Skip to content

[Recovery] chore(deps)(deps): bump cors from 2.8.5 to 2.8.6 in /apps/api#33

Merged
LessUp merged 1 commit intomasterfrom
recovery/pr-19-chore-deps-deps-bump-cors-from-2-8-5-to--6ffc9d5
Apr 27, 2026
Merged

[Recovery] chore(deps)(deps): bump cors from 2.8.5 to 2.8.6 in /apps/api#33
LessUp merged 1 commit intomasterfrom
recovery/pr-19-chore-deps-deps-bump-cors-from-2-8-5-to--6ffc9d5

Conversation

@LessUp
Copy link
Copy Markdown
Owner

@LessUp LessUp commented Apr 27, 2026

Recovered from closed PR #19 because the original Dependabot branch was deleted.

Original PR: #19

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 27, 2026

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/cors 2.8.6 🟢 7.4
Details
CheckScoreReason
Maintained🟢 34 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 3
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Code-Review🟢 9Found 18/19 approved changesets -- score normalized to 9
Dependency-Update-Tool🟢 10update tool detected
Vulnerabilities🟢 100 existing vulnerabilities detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
SAST🟢 9SAST tool detected but not run on all commits
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
CI-Tests🟢 723 out of 30 merged PRs checked by a CI test -- score normalized to 7
Contributors🟢 10project has 8 contributing companies or organizations

Scanned Files

  • apps/api/package-lock.json

@LessUp LessUp marked this pull request as ready for review April 27, 2026 11:06
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@LessUp LessUp force-pushed the recovery/pr-19-chore-deps-deps-bump-cors-from-2-8-5-to--6ffc9d5 branch from 6ffc9d5 to a2787e2 Compare April 27, 2026 11:08
@LessUp LessUp merged commit 2503099 into master Apr 27, 2026
3 of 4 checks passed
@LessUp LessUp deleted the recovery/pr-19-chore-deps-deps-bump-cors-from-2-8-5-to--6ffc9d5 branch April 27, 2026 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants