Skip to content

chore(deps): bump axios@1.17.0, express-rate-limit@8.5.2, others#585

Merged
petruki merged 1 commit into
masterfrom
staging
Jun 5, 2026
Merged

chore(deps): bump axios@1.17.0, express-rate-limit@8.5.2, others#585
petruki merged 1 commit into
masterfrom
staging

Conversation

@petruki
Copy link
Copy Markdown
Member

@petruki petruki commented Jun 5, 2026

This pull request mainly focuses on updating dependencies and workflow actions to their latest versions, as well as adding a security badge to the README. These updates help ensure better security, compatibility, and visibility for the project. Additionally, some unused Docker Compose version declarations were removed for cleanup.

Dependency updates:

  • Updated several dependencies in package.json to their latest patch versions, including axios, express-rate-limit, graphql, helmet, mongoose, and others, as well as the eslint dev dependency. [1] [2]

CI/CD and workflow improvements:

  • Updated the sonarsource/sonarqube-scan-action GitHub Action from v8.0.0 to v8.1.0 in both master.yml and sonar.yml workflows. [1] [2]
  • Updated the actions/github-script action from v7 to v9 in the sonar.yml workflow.

Documentation and badges:

  • Added a Snyk security vulnerability badge to the README.md for improved visibility of known vulnerabilities.

Docker configuration cleanup:

  • Removed the version field from both .devcontainer/docker-compose.yml and docker-compose.yml as it is no longer required in recent Docker Compose versions. [1] [2]

@petruki petruki added this to the v1.4.1 milestone Jun 5, 2026
@petruki petruki self-assigned this Jun 5, 2026
@petruki petruki added patch Updating dependencies dependencies Pull requests that update a dependency file labels Jun 5, 2026
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented Jun 5, 2026

@petruki petruki merged commit c0f2d69 into master Jun 5, 2026
5 checks passed
@petruki petruki deleted the staging branch June 5, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file patch Updating dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant