0170a57c0d...3f74677422 )
Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](0170a57c0d...3f74677422 )
Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](0170a57c0d...3f74677422 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml
dependency-version: 1.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
dependency-version: 1.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
dependency-version: 1.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 18:39:20 -04:00
Adam Moussa
507a7a1251
style(ci): normalize workflow block spacing
2026-07-28 18:06:30 -04:00
Adam Moussa
69fdc92623
ci(deps): pin org reusable workflows to v1.0.2
2026-07-28 17:56:30 -04:00
Adam Moussa
1b71f5f56e
chore(security): resolve open npm audit and code scanning alerts ( #31 )
...
Deploy / deploy (push) Waiting to run
* build(deps): resolve npm audit advisories via in-range bumps
npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs
10.27.2, and brace-expansion 1.1.16 to clear four high DoS
advisories. Eleventy build verified passing at 3.1.6.
The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has
no in-range fix: the patch exists only in 5.0.8, and
@11ty/recursive-copy pins an older minimatch. Exposure is
build-time only (glob patterns from our own config, never
untrusted input), so it is suppressed with justification in
.security-review/suppressions.json rather than forcing the
eleventy downgrade npm audit fix --force proposes. Remove the
npmaudit-* suppressions when recursive-copy ships a minimatch
>=10.0.3 bump.
* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.
* ci(dependency-review): allow adjudicated brace-expansion GHSA
Re-pins the callable to 07ce007 (adds the allow-ghsas input, org
PR #89 ) and allows GHSA-mh99-v99m-4gvg, which the review check
flags on the bumped-but-still-in-range brace-expansion 1.1.16.
The advisory has no in-range fix and is an accepted risk with
written justification in .security-review/suppressions.json;
remove the allowance together with those suppressions when
@11ty/recursive-copy ships a minimatch >=10.0.3 bump.
2026-07-27 17:41:00 +00:00
Adam Moussa
3d8a9cb459
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) ( #25 )
Deploy / deploy (push) Waiting to run
2026-07-06 18:28:22 -04:00
Adam Moussa
c1b463639b
chore(ci): add org dependency-review caller (INFRA-125) ( #23 )
Deploy / deploy (push) Waiting to run
2026-07-06 17:41:00 -04:00