It had none: no security policy, no contributing guide, no code of conduct, no sponsor link, and no CI. A public repository with an administrative interface in it should at least say where to send a vulnerability, so that part names what is worth reporting here specifically -- a session acting beyond its permissions, one tenant's data reaching another, a token landing somewhere that outlives the session -- and where a report goes if it turns out to belong to the server or to upstream. CI is what a contributor can run: typecheck, lint, test, build. Nothing in it needs a live server, so a red run means the code, not the runner.
32 lines
784 B
YAML
32 lines
784 B
YAML
version: 2
|
|
updates:
|
|
# One npm entry at the root, where the single lockfile is.
|
|
#
|
|
# Minor and patch arrive as one pull request a week. Majors are left out of
|
|
# the group on purpose: they are migrations rather than bumps, and each one
|
|
# deserves its own pull request and its own CI run.
|
|
- package-ecosystem: npm
|
|
directory: "/"
|
|
schedule:
|
|
interval: weekly
|
|
day: tuesday
|
|
time: "09:00"
|
|
timezone: Etc/UTC
|
|
open-pull-requests-limit: 5
|
|
groups:
|
|
minor-and-patch:
|
|
update-types:
|
|
- minor
|
|
- patch
|
|
- package-ecosystem: github-actions
|
|
directory: "/"
|
|
schedule:
|
|
interval: weekly
|
|
day: tuesday
|
|
time: "09:00"
|
|
timezone: Etc/UTC
|
|
groups:
|
|
actions:
|
|
patterns:
|
|
- "*"
|