diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 080f610..db9b872 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,9 +19,9 @@ jobs: with: fetch-depth: 0 persist-credentials: false - - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 + - uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1 with: - version: 2026.9.1 + version: 2026.10.1 - name: Install native test tools run: | sudo apt-get update @@ -29,13 +29,13 @@ jobs: - run: npm ci --ignore-scripts - run: ./node_modules/.bin/playwright install --with-deps chromium firefox - run: just ci - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: extension-bundle path: '*.shell-extension.zip' if-no-files-found: error retention-days: 90 - - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3 + - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 if: github.event_name == 'push' && github.ref == 'refs/heads/main' with: path: docs diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index cd0c32f..0e9e236 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -19,7 +19,7 @@ jobs: name: github-pages url: ${{ steps.deploy.outputs.page_url }} steps: - - uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4 + - uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 id: deploy with: artifact_name: github-pages diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 27e8b3e..7ba150f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -22,9 +22,9 @@ jobs: with: fetch-depth: 0 persist-credentials: false - - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 + - uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1 with: - version: 2026.9.1 + version: 2026.10.1 cache: false - name: Verify tag and tested commit id: verify @@ -50,14 +50,14 @@ jobs: contents: write # Create the release and attach its tested ZIP. actions: read # Inspect workflow runs and download their tested artifacts. steps: - - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 + - uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1 with: - version: 2026.9.1 + version: 2026.10.1 cache: false mise_toml: | [tools] - gh = "2.99.0" - - uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5 + gh = "2.102.0" + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: extension-bundle run-id: ${{ needs.verify.outputs.run }} diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index dccb6d4..3352dd5 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -22,11 +22,11 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + - uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: javascript-typescript,python queries: security-extended - - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + - uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 scanners: name: scanners if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' @@ -37,8 +37,8 @@ jobs: with: fetch-depth: 0 persist-credentials: false - - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 + - uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1 with: - version: 2026.9.1 + version: 2026.10.1 - run: npm ci --ignore-scripts - run: just security diff --git a/.github/workflows/sonar.yml b/.github/workflows/sonar.yml index 7c0ec87..5685c68 100644 --- a/.github/workflows/sonar.yml +++ b/.github/workflows/sonar.yml @@ -22,9 +22,9 @@ jobs: with: fetch-depth: 0 persist-credentials: false - - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 + - uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1 with: - version: 2026.9.1 + version: 2026.10.1 - name: Require Sonar configuration env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} diff --git a/.github/workflows/template.yml b/.github/workflows/template.yml index 5feedf4..8b2f8b4 100644 --- a/.github/workflows/template.yml +++ b/.github/workflows/template.yml @@ -17,7 +17,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 + - uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1 with: - version: 2026.9.1 + version: 2026.10.1 - run: just template-check template-status diff --git a/mise.toml b/mise.toml index 06797f4..a058966 100644 --- a/mise.toml +++ b/mise.toml @@ -1,18 +1,18 @@ # Exact tool versions shared by every Quick extension. [tools] node = "24.21.0" -python = "3.14.7" -uv = "0.12.9" +python = "3.14.8" +uv = "0.12.22" "pipx:coverage" = "7.16.2" just = "1.58.0" -ruff = "0.16.9" +ruff = "0.16.10" actionlint = "1.7.12" gitleaks = "8.30.1" osv-scanner = "2.6.0" shellcheck = "0.11.0" -trivy = "0.74.0" +trivy = "0.75.0" zizmor = "1.30.1" -gh = "2.99.0" +gh = "2.102.0" sonar-scanner-cli = "8.1.0.6389" [env] diff --git a/package-lock.json b/package-lock.json index 3b8eeb6..610dc11 100644 --- a/package-lock.json +++ b/package-lock.json @@ -12,12 +12,12 @@ "@axe-core/playwright": "4.13.0", "@eslint/js": "10.0.1", "@playwright/test": "1.63.0", - "@vitest/coverage-v8": "5.0.2", - "eslint": "10.11.0", - "eslint-plugin-security": "4.0.1", - "globals": "17.12.0", + "@vitest/coverage-v8": "5.0.3", + "eslint": "10.12.0", + "eslint-plugin-security": "4.2.0", + "globals": "17.13.0", "prettier": "3.9.9", - "vitest": "5.0.2" + "vitest": "5.0.3" }, "engines": { "node": ">=24" @@ -729,9 +729,9 @@ "license": "MIT" }, "node_modules/@vitest/coverage-v8": { - "version": "5.0.2", - "resolved": "https://registry.npmjs.org/@vitest/coverage-v8/-/coverage-v8-5.0.2.tgz", - "integrity": "sha512-3ffHBEi8DOOBLwIGBhOBZbRfYFYWjMUuxZicONdhuFEFEG5AVsMOSrVeuROskqnqpbOmEJwxM2eTVZ9N3a1t+A==", + "version": "5.0.3", + "resolved": "https://registry.npmjs.org/@vitest/coverage-v8/-/coverage-v8-5.0.3.tgz", + "integrity": "sha512-+klsyz7BvT1vCU28Zkfzms1Ia78XD0V41U3FUtRaa3S+vOr/EXvK1O6BvVD7l1RzEjm6SONR2aybOvDDf9u0mQ==", "dev": true, "license": "MIT", "dependencies": { @@ -748,8 +748,8 @@ "url": "https://opencollective.com/vitest" }, "peerDependencies": { - "@vitest/browser": "5.0.2", - "vitest": "5.0.2" + "@vitest/browser": "5.0.3", + "vitest": "5.0.3" }, "peerDependenciesMeta": { "@vitest/browser": { @@ -781,14 +781,14 @@ } }, "node_modules/@vitest/mocker": { - "version": "5.0.2", - "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-5.0.2.tgz", - "integrity": "sha512-Z5FS00Q1SJHkB35xATsmWGdQ5WA1/0MV3CDjqyv7GavHv1OfOj145MNfHOlHk7QLes21dKFDHr8EO2zvL+9WGA==", + "version": "5.0.3", + "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-5.0.3.tgz", + "integrity": "sha512-T8sWAIbkSyAjkwTcaEc3Iu0o9A27X1/kdXrizhZkGuSKScRQtRzclfAMpOTcGdXCsqxeWlpGy3XjqaW8CpLORg==", "dev": true, "license": "MIT", "dependencies": { "@jridgewell/trace-mapping": "0.3.31", - "@vitest/spy": "5.0.2", + "@vitest/spy": "5.0.3", "estree-walker": "^3.0.3", "magic-string": "^1.2.3" }, @@ -809,9 +809,9 @@ } }, "node_modules/@vitest/spy": { - "version": "5.0.2", - "resolved": "https://registry.npmjs.org/@vitest/spy/-/spy-5.0.2.tgz", - "integrity": "sha512-Ijc7T1nT9efNb5LxvjaBrEqw3f/QwUv5EE0nKqZxgqsaV/FxAAZ8baGylA8X/Z2oS4Lp+K74Jr6dTJsDKxJDeg==", + "version": "5.0.3", + "resolved": "https://registry.npmjs.org/@vitest/spy/-/spy-5.0.3.tgz", + "integrity": "sha512-XhFysQTB8AZ+P4gMi+Lpo99vg2AZi0qKpaB9yXQl37+CaMEAPO3iH/wGVnSyL5MPERiLezpqTVtrR6UZH5GCXg==", "dev": true, "license": "MIT", "funding": { @@ -1009,9 +1009,9 @@ } }, "node_modules/eslint": { - "version": "10.11.0", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.11.0.tgz", - "integrity": "sha512-P7a6UEEqb9G95MYAtqkmsTbVXIYyzIfl6NGOIJk162PaahFxFyeGcrlXYFSiagECg4sEm8IseJdZBKR3rx6MsQ==", + "version": "10.12.0", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.12.0.tgz", + "integrity": "sha512-npHjrHb2o4ehH3mE+YuxABR+0gyb0aVWCIolgJDArwCiHEIsonBm3ZKjel5b0U5+a+MbEvIyRCGCzD3eKKK2NA==", "dev": true, "license": "MIT", "workspaces": [ @@ -1068,9 +1068,9 @@ } }, "node_modules/eslint-plugin-security": { - "version": "4.0.1", - "resolved": "https://registry.npmjs.org/eslint-plugin-security/-/eslint-plugin-security-4.0.1.tgz", - "integrity": "sha512-/lZCkOxPOWaf1jXAqgICrS8St3BMBccIPvhOSUYuV6VCr1o5nFVG998FnTLt6w2Nxb8Uo0nM8fzmnhp+GY/aEg==", + "version": "4.2.0", + "resolved": "https://registry.npmjs.org/eslint-plugin-security/-/eslint-plugin-security-4.2.0.tgz", + "integrity": "sha512-LL5jbxRzlNv0vkSyBtbO7qAPofqd3xlseAFTDevyDTMmScjBrLv2/VkQ7ZFQxBaFYsa3dhpE7NcV+JkwJ9l6RQ==", "dev": true, "license": "Apache-2.0", "dependencies": { @@ -1314,9 +1314,9 @@ } }, "node_modules/globals": { - "version": "17.12.0", - "resolved": "https://registry.npmjs.org/globals/-/globals-17.12.0.tgz", - "integrity": "sha512-cezEd/DTyyht9cvSSURyygXPfy04GtWO/5e6ZPvH7fCtjKz9PYOmuawphw1Ctd1f6C+5JypXfGD7ahNMXvevBA==", + "version": "17.13.0", + "resolved": "https://registry.npmjs.org/globals/-/globals-17.13.0.tgz", + "integrity": "sha512-RwMTC61u7hrG3ZJMkZQOK4JLJrKS8QtoTii63EmWvFXHqycY9FObBJQCbsLxSO8kjKhWE5kV1GC+Vb1g3RI0Zg==", "dev": true, "license": "MIT", "engines": { @@ -2279,14 +2279,14 @@ } }, "node_modules/vitest": { - "version": "5.0.2", - "resolved": "https://registry.npmjs.org/vitest/-/vitest-5.0.2.tgz", - "integrity": "sha512-7MQrx9pDv5aHiUcovIb/70Ys3tgtkUVgCtledvKdCmEO+/1Dicq5ZqoSxOW034m03oqC+oHOKui2dM6qtMLoJg==", + "version": "5.0.3", + "resolved": "https://registry.npmjs.org/vitest/-/vitest-5.0.3.tgz", + "integrity": "sha512-xMw97S3rjdtj5dkVat7jCsqWBpvchs3RlpQctUqwJD0KkERk40vz2fJ77lDwW/Vzh/pk18eItYAzkodhSes3jQ==", "dev": true, "license": "MIT", "dependencies": { "@types/chai": "^5.2.2", - "@vitest/mocker": "5.0.2", + "@vitest/mocker": "5.0.3", "chai": "^6.2.2", "es-module-lexer": "^2.3.2", "expect-type": "^1.4.0", @@ -2297,7 +2297,7 @@ "tinybench": "^6.1.4", "tinyexec": "^1.3.0", "tinyglobby": "^0.2.17", - "why-is-node-running": "^3.2.1" + "why-is-node-running": "3.2.1" }, "bin": { "vitest": "vitest.mjs" @@ -2312,12 +2312,12 @@ "@edge-runtime/vm": "*", "@opentelemetry/api": "^1.9.0", "@types/node": "^22.0.0 || >=24.0.0", - "@vitest/browser-playwright": "5.0.2", - "@vitest/browser-preview": "5.0.2", + "@vitest/browser-playwright": "5.0.3", + "@vitest/browser-preview": "5.0.3", "@vitest/browser-webdriverio": "^5.0.0-beta.5 || >=5.0.0", - "@vitest/coverage-istanbul": "5.0.2", - "@vitest/coverage-v8": "5.0.2", - "@vitest/ui": "5.0.2", + "@vitest/coverage-istanbul": "5.0.3", + "@vitest/coverage-v8": "5.0.3", + "@vitest/ui": "5.0.3", "happy-dom": "*", "jsdom": "*", "vite": "^6.4.0 || ^7.0.0 || ^8.0.0" @@ -2378,9 +2378,9 @@ } }, "node_modules/why-is-node-running": { - "version": "3.2.2", - "resolved": "https://registry.npmjs.org/why-is-node-running/-/why-is-node-running-3.2.2.tgz", - "integrity": "sha512-NKUzAelcoCXhXL4dJzKIwXeR8iEVqsA0Lq6Vnd0UXvgaKbzVo4ZTHROF2Jidrv+SgxOQ03fMinnNhzZATxOD3A==", + "version": "3.2.1", + "resolved": "https://registry.npmjs.org/why-is-node-running/-/why-is-node-running-3.2.1.tgz", + "integrity": "sha512-Tb2FUhB4vUsGQlfSquQLYkApkuPAFQXGFzxWKHHumVz2dK+X1RUm/HnID4+TfIGYJ1kTcwOaCk/buYCEJr6YjQ==", "dev": true, "license": "MIT", "bin": { diff --git a/package.json b/package.json index 43f4961..dc5d34d 100644 --- a/package.json +++ b/package.json @@ -8,12 +8,12 @@ "@axe-core/playwright": "4.13.0", "@eslint/js": "10.0.1", "@playwright/test": "1.63.0", - "@vitest/coverage-v8": "5.0.2", - "eslint": "10.11.0", - "eslint-plugin-security": "4.0.1", - "globals": "17.12.0", + "@vitest/coverage-v8": "5.0.3", + "eslint": "10.12.0", + "eslint-plugin-security": "4.2.0", + "globals": "17.13.0", "prettier": "3.9.9", - "vitest": "5.0.2" + "vitest": "5.0.3" }, "engines": { "node": ">=24" diff --git a/quick-template.lock.json b/quick-template.lock.json index ab690bc..63bc8aa 100644 --- a/quick-template.lock.json +++ b/quick-template.lock.json @@ -1,5 +1,5 @@ { "$schema": "quick-template.schema.json", "repository": "Ghost-Assembly/quick-template", - "revision": "40e31d2739e0c94162c707adb6851cc207ce6d2c" + "revision": "174a20f771bc1b25d19b5547820fa3647c752a1a" }