Skip to content

Commit 223bd5f

Browse files
pull[bot]qwerty541dependabot[bot]GitHub Readme Stats Bot
authored
[pull] master from anuraghazra:master (#9)
* Refactor: Wakatime card: Add missing return statements for helper functions (anuraghazra#2998) * Refactor: Wakatime card: Add missing return statements for helper functions * dev * Refactor: Repo card: Fixed type error in iconWithLabel function (anuraghazra#2999) * Refactor: Improve docstring for lowercaseTrim utils function (anuraghazra#3002) * Refactor: Improve docstring for dateDiff utils function (anuraghazra#3001) * CI: skx/github-action-tester dependency pinned by hash (anuraghazra#3014) * Refactor: Fix MissingParamError class constructor docstring (anuraghazra#3012) * Refactor: Fix docstring for getCardColors utils function (anuraghazra#3011) * I10n: Add partially-missing Uzbek translations (anuraghazra#3018) * Stats card: Add Uzbek to long languages (anuraghazra#3019) * Docs: Add security policy (anuraghazra#2908) * Build(deps-dev): Bump jest from 29.6.1 to 29.6.2 (anuraghazra#3026) Bumps [jest](https://github.com/facebook/jest/tree/HEAD/packages/jest) from 29.6.1 to 29.6.2. - [Release notes](https://github.com/facebook/jest/releases) - [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/jest/commits/v29.6.2/packages/jest) --- updated-dependencies: - dependency-name: jest dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Alexandr <[email protected]> * Build(deps-dev): Bump eslint from 8.45.0 to 8.46.0 (anuraghazra#3025) Bumps [eslint](https://github.com/eslint/eslint) from 8.45.0 to 8.46.0. - [Release notes](https://github.com/eslint/eslint/releases) - [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md) - [Commits](eslint/eslint@v8.45.0...v8.46.0) --- updated-dependencies: - dependency-name: eslint dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Alexandr <[email protected]> * Build(deps-dev): Bump eslint-config-prettier from 8.8.0 to 8.9.0 (anuraghazra#3027) Bumps [eslint-config-prettier](https://github.com/prettier/eslint-config-prettier) from 8.8.0 to 8.9.0. - [Changelog](https://github.com/prettier/eslint-config-prettier/blob/main/CHANGELOG.md) - [Commits](prettier/eslint-config-prettier@v8.8.0...v8.9.0) --- updated-dependencies: - dependency-name: eslint-config-prettier dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Build(deps-dev): Bump jest-environment-jsdom from 29.6.1 to 29.6.2 (anuraghazra#3024) Bumps [jest-environment-jsdom](https://github.com/facebook/jest/tree/HEAD/packages/jest-environment-jsdom) from 29.6.1 to 29.6.2. - [Release notes](https://github.com/facebook/jest/releases) - [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/jest/commits/v29.6.2/packages/jest-environment-jsdom) --- updated-dependencies: - dependency-name: jest-environment-jsdom dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Build(deps): Bump rickstaa/top-issues-action from 1.3.29 to 1.3.32 (anuraghazra#3023) Bumps [rickstaa/top-issues-action](https://github.com/rickstaa/top-issues-action) from 1.3.29 to 1.3.32. - [Release notes](https://github.com/rickstaa/top-issues-action/releases) - [Commits](rickstaa/top-issues-action@f31962c...c66e5d5) --- updated-dependencies: - dependency-name: rickstaa/top-issues-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Build(deps): Bump github/codeql-action from 2.21.0 to 2.21.2 (anuraghazra#3022) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.21.0 to 2.21.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@1813ca7...0ba4244) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Build(deps): Bump rickstaa/empty-issues-closer-action (anuraghazra#3021) Bumps [rickstaa/empty-issues-closer-action](https://github.com/rickstaa/empty-issues-closer-action) from 1.1.0 to 1.1.2. - [Release notes](https://github.com/rickstaa/empty-issues-closer-action/releases) - [Commits](rickstaa/empty-issues-closer-action@773bc31...09d48db) --- updated-dependencies: - dependency-name: rickstaa/empty-issues-closer-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * CI: Fix theme preview workflow (anuraghazra#3017) * Refactor: Fix docstring for rankIcon function (anuraghazra#3029) * CI: Add SECURITY.md to pull requests labeler (anuraghazra#3030) * Refactor: Wakatime card: Add missing returns statement for createTextNode function (anuraghazra#3032) * Refactor: Wakatime card: Use @typedef to resolve eslint errors (anuraghazra#3033) * CI: Fix theme preview workflow (Attempt 2) (anuraghazra#3034) * Themes: Add test AI-generated themes to check preview workflow (anuraghazra#3028) * Themes: Add test theme to check preview workflow * dev * dev * dev * docs(theme): Auto update theme readme (anuraghazra#3038) Co-authored-by: GitHub Readme Stats Bot <[email protected]> * Refactor: Wakatime card: Use typedef tags to resolve eslint errors (anuraghazra#3037) * Refactor: Top langs card: Fix returns tag in docstrings (anuraghazra#3036) * Refactor: Stats card: Use typedef tags to resolve eslint errors (anuraghazra#3039) * Refactor: Top langs card: Use typedef tags to resolve eslint errors (anuraghazra#3040) * Refactor: Repo card: Use typedef tags inside data fetcher to resolve eslint errors (anuraghazra#3043) --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: Alexandr Garbuzov <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: GitHub Readme Stats Bot <[email protected]>
1 parent c213ca7 commit 223bd5f

18 files changed

+864
-702
lines changed

.github/labeler.yml

+1
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ documentation:
77
- readme.md
88
- CONTRIBUTING.md
99
- CODE_OF_CONDUCT.md
10+
- SECURITY.md
1011
dependencies:
1112
- package.json
1213
- package-lock.json

.github/workflows/empty-issues-closer.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929
- uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3 # NOTE: Retrieve issue templates.
3030

3131
- name: Run empty issues closer action
32-
uses: rickstaa/empty-issues-closer-action@773bc3171b488f30f89cb17bb86d8fd85bcecf0c # v1.1.0
32+
uses: rickstaa/empty-issues-closer-action@09d48dba81e64a390dce550d643fb54cd1636d97 # v1.1.2
3333
env:
3434
github_token: ${{ secrets.GITHUB_TOKEN }}
3535
with:

.github/workflows/generate-theme-doc.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ jobs:
4949
CI: true
5050

5151
- name: Run Script
52-
uses: skx/github-action-tester@master
52+
uses: skx/github-action-tester@e29768ff4ff67be9d1fdbccd8836ab83233bebb1 # v0.10.0
5353
with:
5454
script: ./scripts/push-theme-readme.sh
5555
env:

.github/workflows/ossf-analysis.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,6 @@ jobs:
4343

4444
# required for Code scanning alerts
4545
- name: "Upload SARIF results to code scanning"
46-
uses: github/codeql-action/upload-sarif@1813ca74c3faaa3a2da2070b9b8a0b3e7373a0d8 # v2.21.0
46+
uses: github/codeql-action/upload-sarif@0ba4244466797eb048eb91a6cd43d5c03ca8bd05 # v2.21.2
4747
with:
4848
sarif_file: results.sarif

.github/workflows/top-issues-dashboard.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ jobs:
3434
runs-on: ubuntu-latest
3535
steps:
3636
- name: Run top issues action
37-
uses: rickstaa/top-issues-action@f31962cb26fb9d64bc0129d3e2bf3d109d7ae21f # v1.3.29
37+
uses: rickstaa/top-issues-action@c66e5d53ffc26f7ae020ff8454582884d4af4cdb # v1.3.32
3838
env:
3939
github_token: ${{ secrets.GITHUB_TOKEN }}
4040
with:

SECURITY.md

+39
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
# GitHub Readme Stats Security Policies and Procedures <!-- omit in toc -->
2+
3+
This document outlines security procedures and general policies for the
4+
GitHub Readme Stats project.
5+
6+
- [Reporting a Vulnerability](#reporting-a-vulnerability)
7+
- [Disclosure Policy](#disclosure-policy)
8+
9+
## Reporting a Vulnerability
10+
11+
The GitHub Readme Stats team and community take all security vulnerabilities
12+
seriously. Thank you for improving the security of our open source
13+
software. We appreciate your efforts and responsible disclosure and will
14+
make every effort to acknowledge your contributions.
15+
16+
Report security vulnerabilities by emailing the GitHub Readme Stats team at:
17+
18+
```
19+
20+
```
21+
22+
The lead maintainer will acknowledge your email within 24 hours, and will
23+
send a more detailed response within 48 hours indicating the next steps in
24+
handling your report. After the initial reply to your report, the security
25+
team will endeavor to keep you informed of the progress towards a fix and
26+
full announcement, and may ask for additional information or guidance.
27+
28+
Report security vulnerabilities in third-party modules to the person or
29+
team maintaining the module.
30+
31+
## Disclosure Policy
32+
33+
When the security team receives a security bug report, they will assign it
34+
to a primary handler. This person will coordinate the fix and release
35+
process, involving the following steps:
36+
37+
* Confirm the problem.
38+
* Audit code to find any potential similar problems.
39+
* Prepare fixes and release them as fast as possible.

0 commit comments

Comments
 (0)