Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: octokit/auth-token.js
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v2.5.0
Choose a base ref
...
head repository: octokit/auth-token.js
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v3.0.0
Choose a head ref

Commits on Sep 17, 2021

  1. Copy the full SHA
    4cfd245 View commit details
  2. Copy the full SHA
    8202acc View commit details

Commits on Sep 20, 2021

  1. build(deps): lock file maintenance

    Co-authored-by: Renovate Bot <bot@renovateapp.com>
    renovate[bot] and renovate-bot authored Sep 20, 2021
    Copy the full SHA
    aa73975 View commit details

Commits on Sep 27, 2021

  1. build(deps): lock file maintenance

    Co-authored-by: Renovate Bot <bot@renovateapp.com>
    renovate[bot] and renovate-bot authored Sep 27, 2021
    Copy the full SHA
    28862ce View commit details

Commits on Oct 4, 2021

  1. build(deps): lock file maintenance

    Co-authored-by: Renovate Bot <bot@renovateapp.com>
    renovate[bot] and renovate-bot authored Oct 4, 2021
    1
    Copy the full SHA
    9c313b2 View commit details

Commits on Apr 12, 2022

  1. Copy the full SHA
    4177368 View commit details
  2. build(deps): bump node-fetch from 2.6.5 to 2.6.7 (#220)

    Bumps [node-fetch](https://github.com/node-fetch/node-fetch) from 2.6.5 to 2.6.7.
    - [Release notes](https://github.com/node-fetch/node-fetch/releases)
    - [Commits](node-fetch/node-fetch@v2.6.5...v2.6.7)
    
    ---
    updated-dependencies:
    - dependency-name: node-fetch
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2022
    Copy the full SHA
    682997f View commit details
  3. build(deps): bump minimist from 1.2.5 to 1.2.6 (#215)

    Bumps [minimist](https://github.com/substack/minimist) from 1.2.5 to 1.2.6.
    - [Release notes](https://github.com/substack/minimist/releases)
    - [Commits](https://github.com/substack/minimist/compare/1.2.5...1.2.6)
    
    ---
    updated-dependencies:
    - dependency-name: minimist
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Oscar Dominguez <dominguez.celada@gmail.com>
    dependabot[bot] and oscard0m authored Apr 12, 2022
    Copy the full SHA
    99869ea View commit details

Commits on Apr 13, 2022

  1. ci(codeql): remove unnecessary step to checkout HEAD~2 from PRs (#219)

    Co-authored-by: wolfy1339 <4595477+wolfy1339@users.noreply.github.com>
    oscard0m and wolfy1339 authored Apr 13, 2022
    Copy the full SHA
    769ee2f View commit details

Commits on Jun 17, 2022

  1. Create SECURITY.md

    nickfloyd authored Jun 17, 2022
    Copy the full SHA
    89e949e View commit details
  2. Copy the full SHA
    f9fba03 View commit details
  3. build(deps-dev): bump semantic-release from 18.0.0 to 19.0.3

    Bumps [semantic-release](https://github.com/semantic-release/semantic-release) from 18.0.0 to 19.0.3.
    - [Release notes](https://github.com/semantic-release/semantic-release/releases)
    - [Commits](semantic-release/semantic-release@v18.0.0...v19.0.3)
    
    ---
    updated-dependencies:
    - dependency-name: semantic-release
      dependency-type: direct:development
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 17, 2022
    Copy the full SHA
    4674394 View commit details
  4. build(deps): bump semver-regex from 3.1.3 to 3.1.4

    Bumps [semver-regex](https://github.com/sindresorhus/semver-regex) from 3.1.3 to 3.1.4.
    - [Release notes](https://github.com/sindresorhus/semver-regex/releases)
    - [Commits](https://github.com/sindresorhus/semver-regex/commits/v3.1.4)
    
    ---
    updated-dependencies:
    - dependency-name: semver-regex
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 17, 2022
    Copy the full SHA
    f0725bd View commit details

Commits on Jun 23, 2022

  1. chore(deps): update dependency prettier to v2.7.1 (#224)

    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Jun 23, 2022
    Copy the full SHA
    547c166 View commit details
  2. chore(deps): update jest monorepo to v28 (#225)

    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Jun 23, 2022
    Copy the full SHA
    8232d90 View commit details

Commits on Jun 24, 2022

  1. ci(action): update actions/checkout action to v3 (#227)

    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Jun 24, 2022
    Copy the full SHA
    1e2cb92 View commit details
  2. ci(action): update actions/cache action to v3 (#226)

    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Jun 24, 2022
    Copy the full SHA
    54d1163 View commit details
  3. ci(action): update actions/setup-node action to v3 (#228)

    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Jun 24, 2022
    Copy the full SHA
    c8331fa View commit details
  4. ci(action): update github/codeql-action action to v2 (#229)

    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Jun 24, 2022
    Copy the full SHA
    051b335 View commit details
  5. Copy the full SHA
    f23f340 View commit details

Commits on Jul 7, 2022

  1. ci: stop testing against NodeJS v10, v12 (#232)

    * build(package): set minimal node version in engines field to v14
    BREAKING CHANGE: Drop support for NodeJS v10, v12
    
    * ci: stop testing against NodeJS v10, v12
    
    * ci: stop testing against NodeJS v10, v12
    
    * ci: stop testing against NodeJS v10, v12
    
    * ci: stop testing against NodeJS v10, v12
    wolfy1339 authored Jul 7, 2022
    Copy the full SHA
    8c56e5c View commit details
Showing with 16,685 additions and 2,344 deletions.
  1. +6 −9 .github/workflows/codeql.yml
  2. +3 −3 .github/workflows/release.yml
  3. +6 −7 .github/workflows/test.yml
  4. +5 −5 .github/workflows/update-prettier.yml
  5. +11 −0 SECURITY.md
  6. +16,641 −2,313 package-lock.json
  7. +13 −7 package.json
15 changes: 6 additions & 9 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -2,6 +2,8 @@ name: "Code scanning - action"

on:
push:
branches-ignore:
- "dependabot/**"
pull_request:
schedule:
- cron: '0 19 * * 0'
@@ -14,28 +16,23 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v2
uses: actions/checkout@v3
with:
# We must fetch at least the immediate parents so that if this is
# a pull request then we can checkout the head.
fetch-depth: 2

# If this run was triggered by a pull request event, then checkout
# the head of the pull request instead of the merge commit.
- run: git checkout HEAD^2
if: ${{ github.event_name == 'pull_request' }}

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v1
uses: github/codeql-action/init@v2
# Override language selection by uncommenting this and choosing your languages
# with:
# languages: go, javascript, csharp, python, cpp, java

# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v1
uses: github/codeql-action/autobuild@v2

# ℹ️ Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl
@@ -49,4 +46,4 @@ jobs:
# make release

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v1
uses: github/codeql-action/analyze@v2
6 changes: 3 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -12,10 +12,10 @@ jobs:
name: release
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- uses: actions/setup-node@v2
- uses: actions/checkout@v3
- uses: actions/setup-node@v3
with:
node-version: "12.x"
node-version: 16
cache: npm
- run: npm ci
- run: npm run build
13 changes: 6 additions & 7 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
@@ -14,19 +14,18 @@ jobs:
strategy:
matrix:
node_version:
- 10
- 12
- 14
- 16
- 18

steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v3
- name: Setup Node v${{ matrix.node_version }}
uses: actions/setup-node@v2
uses: actions/setup-node@v3
with:
node-version: ${{ matrix.node_version }}
cache: npm
- uses: actions/cache@v2
- uses: actions/cache@v3
with:
path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
@@ -39,8 +38,8 @@ jobs:
runs-on: ubuntu-latest
needs: test_matrix
steps:
- uses: actions/checkout@v2
- uses: actions/setup-node@v2
- uses: actions/checkout@v3
- uses: actions/setup-node@v3
with:
node-version: 16
cache: npm
10 changes: 5 additions & 5 deletions .github/workflows/update-prettier.yml
Original file line number Diff line number Diff line change
@@ -8,17 +8,17 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@master
- uses: actions/setup-node@v2
- uses: actions/setup-node@v3
with:
version: 12
cache: npm
node-version: 16
- run: npm ci
- run: "npm run lint:fix"
- run: npm run lint:fix
- uses: gr2m/create-or-update-pull-request-action@v1.x
env:
GITHUB_TOKEN: "${{ secrets.OCTOKITBOT_PAT }}"
GITHUB_TOKEN: ${{ secrets.OCTOKITBOT_PAT }}
with:
title: Prettier updated
body: An update to prettier required updates to your code.
branch: "${{ github.ref }}"
branch: ${{ github.ref }}
commit-message: "style: prettier"
11 changes: 11 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Security Policy

Thanks for helping make GitHub Open Source Software safe for everyone.

GitHub takes the security of our software products and services seriously, including all of the open source code repositories managed through our GitHub organizations, such as [Octokit](https://github.com/octokit).

Even though [open source repositories are outside of the scope of our bug bounty program](https://bounty.github.com/index.html#scope) and therefore not eligible for bounty rewards, we want to make sure that your finding gets passed along to the maintainers of this project for remediation.

## Reporting a Vulnerability

Since this source is part of [Octokit](https://github.com/octokit) (a GitHub organization) we ask that you follow the guidelines [here](https://github.com/github/.github/blob/master/SECURITY.md#reporting-security-issues) to report anything that you might've found.
Loading