-
Notifications
You must be signed in to change notification settings - Fork 16
[Snyk] Security upgrade next from 13.5.3 to 14.2.32 #1194
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
omercnet
wants to merge
3,471
commits into
main
Choose a base branch
from
snyk-fix-2aecc1719641f372cb85688c4cd34b30
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
3471 commits
Select commit
Hold shift + click to select a range
bc088d4
Fix: Fixed README to say we don't support React 16 (#1135)
gaokevin1 dd25875
fix: issue 11105 RELEASE (#1136)
nirgur 999b974
chore(react-sdk): release version 2.14.24
invalid-email-address 66be4c0
chore(nextjs-sdk): release version 0.13.19
invalid-email-address 691b5fb
Fix: Fixed README to say we support React 16 (#1139)
gaokevin1 d86e16d
fix: UPW login flow (#1141)
nirgur 6740891
chore: update scripts version 1.0.9 (#1143) RELEASE
Bars92 a8ef92e
chore(web-component): release version 3.43.18
invalid-email-address 647af21
chore(user-profile-widget): release version 0.5.2
invalid-email-address eb903d5
chore(react-sdk): release version 2.14.25
invalid-email-address c91b936
chore(nextjs-sdk): release version 0.13.20
invalid-email-address f6cd423
chore(vue-sdk): release version 2.9.34
invalid-email-address d8981cf
chore(angular-sdk): release version 0.15.18
invalid-email-address 5d6b6bf
fix: Issue 11222 - retry on 521 and 524 (#1151)
nirgur ed1937c
feat: Support multiple global sdks in next sdk (#1154) RELEASE
asafshen 1d46723
chore(core-js-sdk): release version 2.44.4
invalid-email-address 06ada64
chore(web-js-sdk): release version 1.33.5
invalid-email-address 8813c0a
chore(web-component): release version 3.43.19
invalid-email-address bbe95fd
chore(role-management-widget): release version 0.3.32
invalid-email-address 44f1b56
chore(applications-portal-widget): release version 0.3.31
invalid-email-address bfcea3b
chore(user-profile-widget): release version 0.5.3
invalid-email-address aa88315
chore(access-key-management-widget): release version 0.4.31
invalid-email-address 3ce8b4b
chore(audit-management-widget): release version 0.4.31
invalid-email-address 91aa6b9
chore(user-management-widget): release version 0.7.31
invalid-email-address 937b6e9
chore(react-sdk): release version 2.14.26
invalid-email-address 6b74ed2
chore(nextjs-sdk): release version 0.14.0
invalid-email-address d32fddc
chore(angular-sdk): release version 0.15.19
invalid-email-address 041f8ee
chore(vue-sdk): release version 2.9.35
invalid-email-address 0bc53d5
fix: issue 11209 - stop polling on specific errors (#1152)
nirgur 373e253
fix: disable components on submit (#1160)
nirgur 21e5bf4
fix oauth with popup (#1164)
asafshen 7386daf
feat: add auto refresh config to web-framework sdks (#1149)
asafshen b4d39ec
feat: support passkey removal (#1165)
nirgur 2f2231d
RELEASE (#1166)
nirgur e4f63f5
chore(sdk-component-drivers): release version 0.3.0
invalid-email-address 6b252e6
chore(sdk-mixins): release version 0.13.7
invalid-email-address b429eb9
chore(web-component): release version 3.43.20
invalid-email-address be820b5
chore(user-profile-widget): release version 0.6.0
invalid-email-address fcdeeb6
chore(role-management-widget): release version 0.3.33
invalid-email-address 02dd222
chore(applications-portal-widget): release version 0.3.32
invalid-email-address baeb0fe
chore(access-key-management-widget): release version 0.4.32
invalid-email-address 7fff3db
chore(audit-management-widget): release version 0.4.32
invalid-email-address f7940ae
chore(user-management-widget): release version 0.7.32
invalid-email-address fc304c0
chore(react-sdk): release version 2.15.0
invalid-email-address f6c1203
chore(nextjs-sdk): release version 0.14.1
invalid-email-address 699aab1
chore(angular-sdk): release version 0.16.0
invalid-email-address f8a2175
chore(vue-sdk): release version 2.10.0
invalid-email-address 16e5ec6
feat: Tenant admin widget (#1158)
Nitzperetz 8fdb11d
chore: RELEASE (#1167)
Nitzperetz 58d5d11
chore(sdk-component-drivers): release version 0.4.0
invalid-email-address 9bca864
chore(sdk-mixins): release version 0.13.8
invalid-email-address b386dcd
chore(web-component): release version 3.44.0
invalid-email-address d01da32
chore(user-profile-widget): release version 0.6.1
invalid-email-address fdb6285
chore(user-management-widget): release version 0.8.0
invalid-email-address faed2d2
chore(audit-management-widget): release version 0.5.0
invalid-email-address 8fa4d26
chore(access-key-management-widget): release version 0.5.0
invalid-email-address c2b4346
chore(applications-portal-widget): release version 0.3.33
invalid-email-address b2939b5
chore(role-management-widget): release version 0.4.0
invalid-email-address 05f3e31
chore(tenant-profile-widget): release version 0.1.0
invalid-email-address 2e81782
chore(react-sdk): release version 2.16.0
invalid-email-address 023cb13
chore(nextjs-sdk): release version 0.14.2
invalid-email-address 5a67130
chore(vue-sdk): release version 2.10.1
invalid-email-address 2bf05fc
chore(angular-sdk): release version 0.17.0
invalid-email-address ca36c4e
fix: restore components state when page is shown from cache RELEASE (…
nirgur de3b72d
chore(web-component): release version 3.44.1
invalid-email-address 45911ce
chore(user-profile-widget): release version 0.6.2
invalid-email-address 595e8d6
chore(tenant-profile-widget): release version 0.1.1
invalid-email-address 6e2f0c9
chore(react-sdk): release version 2.16.1
invalid-email-address 040fe1f
chore(nextjs-sdk): release version 0.14.3
invalid-email-address 63c20c4
chore(vue-sdk): release version 2.10.2
invalid-email-address 9562c9a
chore(angular-sdk): release version 0.17.1
invalid-email-address c94dcbe
feat: APW - OIDC apps (#1169)
nirgur 4f4dcb7
chore: RELEASE (#1170)
nirgur ddaa4f1
chore(applications-portal-widget): release version 0.4.0
invalid-email-address 9c8dcc7
chore(react-sdk): release version 2.16.2
invalid-email-address 0f342c1
chore(nextjs-sdk): release version 0.14.4
invalid-email-address 5b1f2d1
chore(vue-sdk): release version 2.10.3
invalid-email-address 8214f8f
chore(angular-sdk): release version 0.17.2
invalid-email-address 431805e
feat: Support exclusion from sso by login ids (#1171)
aviadl 2a42c09
fix: trying to fix issue 11567 RELEASE (#1173)
nirgur 2d3ad34
chore(web-component): release version 3.44.2
invalid-email-address d8ca257
chore(user-profile-widget): release version 0.6.3
invalid-email-address 4b219e9
chore(tenant-profile-widget): release version 0.2.0
invalid-email-address 5da9f89
chore(react-sdk): release version 2.16.3
invalid-email-address 879490b
chore(nextjs-sdk): release version 0.14.5
invalid-email-address 79ef784
chore(vue-sdk): release version 2.10.4
invalid-email-address 9f40a85
chore(angular-sdk): release version 0.17.3
invalid-email-address 0366de0
fix: add logs to redirect in popup (#1174)
nirgur 21e6f11
chore:RELEASE (#1175)
dorsha bef4587
chore(web-component): release version 3.44.3
invalid-email-address 87f01f0
chore(user-profile-widget): release version 0.6.4
invalid-email-address a20566f
chore(tenant-profile-widget): release version 0.2.1
invalid-email-address e4a3179
chore(react-sdk): release version 2.16.4
invalid-email-address 856940e
chore(nextjs-sdk): release version 0.14.6
invalid-email-address ca7b2a0
chore(vue-sdk): release version 2.10.5
invalid-email-address 341f86f
chore(angular-sdk): release version 0.17.4
invalid-email-address bde317f
feat: Outbound Apps widget (#1156)
tomerlichtash 2ea4d87
chore: Dynamic ports in widget playwright specs (#1176)
tomerlichtash cba2524
fix: rename outbound connect redirect url param RELEASE (#1178)
talaharoni 43505a3
chore(sdk-component-drivers): release version 0.5.0
invalid-email-address 2689356
chore(core-js-sdk): release version 2.44.5
invalid-email-address f969a78
chore(web-js-sdk): release version 1.33.6
invalid-email-address 0dadb81
chore(sdk-mixins): release version 0.13.9
invalid-email-address 4bcf3d9
chore(e2e-helpers): release version 0.1.0
invalid-email-address 36c2a32
chore(web-component): release version 3.44.4
invalid-email-address 5b06b36
chore(role-management-widget): release version 0.4.1
invalid-email-address 233b4d6
chore(applications-portal-widget): release version 0.4.1
invalid-email-address 75d6e87
chore(access-key-management-widget): release version 0.5.1
invalid-email-address 512bc5b
chore(audit-management-widget): release version 0.5.1
invalid-email-address 9ecf5c2
chore(user-management-widget): release version 0.8.1
invalid-email-address a1fefec
chore(user-profile-widget): release version 0.6.5
invalid-email-address 484aaf9
chore(tenant-profile-widget): release version 0.2.2
invalid-email-address f3860d0
chore(react-sdk): release version 2.16.5
invalid-email-address 5b28561
chore(nextjs-sdk): release version 0.14.7
invalid-email-address 07507f5
chore(vue-sdk): release version 2.10.6
invalid-email-address d7d6e7d
chore(angular-sdk): release version 0.18.0
invalid-email-address 047d7a1
chore(outbound-applications-widget): release version 0.1.0
invalid-email-address bd8b562
feat: added the option to add external request id to requests - React…
nirgur 15c81b7
fix: remove loading state when closing oauth popup manually (#1179)
nirgur 2ba7931
feat: Darwinium (#1180) RELEASE
itaihanski 610beec
chore(core-js-sdk): release version 2.45.0
invalid-email-address 27d4e15
chore(web-js-sdk): release version 1.33.7
invalid-email-address f4d6594
chore(web-component): release version 3.45.0
invalid-email-address 583e52c
chore(role-management-widget): release version 0.4.2
invalid-email-address 50718da
chore(applications-portal-widget): release version 0.4.2
invalid-email-address de256ba
chore(access-key-management-widget): release version 0.5.2
invalid-email-address 1a455cf
chore(user-profile-widget): release version 0.6.6
invalid-email-address 84c7b4d
chore(audit-management-widget): release version 0.5.2
invalid-email-address 507d18b
chore(user-management-widget): release version 0.8.2
invalid-email-address 54708d5
chore(tenant-profile-widget): release version 0.2.3
invalid-email-address 8fe6bbe
chore(react-sdk): release version 2.17.0
invalid-email-address 7b45e25
chore(nextjs-sdk): release version 0.14.8
invalid-email-address 528f0af
chore(vue-sdk): release version 2.10.7
invalid-email-address 8cc56c3
chore(angular-sdk): release version 0.18.1
invalid-email-address 4145813
chore(outbound-applications-widget): release version 0.1.1
invalid-email-address 02c11ab
fix: reload sdk scripts when restoring components state RELEASE (#1183)
nirgur 1a6c0db
chore(web-component): release version 3.45.1
invalid-email-address bb23d48
chore(user-profile-widget): release version 0.6.7
invalid-email-address 69dd763
chore(tenant-profile-widget): release version 0.2.4
invalid-email-address 8001956
chore(react-sdk): release version 2.17.1
invalid-email-address c1217df
chore(nextjs-sdk): release version 0.14.9
invalid-email-address 8302bc6
chore(vue-sdk): release version 2.10.8
invalid-email-address fb8adfe
chore(angular-sdk): release version 0.18.2
invalid-email-address 24e2740
chore(outbound-applications-widget): release version 0.1.2
invalid-email-address 604fb81
fix: added BYOS example & fix Angular 19 issues (#1181)
nirgur 7d15a1e
feat: add oidcResource parameter to SDK start options (#1184)
orius123 d46262c
feat: Generic flow button (#1172)
OfekAvergil 2f63060
chore: RELEASE (#1187)
orius123 d1b9751
chore(sdk-helpers): release version 0.4.0
invalid-email-address 9d28aed
chore(sdk-component-drivers): release version 0.6.0
invalid-email-address f0df7ed
chore(core-js-sdk): release version 2.46.0
invalid-email-address 34ae329
chore(web-js-sdk): release version 1.34.0
invalid-email-address 637e115
chore(sdk-mixins): release version 0.13.10
invalid-email-address 65d897b
chore(web-component): release version 3.46.0
invalid-email-address 977edd3
chore(role-management-widget): release version 0.4.3
invalid-email-address cc22050
chore(applications-portal-widget): release version 0.4.3
invalid-email-address b9f5755
chore(access-key-management-widget): release version 0.5.3
invalid-email-address 63c5e23
chore(audit-management-widget): release version 0.5.3
invalid-email-address c96a22e
chore(user-management-widget): release version 0.9.0
invalid-email-address d791041
chore(user-profile-widget): release version 0.6.8
invalid-email-address a4cd8ef
chore(tenant-profile-widget): release version 0.2.5
invalid-email-address 071b035
chore(react-sdk): release version 2.18.0
invalid-email-address d6af47f
chore(nextjs-sdk): release version 0.14.10
invalid-email-address 1d8fadb
chore(vue-sdk): release version 2.10.9
invalid-email-address 5b233ee
chore(angular-sdk): release version 0.18.3
invalid-email-address ed28a4c
chore(outbound-applications-widget): release version 0.1.3
invalid-email-address ecf1784
fix: Safe set of OB widget isConnected state RELEASE (#1188)
tomerlichtash af084f7
chore(outbound-applications-widget): release version 0.1.4
invalid-email-address 1fb06b3
refactor: Move http client logic from sdk layer to client and export …
itaihanski 931c3ae
chore(core-js-sdk): release version 2.46.1
invalid-email-address 4c5e1a3
chore(web-js-sdk): release version 1.34.1
invalid-email-address d688cc0
chore(web-component): release version 3.46.1
invalid-email-address 354a214
chore(role-management-widget): release version 0.4.4
invalid-email-address 2116ce6
chore(applications-portal-widget): release version 0.4.4
invalid-email-address 553d667
chore(access-key-management-widget): release version 0.5.4
invalid-email-address 998f848
chore(user-profile-widget): release version 0.6.9
invalid-email-address a53dd32
chore(audit-management-widget): release version 0.5.4
invalid-email-address e8a3831
chore(user-management-widget): release version 0.9.1
invalid-email-address aaed1ff
chore(tenant-profile-widget): release version 0.2.6
invalid-email-address c262413
chore(react-sdk): release version 2.18.1
invalid-email-address d9dfab1
chore(nextjs-sdk): release version 0.14.11
invalid-email-address 88c6725
chore(vue-sdk): release version 2.10.10
invalid-email-address a781fa2
chore(angular-sdk): release version 0.18.4
invalid-email-address 7a6e2af
chore(outbound-applications-widget): release version 0.1.5
invalid-email-address 1964631
fix: issue 11792 RELEASE (#1189)
nirgur 87d929a
chore(core-js-sdk): release version 2.46.2
invalid-email-address d0f3e7d
chore(web-js-sdk): release version 1.34.2
invalid-email-address 6b1f7ff
chore(web-component): release version 3.46.2
invalid-email-address df0d2bf
chore(role-management-widget): release version 0.4.5
invalid-email-address d2969ab
chore(applications-portal-widget): release version 0.4.5
invalid-email-address d4d063b
chore(access-key-management-widget): release version 0.5.5
invalid-email-address 98e06e6
chore(user-profile-widget): release version 0.6.10
invalid-email-address b1a7565
chore(audit-management-widget): release version 0.5.5
invalid-email-address aaa97f9
chore(user-management-widget): release version 0.9.2
invalid-email-address 15eafa7
chore(tenant-profile-widget): release version 0.2.7
invalid-email-address b2585c5
chore(react-sdk): release version 2.18.2
invalid-email-address 87347d3
chore(nextjs-sdk): release version 0.14.12
invalid-email-address 2bf3ca9
chore(vue-sdk): release version 2.10.11
invalid-email-address 7229690
chore(angular-sdk): release version 0.18.5
invalid-email-address 253f859
chore(outbound-applications-widget): release version 0.1.6
invalid-email-address f5948a3
feat: Add tenant options to outbound connect. RELEASE (#1190)
talaharoni f20900e
chore(core-js-sdk): release version 2.47.0
invalid-email-address 93b864e
chore(web-js-sdk): release version 1.34.3
invalid-email-address 3e63df8
chore(web-component): release version 3.46.3
invalid-email-address 54c9b4c
chore(user-management-widget): release version 0.9.3
invalid-email-address eced439
chore(audit-management-widget): release version 0.5.6
invalid-email-address bb8bd35
chore(user-profile-widget): release version 0.6.11
invalid-email-address b5dcd4c
chore(access-key-management-widget): release version 0.5.6
invalid-email-address cd5c1b5
chore(applications-portal-widget): release version 0.4.6
invalid-email-address f7c784a
chore(role-management-widget): release version 0.4.6
invalid-email-address efa100f
chore(tenant-profile-widget): release version 0.2.8
invalid-email-address 94d36ed
chore(react-sdk): release version 2.18.3
invalid-email-address 2d98212
chore(nextjs-sdk): release version 0.14.13
invalid-email-address 46cb41d
chore(outbound-applications-widget): release version 0.1.7
invalid-email-address 81144c7
chore(angular-sdk): release version 0.18.6
invalid-email-address 1450a2f
chore(vue-sdk): release version 2.10.12
invalid-email-address 33fce1a
feat: try refresh API on init (#1182) RELEASE
asafshen 355f3a2
chore(core-js-sdk): release version 2.48.0
invalid-email-address 9237c20
chore(web-js-sdk): release version 1.35.0
invalid-email-address 26ed886
chore(web-component): release version 3.46.4
invalid-email-address 74dd7d9
chore(role-management-widget): release version 0.4.7
invalid-email-address df659e4
chore(applications-portal-widget): release version 0.4.7
invalid-email-address ae36f2a
chore(access-key-management-widget): release version 0.5.7
invalid-email-address cacf19f
chore(user-profile-widget): release version 0.6.12
invalid-email-address 4b7c064
chore(audit-management-widget): release version 0.5.7
invalid-email-address 1d01471
chore(user-management-widget): release version 0.9.4
invalid-email-address 5c4144c
chore(tenant-profile-widget): release version 0.2.9
invalid-email-address 845b916
chore(react-sdk): release version 2.19.0
invalid-email-address 86970f9
chore(nextjs-sdk): release version 0.14.14
invalid-email-address 8c57eca
chore(vue-sdk): release version 2.11.0
invalid-email-address 41edf2d
chore(angular-sdk): release version 0.19.0
invalid-email-address 9466476
chore(outbound-applications-widget): release version 0.1.8
invalid-email-address 4278af5
feat: better storage of last auth (#1191)
dorsha aa7e358
feat: Add loginHint and forceAuthn to saml start RELEASE (#1192)
dorsha 57d16aa
chore(core-js-sdk): release version 2.49.0
invalid-email-address 5aa3322
chore(web-js-sdk): release version 1.35.1
invalid-email-address a6c3a8c
chore(web-component): release version 3.47.0
invalid-email-address e48feb6
chore(role-management-widget): release version 0.5.0
invalid-email-address 6976c75
chore(applications-portal-widget): release version 0.4.8
invalid-email-address b2bbaac
chore(access-key-management-widget): release version 0.5.8
invalid-email-address 1aa4c17
chore(user-profile-widget): release version 0.6.13
invalid-email-address 1fd2dba
chore(audit-management-widget): release version 0.5.8
invalid-email-address ada07d2
chore(user-management-widget): release version 0.9.5
invalid-email-address daadccc
chore(tenant-profile-widget): release version 0.2.10
invalid-email-address 25a56ac
chore(react-sdk): release version 2.19.1
invalid-email-address 36bc193
chore(nextjs-sdk): release version 0.14.15
invalid-email-address fa935cf
chore(vue-sdk): release version 2.11.1
invalid-email-address 4754abc
chore(angular-sdk): release version 0.19.1
invalid-email-address 53bcd93
chore(outbound-applications-widget): release version 0.1.9
invalid-email-address aa9d2cb
fix: packages/sdks/nextjs-sdk/examples/pages-router/package.json & pa…
snyk-bot File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,56 +1,95 @@ | ||
| name: CI | ||
| on: push | ||
| on: | ||
| pull_request: | ||
| push: | ||
| branches: | ||
| - main | ||
| env: | ||
| NODE_VERSION: 18.2 | ||
| PNPM_VERSION: 7.28.0 | ||
| NX_CLOUD_ACCESS_TOKEN: ${{ secrets.NX_CLOUD_ACCESS_TOKEN }} | ||
| jobs: | ||
| gitleaks: | ||
| name: 🔒 Run Git leaks | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout code | ||
| uses: actions/checkout@v3 | ||
| - uses: actions/setup-node@v3 | ||
| with: | ||
| node-version: ${{ env.NODE_VERSION }} | ||
| - uses: pnpm/action-setup@v2 | ||
| with: | ||
| version: ${{ env.PNPM_VERSION }} | ||
| # Skip post-install scripts here, as a malicious | ||
| # script could steal NODE_AUTH_TOKEN. | ||
| - name: Install dependencies | ||
| run: pnpm install --frozen-lockfile --ignore-scripts | ||
| env: | ||
| CI: true | ||
| NODE_AUTH_TOKEN: ${{ secrets.CI_NPM_READ_ORG }} | ||
| - name: Gitleaks | ||
| run: npm run leaks | ||
| shell: bash | ||
| pr: | ||
| name: 👷 Build / Lint / Test | ||
| runs-on: ubuntu-latest | ||
| container: | ||
| # the container version should be the same as the version of the Playwright package | ||
| image: mcr.microsoft.com/playwright:v1.47.0-jammy | ||
| options: --user root | ||
| steps: | ||
| - name: Checkout code | ||
| uses: actions/checkout@v3 | ||
| uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | ||
| with: | ||
| # ref: main | ||
| fetch-depth: 0 | ||
| - uses: actions/setup-node@v3 | ||
| with: | ||
| node-version: ${{ env.NODE_VERSION }} | ||
| - uses: pnpm/action-setup@v2 | ||
|
|
||
| - name: Use Latest Corepack | ||
| run: | | ||
| echo "Before: corepack version => $(corepack --version || echo 'not installed')" | ||
| npm install -g corepack@latest | ||
| echo "After : corepack version => $(corepack --version)" | ||
| corepack enable | ||
| pnpm --version | ||
|
|
||
| - name: Setup Node.js | ||
| uses: actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4.1.0 | ||
| with: | ||
| version: ${{ env.PNPM_VERSION }} | ||
| node-version-file: package.json | ||
| cache: 'pnpm' | ||
| # - name: Restore cached npm dependencies | ||
| # uses: actions/cache/restore@v4 | ||
| # with: | ||
| # path: | | ||
| # node_modules | ||
| # key: npm-dependencies-${{ hashFiles('pnpm-lock.yaml') }} | ||
|
|
||
| # Setup container | ||
| - name: Mark directory as safe | ||
| run: git config --system --add safe.directory /__w/descope-js/descope-js | ||
| - name: Install jq | ||
| run: apt-get update && apt-get install -y jq | ||
| - name: Set permission | ||
| run: chmod -R 777 /usr/local | ||
|
|
||
| - name: Install dependencies | ||
| run: pnpm install --frozen-lockfile --ignore-scripts | ||
| env: | ||
| CI: true | ||
| NODE_AUTH_TOKEN: ${{ secrets.CI_NPM_READ_ORG }} | ||
|
|
||
| # - name: Set NX cloud shas | ||
| # uses: nrwl/nx-set-shas@v4 | ||
| # - name: Install Playwright Browsers | ||
| # run: npx playwright install --with-deps | ||
|
|
||
| # - name: Cache npm dependencies | ||
| # uses: actions/cache/save@v4 | ||
| # with: | ||
| # path: | | ||
| # node_modules | ||
| # key: npm-dependencies-${{ hashFiles('pnpm-lock.yaml') }} | ||
|
|
||
| - name: Gitleaks | ||
| run: npm run leaks | ||
| shell: bash | ||
|
|
||
| - name: License validation | ||
| run: pnpm run licenseCheck | ||
|
|
||
| - name: Build | ||
| run: pnpm run build | ||
| env: | ||
| NODE_AUTH_TOKEN: ${{ secrets.CI_NPM_READ_ORG }} | ||
|
|
||
| - name: Lint | ||
| run: pnpm run lint | ||
|
|
||
| - name: Test | ||
| run: pnpm run test | ||
|
|
||
| - name: E2E | ||
| run: pnpm nx affected --target test:e2e | ||
| env: | ||
| HOME: /root | ||
|
|
||
| - name: Upload HTML report | ||
| if: always() | ||
| uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0 | ||
| with: | ||
| name: e2e-report | ||
| path: packages/**/playwright-report |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,65 @@ | ||
| name: Release next | ||
|
|
||
| on: | ||
| workflow_run: | ||
| workflows: ['Release'] | ||
| branches: [main] | ||
| types: | ||
| - completed | ||
|
|
||
| env: | ||
| NX_CLOUD_ACCESS_TOKEN: ${{ secrets.NX_CLOUD_ACCESS_TOKEN }} | ||
|
|
||
| jobs: | ||
| release: | ||
| name: Release Next | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Get token | ||
| id: get_token | ||
| uses: tibdex/github-app-token@3beb63f4bd073e61482598c45c71c1019b59b73a # v2.1.0 | ||
| with: | ||
| private_key: ${{ secrets.RELEASE_APP_PEM }} | ||
| app_id: ${{ secrets.RELEASE_APP_ID }} | ||
| - name: Checkout code | ||
| uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | ||
| with: | ||
| fetch-depth: 0 | ||
| # persist-credentials: false | ||
| token: ${{ steps.get_token.outputs.token }} | ||
| ref: ${{ github.ref }} | ||
| - name: Run git config | ||
| run: | | ||
| git config user.name github-actions | ||
| git config user.email github-actions@github.com | ||
| - name: Use Latest Corepack | ||
| run: | | ||
| echo "Before: corepack version => $(corepack --version || echo 'not installed')" | ||
| npm install -g corepack@latest | ||
| echo "After : corepack version => $(corepack --version)" | ||
| corepack enable | ||
| pnpm --version | ||
| - name: Setup Node | ||
| uses: actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4.1.0 | ||
| with: | ||
| cache: 'pnpm' | ||
| node-version-file: package.json | ||
| registry-url: https://registry.npmjs.org/ | ||
| - name: Install dependencies | ||
| run: pnpm install --frozen-lockfile --ignore-scripts | ||
| env: | ||
| CI: true | ||
| - name: Set Next Version | ||
| run: | | ||
| SHORT_SHA=$(echo ${{ github.sha }} | cut -c1-8) | ||
| CURRENT_DATE=$(date +'%Y%m%d') | ||
| echo "NEXT_VERSION=0.0.0-next-${SHORT_SHA}-${CURRENT_DATE}" >> $GITHUB_ENV | ||
| - name: Build | ||
| run: pnpm run build:ci | ||
| - name: Bump version | ||
| run: pnpm print-affected:ci | xargs -I {} pnpm --filter={} exec npm version "${NEXT_VERSION}" --git-tag-version=false | ||
| - name: Publish | ||
| run: pnpm -r publish --access=public --no-git-checks --tag=next | ||
| env: | ||
| CI: true | ||
| NODE_AUTH_TOKEN: ${{ secrets.CI_NPM_REGISTRY }} | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
File renamed without changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Check warning
Code scanning / CodeQL
Workflow does not contain permissions Medium
Copilot Autofix
AI 6 months ago
To resolve this issue, you should add a
permissions:block to the workflow file, explicitly restricting the default permissions of GITHUB_TOKEN. This can be done at the root level (to apply to all jobs), or within thereleasejob specifically. Since only one job is present (release), setting it at the root is simplest and most future-proof. The minimal recommended permission iscontents: read. If you later identify the need for additional permissions (e.g., on pull requests or packages), you can add them.Steps:
name: Release nextat the top of the workflow: