Skip to content

Comments

Alert autofix 1577#1087

Open
Wbaker7702 wants to merge 56 commits intothecartercenter:mainfrom
Wbaker7702:alert-autofix-1577
Open

Alert autofix 1577#1087
Wbaker7702 wants to merge 56 commits intothecartercenter:mainfrom
Wbaker7702:alert-autofix-1577

Conversation

@Wbaker7702
Copy link

No description provided.

snyk-bot and others added 30 commits September 17, 2025 10:26
Snyk has created this PR to upgrade core-js from 3.25.1 to 3.45.1.

See this package in yarn:
core-js

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade @babel/plugin-proposal-decorators from 7.19.0 to 7.28.0.

See this package in yarn:
@babel/plugin-proposal-decorators

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade @babel/preset-react from 7.18.6 to 7.27.1.

See this package in yarn:
@babel/preset-react

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade @babel/helper-string-parser from 7.18.10 to 7.27.1.

See this package in yarn:
@babel/helper-string-parser

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade react-bootstrap from 1.3.0 to 1.6.8.

See this package in yarn:
react-bootstrap

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr
…6c5bc70b9f872c7

[Snyk] Upgrade react-bootstrap from 1.3.0 to 1.6.8
…d07172df422773c

[Snyk] Upgrade @babel/helper-string-parser from 7.18.10 to 7.27.1
…870ae797a06641a

[Snyk] Upgrade @babel/preset-react from 7.18.6 to 7.27.1
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
…eb007a9218cf7be

[Snyk] Upgrade @babel/plugin-proposal-decorators from 7.19.0 to 7.28.0
…e5314e5c10c2c6c

[Snyk] Upgrade core-js from 3.25.1 to 3.45.1
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
…ng unencrypted communication channel

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Potential fix for code scanning alert no. 29: Dependency download using unencrypted communication channel
…on character escape

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Potential fix for code scanning alert no. 2: Useless regular-expression character escape
…ession for hostnames

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Potential fix for code scanning alert no. 23: Incomplete regular expression for hostnames
…ensitive information

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Potential fix for code scanning alert no. 24: Clear-text storage of sensitive information
…d or disabled

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Potential fix for code scanning alert no. 19: CSRF protection weakened or disabled
…as HTML

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Potential fix for code scanning alert no. 15: DOM text reinterpreted as HTML
…in permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Potential fix for code scanning alert no. 28: Workflow does not contain permissions
…ar expression range

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Wbaker7702 and others added 26 commits September 25, 2025 23:16
Potential fix for code scanning alert no. 21: Overly permissive regular expression range
Snyk has created this PR to upgrade enketo-transformer from 4.1.1 to 4.2.0.

See this package in yarn:
enketo-transformer

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/5365759b-d209-456c-9448-7fda2875ba19?utm_source=github&utm_medium=referral&page=upgrade-pr
…a1a5c230b74196cc

[Snyk] Upgrade enketo-transformer from 4.1.1 to 4.2.0
…98c633c65261

[Snyk] Fix for 4 vulnerabilities
Co-authored-by: wbaker7702 <wbaker7702@mail.kvcc.edu>
This commit updates various dependencies to their latest versions, including Rails to 8.0. It also includes numerous code refactors to improve code quality and maintainability. Key changes include:

- Updated `shakapacker` to v8.0.0.
- Updated Rails dependencies to v8.0.
- Refactored numerous controller actions and model methods for clarity and efficiency.
- Improved error handling and logging throughout the application.
- Added new test cases and updated existing ones to ensure compatibility with the updated dependencies.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-POSTCSS-5926692

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
* fix: upgrade css-loader from 5.0.0 to 5.2.7

Snyk has created this PR to upgrade css-loader from 5.0.0 to 5.2.7.

See this package in yarn:
css-loader

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr

* Update package.json

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>

---------

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: snyk-bot <snyk-bot@snyk.io>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
… 7.20.7 (#109)

Snyk has created this PR to upgrade @babel/plugin-proposal-object-rest-spread from 7.18.9 to 7.20.7.

See this package in yarn:
@babel/plugin-proposal-object-rest-spread

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
Snyk has created this PR to upgrade regenerator-runtime from 0.13.9 to 0.14.0.

See this package in yarn:
regenerator-runtime

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
Snyk has created this PR to upgrade query-string from 6.13.1 to 6.14.1.

See this package in yarn:
query-string

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
…111)

Ensures CI applies new Rails migrations so tests run against current schema.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Snyk has created this PR to upgrade react_ujs from 2.6.1 to 2.7.1.

See this package in yarn:
react_ujs

See this project in Snyk:
https://app.snyk.io/org/wbaker7702/project/7b5dd519-a5aa-402d-8871-c767616f1940?utm_source=github&utm_medium=referral&page=upgrade-pr

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: snyk-bot <snyk-bot@snyk.io>
- Document the gem cache permission issues encountered
- Explain the root cause and solution implemented
- Provide configuration details for local bundle setup
- List required system dependencies for future reference

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
#114)

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* feat: Implement webhooks, AI validation, and workflows

This commit introduces several new features:
- Webhook functionality for real-time event notifications.
- AI-powered validation rules and results for data quality checks.
- Workflow engine for automating multi-step processes.
- Custom dashboards for data visualization.

Co-authored-by: wbaker7702 <wbaker7702@mail.kvcc.edu>

* Potential fix for code scanning alert no. 33: Insecure Mass Assignment

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>

* Potential fix for code scanning alert no. 36: Code injection

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>

---------

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
#116)

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…er-controlled sources (#117)

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…ession for hostnames (#119)

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…d or disabled (#120)

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
#121)

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…as HTML (#122)

Signed-off-by: Wes  <93578022+Wbaker7702@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants