Compare commits

..

20 Commits

Author SHA1 Message Date
dependabot[bot]
c8699bbd1b chore(deps): bump tar from 7.5.10 to 7.5.11
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.11.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.10...v7.5.11)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.11
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-11 21:30:07 +00:00
renovate[bot]
c7b34723ef chore(actions): update ivuorinen/actions action to v2026.03.10 (#487)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-11 01:36:04 +02:00
66ddc6a9db ci: migrate CodeQL to ivuorinen/actions/codeql-analysis (#486)
* ci: migrate codeql to composable workflow

* fix: correct codeql workflow permissions, cron, and action ref

- Set root-level permissions to {}
- Add job-level permissions (actions, contents, packages, security-events)
- Pin action ref to commit hash with version comment
- Fix mangled cron schedule
- Clean up workflow structure

* fix: correct codeql workflow language, queries, permissions, and action ref

- Use 'javascript' instead of 'javascript-typescript' for CodeQL language
- Add queries: security-and-quality parameter
- Set root-level permissions to {}
- Add job-level permissions (actions, contents, packages, security-events)
- Pin action ref to commit hash with version comment
- Fix mangled cron schedule
2026-03-07 17:49:19 +02:00
semantic-release-bot
100e51b279 chore(release): 1.0.10 [skip ci]
## [1.0.10](https://github.com/ivuorinen/base-configs/compare/v1.0.9...v1.0.10) (2026-03-06)
2026-03-06 02:39:37 +00:00
renovate[bot]
74a0d402e7 chore(deps): lock file maintenance (#485)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-06 04:35:39 +02:00
renovate[bot]
44a71a4341 chore(deps): update ivuorinen/actions action (v2026.03.02 → v2026.03.05) (#484)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-06 04:35:20 +02:00
renovate[bot]
9bb988cbc4 chore(deps): update github/codeql-action action (v4.32.5 → v4.32.6) (#483)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-06 04:35:00 +02:00
semantic-release-bot
aa950c4f19 chore(release): 1.0.9 [skip ci]
## [1.0.9](https://github.com/ivuorinen/base-configs/compare/v1.0.8...v1.0.9) (2026-03-05)
2026-03-05 19:26:20 +00:00
renovate[bot]
c5c0bc853c chore(deps): update actions/setup-node action (v6.2.0 → v6.3.0) (#481) 2026-03-05 21:22:36 +02:00
semantic-release-bot
818c1311f1 chore(release): 1.0.8 [skip ci]
## [1.0.8](https://github.com/ivuorinen/base-configs/compare/v1.0.7...v1.0.8) (2026-03-05)
2026-03-05 17:43:33 +00:00
renovate[bot]
d12ab3d012 chore(deps): lock file maintenance (#482) 2026-03-05 19:27:18 +02:00
semantic-release-bot
69e646c10d chore(release): 1.0.7 [skip ci]
## [1.0.7](https://github.com/ivuorinen/base-configs/compare/v1.0.6...v1.0.7) (2026-03-04)

### Bug Fixes

* **deps:** resolve peer dependency warnings and minimatch vulnerability ([#480](https://github.com/ivuorinen/base-configs/issues/480)) ([81812c1](81812c163a))
2026-03-04 11:57:02 +00:00
81812c163a fix(deps): resolve peer dependency warnings and minimatch vulnerability (#480)
* fix(deps): resolve peer dependency warnings and minimatch vulnerability

Add packageExtensions to .yarnrc.yml for @commitlint/load and
eslint-plugin-n peer dependency warnings. Add resolutions to
package.json to force minimatch >=10.2.4, fixing 3 HIGH ReDoS
CVEs (CVE-2026-26996, CVE-2026-27903, CVE-2026-27904).

* chore(deps): add missing stylelint-config package
2026-03-04 13:53:03 +02:00
semantic-release-bot
94e8eba521 chore(release): 1.0.6 [skip ci]
## [1.0.6](https://github.com/ivuorinen/base-configs/compare/v1.0.5...v1.0.6) (2026-03-04)
2026-03-04 10:07:59 +00:00
renovate[bot]
cbe077330f chore(deps): update github/codeql-action action (v4.32.4 → v4.32.5) (#479)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-04 12:00:23 +02:00
semantic-release-bot
6cdb36b92b chore(release): 1.0.5 [skip ci]
## [1.0.5](https://github.com/ivuorinen/base-configs/compare/v1.0.4...v1.0.5) (2026-03-03)
2026-03-03 07:04:45 +00:00
renovate[bot]
60439e025d chore(deps): lock file maintenance (#478)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-03 09:00:50 +02:00
semantic-release-bot
b8e734f888 chore(release): 1.0.4 [skip ci]
## [1.0.4](https://github.com/ivuorinen/base-configs/compare/v1.0.3...v1.0.4) (2026-03-03)
2026-03-03 05:26:41 +00:00
renovate[bot]
938219f0b5 chore(deps): update ivuorinen/actions action (v2026.02.24 → v2026.03.02) (#477)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-03 05:23:03 +00:00
renovate[bot]
49e5e8619c chore(deps): lock file maintenance (#476)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-27 22:09:38 +02:00
10 changed files with 1033 additions and 372 deletions

View File

@@ -1,51 +1,34 @@
---
# yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json
name: 'CodeQL Advanced'
name: "CodeQL"
on:
push:
branches: ['main']
branches: ["main"]
pull_request:
branches: ['main']
branches: ["main"]
schedule:
- cron: '30 1 * * 0' # Run at 1:30 AM UTC every Sunday
- cron: "30 1 * * 0"
merge_group:
permissions:
actions: read
contents: read
permissions: {}
jobs:
analyze:
name: Analyze (${{ matrix.language }})
name: Analyze
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
packages: read
security-events: write
strategy:
fail-fast: false
matrix:
include:
- language: actions
build-mode: none
- language: javascript-typescript
build-mode: none
language: ["actions", "javascript"]
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Initialize CodeQL
uses: github/codeql-action/init@89a39a4e59826350b863aa6b6252a07ad50cf83e # v4.32.4
- name: CodeQL Analysis
uses: ivuorinen/actions/codeql-analysis@9b5ae9da1b4cb135aee0ca52403e3924fba6e84f # v2026.03.10
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
language: ${{ matrix.language }}
queries: security-and-quality
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@89a39a4e59826350b863aa6b6252a07ad50cf83e # v4.32.4
with:
category: '/language:${{matrix.language}}'

View File

@@ -49,7 +49,7 @@ jobs:
- name: Run PR Lint
# https://github.com/ivuorinen/actions
uses: ivuorinen/actions/pr-lint@8faacf8a1cae049c1471708dcb408a167e91afaf # v2026.02.24
uses: ivuorinen/actions/pr-lint@9b5ae9da1b4cb135aee0ca52403e3924fba6e84f # v2026.03.10
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}

View File

@@ -21,7 +21,7 @@ jobs:
fetch-depth: 0
- name: Setup Node.js Environment
uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6.2.0
uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
with:
always-auth: true
node-version-file: '.nvmrc'

View File

@@ -27,7 +27,7 @@ jobs:
steps:
- name: Run PR Lint
# https://github.com/ivuorinen/actions
uses: ivuorinen/actions/pr-lint@8faacf8a1cae049c1471708dcb408a167e91afaf # v2026.02.24
uses: ivuorinen/actions/pr-lint@9b5ae9da1b4cb135aee0ca52403e3924fba6e84f # v2026.03.10
publish:
name: Publish
@@ -47,7 +47,7 @@ jobs:
fetch-depth: 0
- name: Setup Node.js Environment
uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6.2.0
uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
with:
always-auth: true
node-version-file: '.nvmrc'

View File

@@ -23,4 +23,4 @@ jobs:
issues: write
pull-requests: write
steps:
- uses: ivuorinen/actions/stale@8faacf8a1cae049c1471708dcb408a167e91afaf # v2026.02.24
- uses: ivuorinen/actions/stale@9b5ae9da1b4cb135aee0ca52403e3924fba6e84f # v2026.03.10

View File

@@ -39,4 +39,4 @@ jobs:
with:
token: ${{ secrets.GITHUB_TOKEN }}
- name: ⤵️ Sync Latest Labels Definitions
uses: ivuorinen/actions/sync-labels@8faacf8a1cae049c1471708dcb408a167e91afaf # v2026.02.24
uses: ivuorinen/actions/sync-labels@9b5ae9da1b4cb135aee0ca52403e3924fba6e84f # v2026.03.10

View File

@@ -1 +1,10 @@
nodeLinker: node-modules
packageExtensions:
"@commitlint/load@*":
dependencies:
typescript: "*"
"@types/node": "*"
"eslint-plugin-n@*":
dependencies:
typescript: "*"

View File

@@ -3,6 +3,25 @@
All notable changes to this project will be documented in this file. See
[Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.0.10](https://github.com/ivuorinen/base-configs/compare/v1.0.9...v1.0.10) (2026-03-06)
## [1.0.9](https://github.com/ivuorinen/base-configs/compare/v1.0.8...v1.0.9) (2026-03-05)
## [1.0.8](https://github.com/ivuorinen/base-configs/compare/v1.0.7...v1.0.8) (2026-03-05)
## [1.0.7](https://github.com/ivuorinen/base-configs/compare/v1.0.6...v1.0.7) (2026-03-04)
### Bug Fixes
* **deps:** resolve peer dependency warnings and minimatch vulnerability ([#480](https://github.com/ivuorinen/base-configs/issues/480)) ([81812c1](https://github.com/ivuorinen/base-configs/commit/81812c163a6cbfbfdafa3b8adad939b1488b47a9))
## [1.0.6](https://github.com/ivuorinen/base-configs/compare/v1.0.5...v1.0.6) (2026-03-04)
## [1.0.5](https://github.com/ivuorinen/base-configs/compare/v1.0.4...v1.0.5) (2026-03-03)
## [1.0.4](https://github.com/ivuorinen/base-configs/compare/v1.0.3...v1.0.4) (2026-03-03)
## [1.0.3](https://github.com/ivuorinen/base-configs/compare/v1.0.2...v1.0.3) (2026-02-27)

View File

@@ -1,6 +1,6 @@
{
"name": "@ivuorinen/base-configs",
"version": "1.0.3",
"version": "1.0.10",
"type": "module",
"description": "ivuorinen's shareable configurations meta package",
"author": {
@@ -48,17 +48,23 @@
"prettier:fix": "./node_modules/.bin/prettier '**/*.{js,tsx,ts,json,mjs,cjs}' '.*.{js,mjs,cjs,json}' --write",
"prettier:report": "./node_modules/.bin/prettier '**/*.{js,tsx,ts,json,mjs,cjs}' '.*.{js,mjs,cjs,json}' --check"
},
"devDependencies": {
"dependencies": {
"@ivuorinen/browserslist-config": "^1.0.1",
"@ivuorinen/commitlint-config": "^1.0.0",
"@ivuorinen/eslint-config": "^1.0.0",
"@ivuorinen/markdownlint-config": "^1.0.1",
"@ivuorinen/prettier-config": "^1.0.0",
"@ivuorinen/semantic-release-config": "^1.1.1",
"@ivuorinen/stylelint-config": "^1.0.6"
},
"devDependencies": {
"@types/node": "*",
"npm-run-all2": "^8.0.4",
"simple-git-hooks": "^2.13.1",
"typescript": ">=4.2.0"
},
"resolutions": {
"minimatch": "^10.2.4"
},
"packageManager": "yarn@4.12.0"
}

1316
yarn.lock

File diff suppressed because it is too large Load Diff