Skip to content

v0.1.2: current dependencies and Dependabot checks

Latest

Choose a tag to compare

@napalm255 napalm255 released this 03 Oct 23:27
174a20f

Refresh shared dependencies, scanner tools, and SHA-pinned GitHub Actions across the Quick extension fleet.

Update Vitest and its coverage provider together to 5.0.3, ESLint to 10.12.0, eslint-plugin-security to 4.2.0, and globals to 17.13.0. Update Python, uv, Ruff, Trivy, gh, and the pinned mise release while retaining Node 24 LTS.

mise-action 5.0.1 fixes cached-binary verification. CodeQL init/analyze remain on the same 4.38.2 commit. Pages/artifact Actions use current stable pinned commits; download-artifact fails on digest mismatches by default. Dependabot scans root and payload npm directories, and its separate SONAR_TOKEN secret is configured across the fleet.

Validation: full local CI and hosted main CI, CodeQL, and Sonar pass. Main has zero security, reliability, maintainability, hotspot, and duplication metrics; no findings are dismissed. No outdated npm direct dependencies or known npm vulnerabilities remain.