Skip to content
This repository was archived by the owner on Feb 1, 2026. It is now read-only.

Revert "fix(deps): update dependency @fastify/cors to v11"#361

Closed
gander wants to merge 1 commit into
mainfrom
revert-352-renovate/fastify-cors-11.x
Closed

Revert "fix(deps): update dependency @fastify/cors to v11"#361
gander wants to merge 1 commit into
mainfrom
revert-352-renovate/fastify-cors-11.x

Conversation

@gander

@gander gander commented Feb 1, 2026

Copy link
Copy Markdown
Member

Reverts gander-tools/diff-voyager#352

@github-project-automation github-project-automation Bot moved this to Backlog in Diff Voyager Feb 1, 2026
@github-actions github-actions Bot added dependencies Changes to project dependencies (npm packages) size/small Small effort: 1-2 hours of work backend Backend-related code (Node.js, API, database, repositories) labels Feb 1, 2026
@gander gander closed this Feb 1, 2026
@github-project-automation github-project-automation Bot moved this from Backlog to Done in Diff Voyager Feb 1, 2026
@github-actions

github-actions Bot commented Feb 1, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
  • ⚠️ 1 packages with OpenSSF Scorecard issues.
See the Details below.

License Issues

packages/backend/package.json

PackageVersionLicenseIssue Type
@fastify/cors^9.0.1NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@fastify/cors 9.0.1 🟢 6.8
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Code-Review🟢 4Found 10/23 approved changesets -- score normalized to 4
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 43 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 4
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Vulnerabilities🟢 100 existing vulnerabilities detected
License🟢 9license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
SAST🟢 7SAST tool is not run on all commits -- score normalized to 7
npm/mnemonist 0.39.6 ⚠️ 2.8
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 3Found 10/30 approved changesets -- score normalized to 3
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 0128 existing vulnerabilities detected
npm/obliterator 2.0.5 UnknownUnknown
npm/@fastify/cors ^9.0.1 🟢 6.8
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Code-Review🟢 4Found 10/23 approved changesets -- score normalized to 4
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 43 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 4
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Vulnerabilities🟢 100 existing vulnerabilities detected
License🟢 9license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
SAST🟢 7SAST tool is not run on all commits -- score normalized to 7

Scanned Files

  • package-lock.json
  • packages/backend/package.json

@gander
gander deleted the revert-352-renovate/fastify-cors-11.x branch February 1, 2026 00:13
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

backend Backend-related code (Node.js, API, database, repositories) dependencies Changes to project dependencies (npm packages) size/small Small effort: 1-2 hours of work

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant