Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 3 additions & 8 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,9 @@
# the `all-dependencies` multi-ecosystem group, so Dependabot consolidates them --
# across every directory it monitors -- into a single weekly pull request.
# * Security updates cannot join a multi-ecosystem group, so each ecosystem also
# declares a `*-security-updates` group. Advisory-driven bumps then arrive as one
# grouped pull request per ecosystem instead of one per advisory.
# declares a catch-all `*-security-updates` group. These groups intentionally omit
# `patterns`: Dependabot currently can treat `patterns: ["*"]` as matching nothing
# and fall back to one pull request per dependency (dependabot/dependabot-core#13919).
# * `open-pull-requests-limit: 1` caps each ecosystem at a single open version-update
# pull request, so nothing slips out of the grouping.
# * The `no changelog` label lets the required "Check Changelog Action" gate pass on
Expand Down Expand Up @@ -51,8 +52,6 @@ updates:
groups:
npm-security-updates:
applies-to: security-updates
patterns:
- "*"

# .NET: library, CLI, language server, and Visual Studio extension projects
# discovered through Microsoft.DevSkim.sln.
Expand All @@ -74,8 +73,6 @@ updates:
groups:
nuget-security-updates:
applies-to: security-updates
patterns:
- "*"

# GitHub Actions used by the workflows in .github/workflows.
- package-ecosystem: "github-actions"
Expand All @@ -96,7 +93,5 @@ updates:
groups:
github-actions-security-updates:
applies-to: security-updates
patterns:
- "*"
cooldown:
default-days: 7
9 changes: 8 additions & 1 deletion Changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,14 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [1.0.99] - 2026-09-10
### Dependencies
- Consolidated the five open Dependabot pull requests (#769, #778, #781, #782, and #783) into one update, resolving nine npm security alerts by upgrading `brace-expansion` 1.1.16 to 1.1.18 and 5.0.8 to 5.0.9, `fast-uri` 3.1.4 to 3.1.7, `@humanfs/node` 0.16.7 to 0.16.8, and `js-yaml` 4.3.0 to 4.3.2.
- Upgraded `qs` from 6.15.2 to 6.16.0 through `npm audit fix`, resolving the remaining moderate npm audit finding.

### Pipeline
- Changed each Dependabot security-update group to omit the catch-all `patterns: ["*"]` selector, which Dependabot can incorrectly treat as matching no dependencies and then fall back to independent pull requests (dependabot/dependabot-core#13919).

## [1.0.97] - 2026-08-11
### Pipeline
- Fixed the VS Code extension release pipeline failing at the publish step with `npm error code E401`. The step ran `npx @vscode/vsce`, and because the argument is a package name rather than a bin name, npx cannot short circuit to the copy installed by the preceding `npm install -g @vscode/vsce` step and always fetches the package manifest from the npm registry, which is not authenticated inside the `AzureCLI@2` task. The step now invokes the globally installed `vsce.cmd` by its full path, so publishing needs no registry access, and fails with an explicit message if the binary is missing.
Expand Down Expand Up @@ -497,4 +505,3 @@ New: `devskim analyze -I path/to/src -O path/to/out.sarif`

### Fixes
- Rule improvements and DevSkim engine performance and reliablity improvements.

12 changes: 6 additions & 6 deletions DevSkim-VSCode-Plugin/client/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

85 changes: 50 additions & 35 deletions DevSkim-VSCode-Plugin/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading