Skip to content

Update docs to point to new repo#19

Merged
danielfrankcom merged 1 commit into
mainfrom
dev/frankcom/update-repo-links
Jan 29, 2026
Merged

Update docs to point to new repo#19
danielfrankcom merged 1 commit into
mainfrom
dev/frankcom/update-repo-links

Conversation

@danielfrankcom

Copy link
Copy Markdown
Contributor

This PR updates docs/badges for Hibernate and Django which were recently imported, and not covered by #4

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@danielfrankcom danielfrankcom marked this pull request as ready for review January 28, 2026 23:52
@danielfrankcom danielfrankcom requested a review from a team as a code owner January 28, 2026 23:52
@danielfrankcom danielfrankcom merged commit 7e7027b into main Jan 29, 2026
44 checks passed
@danielfrankcom danielfrankcom deleted the dev/frankcom/update-repo-links branch January 29, 2026 18:39
amaksimo added a commit that referenced this pull request Feb 28, 2026
Security fixes:
- Bump hono override from ^4.11.7 to ^4.11.10 (timing comparison
  hardening in basicAuth/bearerAuth, alerts #18 and #19)
- Add fast-xml-parser ^5.4.1 override to node/prisma (stack overflow
  in XMLBuilder, alert #32)
- Bump fast-xml-parser override in veterinary-app from ^5.3.4 to
  ^5.4.1 for consistency

Dependabot improvement:
- Use directories (plural) for node/prisma so the connector and its
  veterinary-app example are updated in the same PR, keeping
  lockfiles consistent.
amaksimo added a commit that referenced this pull request Feb 28, 2026
…abot config (#300)

## Summary

Resolves all 3 open Dependabot security alerts and fixes a systemic
Dependabot config issue.

## Security Alerts Fixed

| Severity | Alert | Package | Location | Fix |
|----------|-------|---------|----------|-----|
| LOW | #32 | fast-xml-parser < 5.3.8 | node/prisma | Added override
^5.4.1 |
| LOW | #19 | hono < 4.11.10 | node/prisma | Bumped override ^4.11.7 →
^4.11.10 |
| LOW | #18 | hono < 4.11.10 | node/prisma/examples/veterinary-app |
Bumped override ^4.11.7 → ^4.11.10 |

The existing overrides had version ranges that were too low to cover the
required fix versions.

## Dependabot Config Fix

Changed `node/prisma` and `node/prisma/examples/veterinary-app` from
separate `directory` entries to a single entry using `directories`
(plural). This ensures both lockfiles are updated in the same PR,
keeping dependencies consistent between the library and its example.

## Test plan

- [x] `npm audit` reports 0 vulnerabilities in both directories
- [ ] CI passes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants