Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

chore: various CI and dependency security improvements #51

Merged
merged 6 commits into from
Nov 9, 2022

Conversation

rzhao271
Copy link
Contributor

@rzhao271 rzhao271 commented Nov 8, 2022

This PR adds a codeql.yml file to help scan for cpp and js code vulnerabilities.
It also bumps minimatch to a newer version to fix a dependabot issue.
It also removes pr-chat.yml because that file isn't necessary anymore.

@rzhao271 rzhao271 self-assigned this Nov 8, 2022
@rzhao271 rzhao271 enabled auto-merge (squash) November 8, 2022 22:50
There's no actual Python file to scan
@rzhao271 rzhao271 changed the title Create codeql.yml Add codeql.yml, bump minimatch, and remove pr-chat.yml Nov 8, 2022
@rzhao271 rzhao271 changed the title Add codeql.yml, bump minimatch, and remove pr-chat.yml Add codeql.yml, bump minimatch, remove pr-chat.yml Nov 8, 2022
@rzhao271 rzhao271 disabled auto-merge November 8, 2022 23:01
@rzhao271 rzhao271 changed the title Add codeql.yml, bump minimatch, remove pr-chat.yml chore: add codeql, bump minimatch, remove old pipeline Nov 8, 2022
@rzhao271 rzhao271 changed the title chore: add codeql, bump minimatch, remove old pipeline chore: various CI and dependency security improvements Nov 8, 2022
connor4312
connor4312 previously approved these changes Nov 8, 2022
Co-authored-by: Connor Peet <connor@peet.io>
@rzhao271 rzhao271 requested a review from connor4312 November 9, 2022 00:10
@Tyriar Tyriar added this to the 0.2.0 milestone Nov 9, 2022
@rzhao271 rzhao271 merged commit f6a9b67 into main Nov 9, 2022
@rzhao271 rzhao271 deleted the rzhao271-patch-1 branch November 9, 2022 16:43
@Tyriar Tyriar modified the milestones: 0.2.0, 0.4.0 Jan 18, 2023
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants