{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":191051391,"defaultBranch":"main","name":"redwood","ownerLogin":"redwoodjs","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2019-06-09T20:17:57.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/45050444?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1726761822.0","currentOid":""},"activityList":{"items":[{"before":"937cd13ace408da6a70150471eaa2335bd04d824","after":null,"ref":"refs/heads/jgmw/fix-label-storage-uploads-experimental","pushedAt":"2024-09-19T16:03:42.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"}},{"before":"a67d5fbecad70ede74dce0d016cfebe996f89094","after":"cfabf6482ffce9090b9583bb1db1b4e82c66b48d","ref":"refs/heads/main","pushedAt":"2024-09-19T16:03:39.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"},"commit":{"message":"fix(docs): warn that uploads/storage is experimental (#11590)\n\nWe want to have this labelled as experimental.","shortMessageHtmlLink":"fix(docs): warn that uploads/storage is experimental (#11590)"}},{"before":null,"after":"937cd13ace408da6a70150471eaa2335bd04d824","ref":"refs/heads/jgmw/fix-label-storage-uploads-experimental","pushedAt":"2024-09-19T15:53:56.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"},"commit":{"message":"backport warning to 8.1 docs","shortMessageHtmlLink":"backport warning to 8.1 docs"}},{"before":"239da4c973f83f90b7214d36972e7ecd4de69ab5","after":"69058fe30f5567408501a6d7b1a6ab9a27d4ae84","ref":"refs/heads/next","pushedAt":"2024-09-19T02:59:27.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"},"commit":{"message":"fix formatting","shortMessageHtmlLink":"fix formatting"}},{"before":"991d7d9444fb86b5f8356ee1c64eeb94a377a61d","after":"2a88d91908600d6ac4256881a21478899468b5d6","ref":"refs/heads/renovate/apollo-graphql-packages","pushedAt":"2024-09-19T02:57:47.000Z","pushType":"force_push","commitsCount":0,"pusher":{"login":"renovate[bot]","name":null,"path":"/apps/renovate","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/2740?s=80&v=4"},"commit":{"message":"fix(deps): update apollo graphql packages","shortMessageHtmlLink":"fix(deps): update apollo graphql packages"}},{"before":"3187ee8cb7ee3c106c2b9c7a669158c8d1b73ef9","after":"239da4c973f83f90b7214d36972e7ecd4de69ab5","ref":"refs/heads/next","pushedAt":"2024-09-19T02:53:57.000Z","pushType":"push","commitsCount":9,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"},"commit":{"message":"chore(deps): update dependency @arethetypeswrong/cli to v0.16.4 (#11586)\n\nThis PR contains the following updates:\n\n| Package | Change | Age | Adoption | Passing | Confidence |\n|---|---|---|---|---|---|\n|\n[@arethetypeswrong/cli](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io)\n([source](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/tree/HEAD/packages/cli))\n| [`0.16.2` ->\n`0.16.4`](https://renovatebot.com/diffs/npm/@arethetypeswrong%2fcli/0.16.2/0.16.4)\n|\n[![age](https://developer.mend.io/api/mc/badges/age/npm/@arethetypeswrong%2fcli/0.16.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@arethetypeswrong%2fcli/0.16.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@arethetypeswrong%2fcli/0.16.2/0.16.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@arethetypeswrong%2fcli/0.16.2/0.16.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n\n---\n\n> [!WARNING]\n> Some dependencies could not be looked up. Check the Dependency\nDashboard for more information.\n\n---\n\n### Release Notes\n\n
\narethetypeswrong/arethetypeswrong.github.io\n(@​arethetypeswrong/cli)\n\n###\n[`v0.16.4`](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/blob/HEAD/packages/cli/CHANGELOG.md#0164)\n\n##### Patch Changes\n\n- Updated dependencies\n\\[[`3ca2866`](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/commit/3ca2866)]\n-\n[@​arethetypeswrong/core](https://redirect.github.com/arethetypeswrong/core)[@​0](https://redirect.github.com/0).16.4\n\n###\n[`v0.16.3`](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/blob/HEAD/packages/cli/CHANGELOG.md#0163)\n\n##### Patch Changes\n\n-\n[`66ada51`](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/commit/66ada51):\nFix warning message json-format suggestion to use proper syntax\n\n
\n\n---\n\n### Configuration\n\n📅 **Schedule**: Branch creation - At any time (no schedule defined),\nAutomerge - At any time (no schedule defined).\n\n🚦 **Automerge**: Enabled.\n\n♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the\nrebase/retry checkbox.\n\n🔕 **Ignore**: Close this PR and you won't be reminded about these\nupdates again.\n\n---\n\n- [ ] If you want to rebase/retry this PR, check\nthis box\n\n---\n\nThis PR was generated by [Mend Renovate](https://mend.io/renovate/).\nView the [repository job\nlog](https://developer.mend.io/github/redwoodjs/redwood).\n\n\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>","shortMessageHtmlLink":"chore(deps): update dependency @arethetypeswrong/cli to v0.16.4 (#11586)"}},{"before":"7a00e3a80263cf79ebb1a9acb967dd143841caed","after":null,"ref":"refs/heads/renovate/arethetypeswrong-cli-0.x","pushedAt":"2024-09-19T01:42:03.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"renovate[bot]","name":null,"path":"/apps/renovate","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/2740?s=80&v=4"}},{"before":"d27b0ce99f07b039fbf71a0d475fc139c11556e4","after":"a67d5fbecad70ede74dce0d016cfebe996f89094","ref":"refs/heads/main","pushedAt":"2024-09-19T01:42:02.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"renovate[bot]","name":null,"path":"/apps/renovate","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/2740?s=80&v=4"},"commit":{"message":"chore(deps): update dependency @arethetypeswrong/cli to v0.16.4 (#11586)\n\nThis PR contains the following updates:\n\n| Package | Change | Age | Adoption | Passing | Confidence |\n|---|---|---|---|---|---|\n|\n[@arethetypeswrong/cli](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io)\n([source](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/tree/HEAD/packages/cli))\n| [`0.16.2` ->\n`0.16.4`](https://renovatebot.com/diffs/npm/@arethetypeswrong%2fcli/0.16.2/0.16.4)\n|\n[![age](https://developer.mend.io/api/mc/badges/age/npm/@arethetypeswrong%2fcli/0.16.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@arethetypeswrong%2fcli/0.16.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@arethetypeswrong%2fcli/0.16.2/0.16.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@arethetypeswrong%2fcli/0.16.2/0.16.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n\n---\n\n> [!WARNING]\n> Some dependencies could not be looked up. Check the Dependency\nDashboard for more information.\n\n---\n\n### Release Notes\n\n
\narethetypeswrong/arethetypeswrong.github.io\n(@​arethetypeswrong/cli)\n\n###\n[`v0.16.4`](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/blob/HEAD/packages/cli/CHANGELOG.md#0164)\n\n##### Patch Changes\n\n- Updated dependencies\n\\[[`3ca2866`](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/commit/3ca2866)]\n-\n[@​arethetypeswrong/core](https://redirect.github.com/arethetypeswrong/core)[@​0](https://redirect.github.com/0).16.4\n\n###\n[`v0.16.3`](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/blob/HEAD/packages/cli/CHANGELOG.md#0163)\n\n##### Patch Changes\n\n-\n[`66ada51`](https://redirect.github.com/arethetypeswrong/arethetypeswrong.github.io/commit/66ada51):\nFix warning message json-format suggestion to use proper syntax\n\n
\n\n---\n\n### Configuration\n\n📅 **Schedule**: Branch creation - At any time (no schedule defined),\nAutomerge - At any time (no schedule defined).\n\n🚦 **Automerge**: Enabled.\n\n♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the\nrebase/retry checkbox.\n\n🔕 **Ignore**: Close this PR and you won't be reminded about these\nupdates again.\n\n---\n\n- [ ] If you want to rebase/retry this PR, check\nthis box\n\n---\n\nThis PR was generated by [Mend Renovate](https://mend.io/renovate/).\nView the [repository job\nlog](https://developer.mend.io/github/redwoodjs/redwood).\n\n\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>","shortMessageHtmlLink":"chore(deps): update dependency @arethetypeswrong/cli to v0.16.4 (#11586)"}},{"before":null,"after":"7a00e3a80263cf79ebb1a9acb967dd143841caed","ref":"refs/heads/renovate/arethetypeswrong-cli-0.x","pushedAt":"2024-09-19T01:23:40.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"renovate[bot]","name":null,"path":"/apps/renovate","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/2740?s=80&v=4"},"commit":{"message":"chore(deps): update dependency @arethetypeswrong/cli to v0.16.4","shortMessageHtmlLink":"chore(deps): update dependency @arethetypeswrong/cli to v0.16.4"}},{"before":"dd879728250153ea1eeaf06cbec45fe56a0a9ab5","after":null,"ref":"refs/heads/rc-jobs-clear","pushedAt":"2024-09-19T00:01:23.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"}},{"before":"0081d3ae607e2d6c4c547219fbfbfa0c79005d6e","after":"d27b0ce99f07b039fbf71a0d475fc139c11556e4","ref":"refs/heads/main","pushedAt":"2024-09-19T00:01:21.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"},"commit":{"message":"Fixes `yarn rw jobs clear` command (#11578)\n\nCloses #11577\r\n\r\n---------\r\n\r\nCo-authored-by: Josh GM Walker <56300765+Josh-Walker-GM@users.noreply.github.com>","shortMessageHtmlLink":"Fixes yarn rw jobs clear command (#11578)"}},{"before":"fcc65f0570bdbb34c61b70fcfeaa909195e54c69","after":null,"ref":"refs/heads/jgmw/fix-graphql-scalar-config","pushedAt":"2024-09-18T17:36:10.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"}},{"before":"09c2f06243eff77bb20b21857bdfaaa489b1be2d","after":"0081d3ae607e2d6c4c547219fbfbfa0c79005d6e","ref":"refs/heads/main","pushedAt":"2024-09-18T17:36:07.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"},"commit":{"message":"fix(graphql): Allow including 'File' scalar by default to be disabled (#11540)\n\nThere was a problem introduced in v8 when we included the `File` scalar\r\nby default. This meant a custom implementation by the user could be\r\nclobbered by the new default. This change allows the user to supply\r\nconfig to disable including it by default.\r\n\r\nThis is not how I would have loved to have done things here. Config in\r\ntwo places is rubbish but given the organisation of this currently it\r\nwas generally unavoidable.","shortMessageHtmlLink":"fix(graphql): Allow including 'File' scalar by default to be disabled ("}},{"before":"af5fdf009ab020451fff8ccf1554bafb77141e60","after":"fcc65f0570bdbb34c61b70fcfeaa909195e54c69","ref":"refs/heads/jgmw/fix-graphql-scalar-config","pushedAt":"2024-09-18T17:18:47.000Z","pushType":"push","commitsCount":40,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"},"commit":{"message":"Merge branch 'main' into jgmw/fix-graphql-scalar-config","shortMessageHtmlLink":"Merge branch 'main' into jgmw/fix-graphql-scalar-config"}},{"before":"24aff481aa18f896fadca4f3c35dd1cc41ce20d9","after":null,"ref":"refs/heads/dependabot/npm_and_yarn/find-my-way-8.2.2","pushedAt":"2024-09-18T16:43:36.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"}},{"before":"ce12b00adbffe5a8e726ec11fcc61a25eea3f37f","after":null,"ref":"refs/heads/renovate/npm-find-my-way-vulnerability","pushedAt":"2024-09-18T16:42:54.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"renovate[bot]","name":null,"path":"/apps/renovate","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/2740?s=80&v=4"}},{"before":"705ea5bb74e0f6a4da1f079b2bcb079b3506c633","after":"09c2f06243eff77bb20b21857bdfaaa489b1be2d","ref":"refs/heads/main","pushedAt":"2024-09-18T16:42:53.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"renovate[bot]","name":null,"path":"/apps/renovate","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/2740?s=80&v=4"},"commit":{"message":"fix(deps): update dependency find-my-way to v8.2.2 [security] (#11585)\n\nThis PR contains the following updates:\n\n| Package | Change | Age | Adoption | Passing | Confidence |\n|---|---|---|---|---|---|\n| [find-my-way](https://redirect.github.com/delvedor/find-my-way) |\n[`8.2.0` ->\n`8.2.2`](https://renovatebot.com/diffs/npm/find-my-way/8.2.0/8.2.2) |\n[![age](https://developer.mend.io/api/mc/badges/age/npm/find-my-way/8.2.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/find-my-way/8.2.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/find-my-way/8.2.0/8.2.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/find-my-way/8.2.0/8.2.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)\n|\n\n---\n\n> [!WARNING]\n> Some dependencies could not be looked up. Check the Dependency\nDashboard for more information.\n\n### GitHub Vulnerability Alerts\n\n####\n[CVE-2024-45813](https://redirect.github.com/delvedor/find-my-way/security/advisories/GHSA-rrr8-f88r-h8q6)\n\n### Impact\n\nA bad regular expression is generated any time you have two parameters\nwithin a single segment, when adding a `-` at the end, like `/:a-:b-`.\n\n### Patches\n\nUpdate to find-my-way v8.2.2 or v9.0.1. or subsequent versions.\n\n### Workarounds\n\nNo known workarounds.\n\n### References\n\n-\n[CVE-2024-45296](https://redirect.github.com/advisories/GHSA-9wv6-86v2-598j)\n- [Detailed blog post about `path-to-regexp`\nvulnerability](https://blakeembrey.com/posts/2024-09-web-redos/)\n\n---\n\n### Release Notes\n\n
\ndelvedor/find-my-way (find-my-way)\n\n###\n[`v8.2.2`](https://redirect.github.com/delvedor/find-my-way/releases/tag/v8.2.2)\n\n[Compare\nSource](https://redirect.github.com/delvedor/find-my-way/compare/186c7db33c6c6aaf4e8e68199722e217bdd69337...v8.2.2)\n\n⚠️ Security Release ⚠️\n\nFixes:\nhttps://github.com/delvedor/find-my-way/security/advisories/GHSA-rrr8-f88r-h8q6\nCVE-2024-45813\n\n**Full Changelog**:\nhttps://github.com/delvedor/find-my-way/compare/v8.2.0...v8.2.2\n\n###\n[`v8.2.1`](https://redirect.github.com/delvedor/find-my-way/compare/v8.2.0...186c7db33c6c6aaf4e8e68199722e217bdd69337)\n\n[Compare\nSource](https://redirect.github.com/delvedor/find-my-way/compare/v8.2.0...186c7db33c6c6aaf4e8e68199722e217bdd69337)\n\n
\n\n---\n\n### Configuration\n\n📅 **Schedule**: Branch creation - \"\" (UTC), Automerge - At any time (no\nschedule defined).\n\n🚦 **Automerge**: Enabled.\n\n♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the\nrebase/retry checkbox.\n\n🔕 **Ignore**: Close this PR and you won't be reminded about this update\nagain.\n\n---\n\n- [ ] If you want to rebase/retry this PR, check\nthis box\n\n---\n\nThis PR was generated by [Mend Renovate](https://mend.io/renovate/).\nView the [repository job\nlog](https://developer.mend.io/github/redwoodjs/redwood).\n\n\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>","shortMessageHtmlLink":"fix(deps): update dependency find-my-way to v8.2.2 [security] (#11585)"}},{"before":"b1e58fc78f7e87757b07750f78e975461bd6e9e8","after":"dd879728250153ea1eeaf06cbec45fe56a0a9ab5","ref":"refs/heads/rc-jobs-clear","pushedAt":"2024-09-18T16:36:22.000Z","pushType":"push","commitsCount":4,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"},"commit":{"message":"Merge branch 'main' into rc-jobs-clear","shortMessageHtmlLink":"Merge branch 'main' into rc-jobs-clear"}},{"before":"a7290cac0d31d15ea48af14da93a1d391de527c6","after":null,"ref":"refs/heads/rc-jobs-environment","pushedAt":"2024-09-18T16:32:32.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"cannikin","name":"Rob Cameron","path":"/cannikin","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/300?s=80&v=4"}},{"before":"29a3ddae85e9bc008190f4b89543ebabc73b0145","after":"705ea5bb74e0f6a4da1f079b2bcb079b3506c633","ref":"refs/heads/main","pushedAt":"2024-09-18T16:32:31.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"cannikin","name":"Rob Cameron","path":"/cannikin","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/300?s=80&v=4"},"commit":{"message":"Default NODE_ENV to \"development\" if it's `undefined` when starting jobs worker (#11572)\n\nThis mimics the behavior of `yarn rw dev` where `NODE_ENV` will equal\r\n`development` if you don't set it explicitly.\r\n\r\nBecause of this, you need to make sure you explicitly set it in other\r\nenvironments. You should set `NODE_ENV=production` in your `.env`\r\nfile/Dockerfile on your production server, for example. The docs have\r\nbeen updated to note this.\r\n\r\nCloses #11569","shortMessageHtmlLink":"Default NODE_ENV to \"development\" if it's undefined when starting j…"}},{"before":null,"after":"ce12b00adbffe5a8e726ec11fcc61a25eea3f37f","ref":"refs/heads/renovate/npm-find-my-way-vulnerability","pushedAt":"2024-09-18T16:24:52.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"renovate[bot]","name":null,"path":"/apps/renovate","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/2740?s=80&v=4"},"commit":{"message":"fix(deps): update dependency find-my-way to v8.2.2 [security]","shortMessageHtmlLink":"fix(deps): update dependency find-my-way to v8.2.2 [security]"}},{"before":null,"after":"24aff481aa18f896fadca4f3c35dd1cc41ce20d9","ref":"refs/heads/dependabot/npm_and_yarn/find-my-way-8.2.2","pushedAt":"2024-09-18T16:21:21.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"chore(deps): bump find-my-way from 8.2.0 to 8.2.2\n\nBumps [find-my-way](https://github.com/delvedor/find-my-way) from 8.2.0 to 8.2.2.\n- [Release notes](https://github.com/delvedor/find-my-way/releases)\n- [Commits](https://github.com/delvedor/find-my-way/compare/v8.2.0...v8.2.2)\n\n---\nupdated-dependencies:\n- dependency-name: find-my-way\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"chore(deps): bump find-my-way from 8.2.0 to 8.2.2"}},{"before":"3698b46207416c543d1e684d3d22ee40f0fd7825","after":"7349050db492bc6aba831bc36f405ff40107fa61","ref":"refs/heads/renovate/supertokens-auth-react-0.x","pushedAt":"2024-09-18T14:26:19.000Z","pushType":"force_push","commitsCount":0,"pusher":{"login":"renovate[bot]","name":null,"path":"/apps/renovate","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/2740?s=80&v=4"},"commit":{"message":"chore(deps): update dependency supertokens-auth-react to v0.47.1","shortMessageHtmlLink":"chore(deps): update dependency supertokens-auth-react to v0.47.1"}},{"before":"1d414acee9f019b9ce855de6d6b1b01ad149df3b","after":null,"ref":"refs/heads/dependabot/npm_and_yarn/packages/storybook/vite-5.4.6","pushedAt":"2024-09-18T14:22:24.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"}},{"before":"bc5768d84472f51981ba3ff4f1e63e43158732fb","after":null,"ref":"refs/heads/renovate/npm-vite-vulnerability","pushedAt":"2024-09-18T14:21:46.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"}},{"before":"4cbbf7a79499fb2d85878a193e7e5458bc88ca42","after":"29a3ddae85e9bc008190f4b89543ebabc73b0145","ref":"refs/heads/main","pushedAt":"2024-09-18T14:21:44.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"Josh-Walker-GM","name":"Josh GM Walker","path":"/Josh-Walker-GM","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/56300765?s=80&v=4"},"commit":{"message":"fix(deps): update dependency vite to v5.4.6 [security] (#11580)\n\nThis PR contains the following updates:\r\n\r\n| Package | Change | Age | Adoption | Passing | Confidence |\r\n|---|---|---|---|---|---|\r\n| [vite](https://vitejs.dev)\r\n([source](https://redirect.github.com/vitejs/vite/tree/HEAD/packages/vite))\r\n| [`5.4.5` ->\r\n`5.4.6`](https://renovatebot.com/diffs/npm/vite/5.4.5/5.4.6) |\r\n[![age](https://developer.mend.io/api/mc/badges/age/npm/vite/5.4.6?slim=true)](https://docs.renovatebot.com/merge-confidence/)\r\n|\r\n[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/vite/5.4.6?slim=true)](https://docs.renovatebot.com/merge-confidence/)\r\n|\r\n[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/vite/5.4.5/5.4.6?slim=true)](https://docs.renovatebot.com/merge-confidence/)\r\n|\r\n[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/vite/5.4.5/5.4.6?slim=true)](https://docs.renovatebot.com/merge-confidence/)\r\n|\r\n\r\n---\r\n\r\n> [!WARNING]\r\n> Some dependencies could not be looked up. Check the Dependency\r\nDashboard for more information.\r\n\r\n### GitHub Vulnerability Alerts\r\n\r\n####\r\n[CVE-2024-45811](https://redirect.github.com/vitejs/vite/security/advisories/GHSA-9cwx-2883-4wfx)\r\n\r\n### Summary\r\nThe contents of arbitrary files can be returned to the browser.\r\n\r\n### Details\r\n`@fs` denies access to files outside of Vite serving allow list. Adding\r\n`?import&raw` to the URL bypasses this limitation and returns the file\r\ncontent if it exists.\r\n\r\n### PoC\r\n```sh\r\n$ npm create vite@latest\r\n$ cd vite-project/\r\n$ npm install\r\n$ npm run dev\r\n\r\n$ echo \"top secret content\" > /tmp/secret.txt\r\n\r\n# expected behaviour\r\n$ curl \"http://localhost:5173/@​fs/tmp/secret.txt\"\r\n\r\n \r\n

403 Restricted

\r\n

The request url "/tmp/secret.txt" is outside of Vite serving allow list.\r\n\r\n# security bypassed\r\n$ curl \"http://localhost:5173/@​fs/tmp/secret.txt?import&raw\"\r\nexport default \"top secret content\\n\"\r\n//# sourceMappingURL=data:application/json;base64,eyJ2...\r\n```\r\n\r\n####\r\n[CVE-2024-45812](https://redirect.github.com/vitejs/vite/security/advisories/GHSA-64vr-g452-qvp3)\r\n\r\n### Summary\r\n\r\nWe discovered a DOM Clobbering vulnerability in Vite when building\r\nscripts to `cjs`/`iife`/`umd` output format. The DOM Clobbering gadget\r\nin the module can lead to cross-site scripting (XSS) in web pages where\r\nscriptless attacker-controlled HTML elements (e.g., an img tag with an\r\nunsanitized name attribute) are present.\r\n\r\nNote that, we have identified similar security issues in Webpack:\r\nhttps://github.com/webpack/webpack/security/advisories/GHSA-4vvj-4cpr-p986\r\n\r\n### Details\r\n\r\n**Backgrounds**\r\n\r\nDOM Clobbering is a type of code-reuse attack where the attacker first\r\nembeds a piece of non-script, seemingly benign HTML markups in the\r\nwebpage (e.g. through a post or comment) and leverages the gadgets\r\n(pieces of js code) living in the existing javascript code to transform\r\nit into executable code. More for information about DOM Clobbering, here\r\nare some references:\r\n\r\n[1] https://scnps.co/papers/sp23_domclob.pdf\r\n[2] https://research.securitum.com/xss-in-amp4email-dom-clobbering/\r\n\r\n**Gadgets found in Vite**\r\n\r\nWe have identified a DOM Clobbering vulnerability in Vite bundled\r\nscripts, particularly when the scripts dynamically import other scripts\r\nfrom the assets folder and the developer sets the build output format to\r\n`cjs`, `iife`, or `umd`. In such cases, Vite replaces relative paths\r\nstarting with `__VITE_ASSET__` using the URL retrieved from\r\n`document.currentScript`.\r\n\r\nHowever, this implementation is vulnerable to a DOM Clobbering attack.\r\nThe `document.currentScript` lookup can be shadowed by an attacker via\r\nthe browser's named DOM tree element access mechanism. This manipulation\r\nallows an attacker to replace the intended script element with a\r\nmalicious HTML element. When this happens, the src attribute of the\r\nattacker-controlled element is used as the URL for importing scripts,\r\npotentially leading to the dynamic loading of scripts from an\r\nattacker-controlled server.\r\n\r\n```\r\nconst relativeUrlMechanisms = {\r\n amd: (relativePath) => {\r\n if (relativePath[0] !== \".\") relativePath = \"./\" + relativePath;\r\n return getResolveUrl(\r\n `require.toUrl('${escapeId(relativePath)}'), document.baseURI`\r\n );\r\n },\r\n cjs: (relativePath) => `(typeof document === 'undefined' ? ${getFileUrlFromRelativePath(\r\n relativePath\r\n )} : ${getRelativeUrlFromDocument(relativePath)})`,\r\n es: (relativePath) => getResolveUrl(\r\n `'${escapeId(partialEncodeURIPath(relativePath))}', import.meta.url`\r\n ),\r\n iife: (relativePath) => getRelativeUrlFromDocument(relativePath),\r\n // NOTE: make sure rollup generate `module` params\r\n system: (relativePath) => getResolveUrl(\r\n `'${escapeId(partialEncodeURIPath(relativePath))}', module.meta.url`\r\n ),\r\n umd: (relativePath) => `(typeof document === 'undefined' && typeof location === 'undefined' ? ${getFileUrlFromRelativePath(\r\n relativePath\r\n )} : ${getRelativeUrlFromDocument(relativePath, true)})`\r\n};\r\n```\r\n\r\n### PoC\r\n\r\nConsidering a website that contains the following `main.js` script, the\r\ndevloper decides to use the Vite to bundle up the program with the\r\nfollowing configuration.\r\n\r\n```\r\n// main.js\r\nimport extraURL from './extra.js?url'\r\nvar s = document.createElement('script')\r\ns.src = extraURL\r\ndocument.head.append(s)\r\n```\r\n\r\n```\r\n// extra.js\r\nexport default \"https://myserver/justAnOther.js\"\r\n```\r\n\r\n```\r\n// vite.config.js\r\nimport { defineConfig } from 'vite'\r\n\r\nexport default defineConfig({\r\n build: {\r\n assetsInlineLimit: 0, // To avoid inline assets for PoC\r\n rollupOptions: {\r\n output: {\r\n format: \"cjs\"\r\n },\r\n },\r\n },\r\n base: \"./\",\r\n});\r\n```\r\n\r\nAfter running the build command, the developer will get following bundle\r\nas the output.\r\n\r\n```\r\n// dist/index-DDmIg9VD.js\r\n\"use strict\";const t=\"\"+(typeof document>\"u\"?require(\"url\").pathToFileURL(__dirname+\"/extra-BLVEx9Lb.js\").href:new URL(\"extra-BLVEx9Lb.js\",document.currentScript&&document.currentScript.src||document.baseURI).href);var e=document.createElement(\"script\");e.src=t;document.head.append(e);\r\n```\r\n\r\nAdding the Vite bundled script, `dist/index-DDmIg9VD.js`, as part of the\r\nweb page source code, the page could load the `extra.js` file from the\r\nattacker's domain, `attacker.controlled.server`. The attacker only needs\r\nto insert an `img` tag with the `name` attribute set to `currentScript`.\r\nThis can be done through a website's feature that allows users to embed\r\ncertain script-less HTML (e.g., markdown renderers, web email clients,\r\nforums) or via an HTML injection vulnerability in third-party JavaScript\r\nloaded on the page.\r\n\r\n```\r\n\r\n\r\n\r\n Vite Example\r\n \r\n \r\n \r\n\r\n\r\n\r\n\r\n\r\n```\r\n\r\n### Impact\r\n\r\nThis vulnerability can result in cross-site scripting (XSS) attacks on\r\nwebsites that include Vite-bundled files (configured with an output\r\nformat of `cjs`, `iife`, or `umd`) and allow users to inject certain\r\nscriptless HTML tags without properly sanitizing the name or id\r\nattributes.\r\n\r\n### Patch\r\n\r\n```\r\n// https://github.com/vitejs/vite/blob/main/packages/vite/src/node/build.ts#L1296\r\nconst getRelativeUrlFromDocument = (relativePath: string, umd = false) =>\r\n getResolveUrl(\r\n `'${escapeId(partialEncodeURIPath(relativePath))}', ${\r\n umd ? `typeof document === 'undefined' ? location.href : ` : ''\r\n }document.currentScript && document.currentScript.tagName.toUpperCase() === 'SCRIPT' && document.currentScript.src || document.baseURI`,\r\n )\r\n```\r\n\r\n---\r\n\r\n### Release Notes\r\n\r\n

\r\nvitejs/vite (vite)\r\n\r\n###\r\n[`v5.4.6`](https://redirect.github.com/vitejs/vite/releases/tag/v5.4.6)\r\n\r\n[Compare\r\nSource](https://redirect.github.com/vitejs/vite/compare/v5.4.5...v5.4.6)\r\n\r\nPlease refer to\r\n[CHANGELOG.md](https://redirect.github.com/vitejs/vite/blob/v5.4.6/packages/vite/CHANGELOG.md)\r\nfor details.\r\n\r\n
\r\n\r\n---\r\n\r\n### Configuration\r\n\r\n📅 **Schedule**: Branch creation - \"\" (UTC), Automerge - At any time (no\r\nschedule defined).\r\n\r\n🚦 **Automerge**: Enabled.\r\n\r\n♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the\r\nrebase/retry checkbox.\r\n\r\n🔕 **Ignore**: Close this PR and you won't be reminded about these\r\nupdates again.\r\n\r\n---\r\n\r\n- [ ] If you want to rebase/retry this PR, check\r\nthis box\r\n\r\n---\r\n\r\nThis PR was generated by [Mend Renovate](https://mend.io/renovate/).\r\nView the [repository job\r\nlog](https://developer.mend.io/github/redwoodjs/redwood).\r\n\r\n\r\n\r\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>","shortMessageHtmlLink":"fix(deps): update dependency vite to v5.4.6 [security] (#11580)"}},{"before":"2b749313203ff4308e60c6cb546b69301646add6","after":"4cbbf7a79499fb2d85878a193e7e5458bc88ca42","ref":"refs/heads/main","pushedAt":"2024-09-18T08:39:37.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"Tobbe","name":"Tobbe Lundberg","path":"/Tobbe","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/30793?s=80&v=4"},"commit":{"message":"chore(test-project): Update TailwindCSS (#11583)","shortMessageHtmlLink":"chore(test-project): Update TailwindCSS (#11583)"}},{"before":null,"after":"bc5768d84472f51981ba3ff4f1e63e43158732fb","ref":"refs/heads/renovate/npm-vite-vulnerability","pushedAt":"2024-09-17T19:55:36.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"renovate[bot]","name":null,"path":"/apps/renovate","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/2740?s=80&v=4"},"commit":{"message":"fix(deps): update dependency vite to v5.4.6 [security]","shortMessageHtmlLink":"fix(deps): update dependency vite to v5.4.6 [security]"}},{"before":null,"after":"1d414acee9f019b9ce855de6d6b1b01ad149df3b","ref":"refs/heads/dependabot/npm_and_yarn/packages/storybook/vite-5.4.6","pushedAt":"2024-09-17T19:51:39.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"chore(deps-dev): bump vite from 5.4.5 to 5.4.6 in /packages/storybook\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 5.4.5 to 5.4.6.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/v5.4.6/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v5.4.6/packages/vite)\n\n---\nupdated-dependencies:\n- dependency-name: vite\n dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"chore(deps-dev): bump vite from 5.4.5 to 5.4.6 in /packages/storybook"}},{"before":"a18bd569aebe3ad04e5ce5a6cda32da6d1034d01","after":"b1e58fc78f7e87757b07750f78e975461bd6e9e8","ref":"refs/heads/rc-jobs-clear","pushedAt":"2024-09-17T16:39:15.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"cannikin","name":"Rob Cameron","path":"/cannikin","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/300?s=80&v=4"},"commit":{"message":"Adds changeset","shortMessageHtmlLink":"Adds changeset"}}],"hasNextPage":true,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"djE6ks8AAAAEuxIPwwA","startCursor":null,"endCursor":null}},"title":"Activity · redwoodjs/redwood"}