Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Configure Renovate #56

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Configure Renovate #56

wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Feb 20, 2023

Mend Renovate

Welcome to Renovate! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin.

🚦 To activate Renovate, merge this Pull Request. To disable Renovate, simply close this Pull Request unmerged.


Detected Package Files

  • .github/workflows/main.yml (github-actions)
  • package.json (npm)

Configuration Summary

Based on the default config's presets, Renovate will:

  • Start dependency updates only once this onboarding PR is merged
  • Enable Renovate Dependency Dashboard creation.
  • If Renovate detects semantic commits, it will use semantic commit type fix for dependencies and chore for all others.
  • Ignore node_modules, bower_components, vendor and various test/tests directories.
  • Automatically detect the best rangeStrategy to use.
  • Rate limit PR creation to a maximum of two per hour.
  • Limit to maximum 10 open PRs at any time.
  • Group known monorepo packages together.
  • Use curated list of recommended non-monorepo package groupings.
  • A collection of workarounds for known problems with packages.

🔡 Would you like to change the way Renovate is upgrading your dependencies? Simply edit the renovate.json in this branch with your custom config and the list of Pull Requests in the "What to Expect" section below will be updated the next time Renovate runs.


What to Expect

With your current configuration, Renovate will create 48 Pull Requests:

Update dependency @​hapi/hoek to 8.5.1 [SECURITY]
  • Branch name: renovate/npm-@hapi/hoek-vulnerability
  • Merge into: master
  • Upgrade @​hapi/hoek to 8.5.1
Update dependency ajv to 6.12.3 [SECURITY]
  • Branch name: renovate/npm-ajv-vulnerability
  • Merge into: master
  • Upgrade ajv to 6.12.3
Update dependency axios to 0.21.1 [SECURITY]
  • Branch name: renovate/npm-axios-vulnerability
  • Merge into: master
  • Upgrade axios to 0.21.1
Update dependency browserslist to 4.16.5 [SECURITY]
  • Branch name: renovate/npm-browserslist-vulnerability
  • Merge into: master
  • Upgrade browserslist to 4.16.5
Update dependency decode-uri-component to 0.2.1 [SECURITY]
  • Branch name: renovate/npm-decode-uri-component-vulnerability
  • Merge into: master
  • Upgrade decode-uri-component to 0.2.1
Update dependency dns-packet to 1.3.2 [SECURITY]
  • Branch name: renovate/npm-dns-packet-vulnerability
  • Merge into: master
  • Upgrade dns-packet to 1.3.2
Update dependency dot-prop to 4.2.1 [SECURITY]
  • Branch name: renovate/npm-dot-prop-vulnerability
  • Merge into: master
  • Upgrade dot-prop to 4.2.1
Update dependency elliptic to 6.5.4 [SECURITY]
  • Branch name: renovate/npm-elliptic-vulnerability
  • Merge into: master
  • Upgrade elliptic to 6.5.4
Update dependency eventsource to 1.1.1 [SECURITY]
  • Branch name: renovate/npm-eventsource-vulnerability
  • Merge into: master
  • Upgrade eventsource to 1.1.1
Update dependency follow-redirects to 1.14.8 [SECURITY]
  • Branch name: renovate/npm-follow-redirects-vulnerability
  • Merge into: master
  • Upgrade follow-redirects to 1.14.8
Update dependency glob-parent to 5.1.2 [SECURITY]
  • Branch name: renovate/npm-glob-parent-vulnerability
  • Merge into: master
  • Upgrade glob-parent to 5.1.2
Update dependency handlebars to 4.7.7 [SECURITY]
  • Branch name: renovate/npm-handlebars-vulnerability
  • Merge into: master
  • Upgrade handlebars to 4.7.7
Update dependency hosted-git-info to 2.8.9 [SECURITY]
  • Branch name: renovate/npm-hosted-git-info-vulnerability
  • Merge into: master
  • Upgrade hosted-git-info to 2.8.9
Update dependency http-proxy to 1.18.1 [SECURITY]
  • Branch name: renovate/npm-http-proxy-vulnerability
  • Merge into: master
  • Upgrade http-proxy to 1.18.1
Update dependency immer to 9.0.6 [SECURITY]
  • Branch name: renovate/npm-immer-vulnerability
  • Merge into: master
  • Upgrade immer to 9.0.6
Update dependency ini to 1.3.6 [SECURITY]
  • Branch name: renovate/npm-ini-vulnerability
  • Merge into: master
  • Upgrade ini to 1.3.6
Update dependency is-svg to 4.2.2 [SECURITY]
  • Branch name: renovate/npm-is-svg-vulnerability
  • Merge into: master
  • Upgrade is-svg to 4.2.2
Update dependency jsdom to 16.5.0 [SECURITY]
  • Branch name: renovate/npm-jsdom-vulnerability
  • Merge into: master
  • Upgrade jsdom to 16.5.0
Update dependency json5 to 2.2.2 [SECURITY]
  • Branch name: renovate/npm-json5-vulnerability
  • Merge into: master
  • Upgrade json5 to 2.2.2
Update dependency loader-utils to 1.4.2 [SECURITY]
  • Branch name: renovate/npm-loader-utils-vulnerability
  • Merge into: master
  • Upgrade loader-utils to 1.4.2
Update dependency lodash to 4.17.21 [SECURITY]
  • Branch name: renovate/npm-lodash-vulnerability
  • Merge into: master
  • Upgrade lodash to 4.17.21
Update dependency merge-deep to 3.0.3 [SECURITY]
  • Branch name: renovate/npm-merge-deep-vulnerability
  • Merge into: master
  • Upgrade merge-deep to 3.0.3
Update dependency minimatch to 3.0.5 [SECURITY]
  • Branch name: renovate/npm-minimatch-vulnerability
  • Merge into: master
  • Upgrade minimatch to 3.0.5
Update dependency minimist to 1.2.6 [SECURITY]
  • Branch name: renovate/npm-minimist-vulnerability
  • Merge into: master
  • Upgrade minimist to 1.2.6
Update dependency node-forge to 1.3.0 [SECURITY]
  • Branch name: renovate/npm-node-forge-vulnerability
  • Merge into: master
  • Upgrade node-forge to 1.3.0
Update dependency node-notifier to 8.0.1 [SECURITY]
  • Branch name: renovate/npm-node-notifier-vulnerability
  • Merge into: master
  • Upgrade node-notifier to 8.0.1
Update dependency nth-check to 2.0.1 [SECURITY]
  • Branch name: renovate/npm-nth-check-vulnerability
  • Merge into: master
  • Upgrade nth-check to 2.0.1
Update dependency path-parse to 1.0.7 [SECURITY]
  • Branch name: renovate/npm-path-parse-vulnerability
  • Merge into: master
  • Upgrade path-parse to 1.0.7
Update dependency postcss to 7.0.36 [SECURITY]
  • Branch name: renovate/npm-postcss-vulnerability
  • Merge into: master
  • Upgrade postcss to 7.0.36
Update dependency qs to 6.5.3 [SECURITY]
  • Branch name: renovate/npm-qs-vulnerability
  • Merge into: master
  • Upgrade qs to 6.5.3
Update dependency react-dev-utils to 11.0.4 [SECURITY]
  • Branch name: renovate/npm-react-dev-utils-vulnerability
  • Merge into: master
  • Upgrade react-dev-utils to 11.0.4
Update dependency serialize-javascript to 3.1.0 [SECURITY]
  • Branch name: renovate/npm-serialize-javascript-vulnerability
  • Merge into: master
  • Upgrade serialize-javascript to 3.1.0
Update dependency shell-quote to 1.7.3 [SECURITY]
  • Branch name: renovate/npm-shell-quote-vulnerability
  • Merge into: master
  • Upgrade shell-quote to 1.7.3
Update dependency sockjs to 0.3.20 [SECURITY]
  • Branch name: renovate/npm-sockjs-vulnerability
  • Merge into: master
  • Upgrade sockjs to 0.3.20
Update dependency ssri to 6.0.2 [SECURITY]
  • Branch name: renovate/npm-ssri-vulnerability
  • Merge into: master
  • Upgrade ssri to 6.0.2
Update dependency terser to 4.8.1 [SECURITY]
  • Branch name: renovate/npm-terser-vulnerability
  • Merge into: master
  • Upgrade terser to 4.8.1
Update dependency tmpl to 1.0.5 [SECURITY]
  • Branch name: renovate/npm-tmpl-vulnerability
  • Merge into: master
  • Upgrade tmpl to 1.0.5
Update dependency url-parse to 1.5.9 [SECURITY]
  • Branch name: renovate/npm-url-parse-vulnerability
  • Merge into: master
  • Upgrade url-parse to 1.5.9
Update dependency y18n to 4.0.1 [SECURITY]
  • Branch name: renovate/npm-y18n-vulnerability
  • Merge into: master
  • Upgrade y18n to 4.0.1
Update dependency yargs-parser to 13.1.2 [SECURITY]
  • Branch name: renovate/npm-yargs-parser-vulnerability
  • Merge into: master
  • Upgrade yargs-parser to 13.1.2
Update dependency axios to ^0.27.0
  • Schedule: ["at any time"]
  • Branch name: renovate/axios-0.x
  • Merge into: master
  • Upgrade axios to ^0.27.0
Update dependency react-scripts to v3.4.4
  • Schedule: ["at any time"]
  • Branch name: renovate/react-scripts-3.x
  • Merge into: master
  • Upgrade react-scripts to 3.4.4
Update actions/checkout action to v3
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-checkout-3.x
  • Merge into: master
  • Upgrade actions/checkout to v3
Update dependency axios to v1
  • Schedule: ["at any time"]
  • Branch name: renovate/axios-1.x
  • Merge into: master
  • Upgrade axios to ^1.0.0
Update dependency react-redux to v8
  • Schedule: ["at any time"]
  • Branch name: renovate/react-redux-8.x
  • Merge into: master
  • Upgrade react-redux to ^8.0.0
Update dependency react-router-dom to v6
  • Schedule: ["at any time"]
  • Branch name: renovate/major-react-router-monorepo
  • Merge into: master
  • Upgrade react-router-dom to ^6.0.0
Update dependency react-scripts to v5
  • Schedule: ["at any time"]
  • Branch name: renovate/react-scripts-5.x
  • Merge into: master
  • Upgrade react-scripts to 5.0.1
Update react monorepo to v18 (major)
  • Schedule: ["at any time"]
  • Branch name: renovate/major-react-monorepo
  • Merge into: master
  • Upgrade react to ^18.0.0
  • Upgrade react-dom to ^18.0.0

🚸 Branch creation will be limited to maximum 2 per hour, so it doesn't swamp any CI resources or overwhelm the project. See docs for prhourlylimit for details.


❓ Got questions? Check out Renovate's Docs, particularly the Getting Started section.
If you need any further assistance then you can also request help here.


This PR has been generated by Mend Renovate. View repository job log here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants