Dependency Dashboard
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 7
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
[View this repository on the Mend.io Web Portal](https://developer.mend.io/github/ljharb/scorecard-cli).
## Deprecations / Replacements
> [!WARNING]
The following dependencies are either deprecated or have replacements available.
| Datasource | Package | Replacement PR? |
|------------|------|--------------|
| npm | [aud](https://redirect.github.com/ljharb/aud) |  |
## Pending Approval
The following branches are pending approval. To create them, click on a checkbox below.
- [ ] [Deps] Update Update `eslint` to v8.57.1
- [ ] [Deps] Update Update `@ljharb/eslint-config` to v22
- [ ] [Deps] Update Update `@nodesecure/ossf-scorecard-sdk` to v4
- [ ] [Deps] Update Update `aud` to v3
- [ ] [Deps] Update Update `eslint` to v10
- [ ] [Deps] Update Update `nyc` to v18
- [ ] [Deps] Update Update actions/checkout action to v7
- [ ] 🔐 **Create all pending approval PRs at once** 🔐
## Detected Dependencies
github-actions (4)
.github/workflows/node-pretest.yml (1)
- `ljharb/actions main`
.github/workflows/node.yml (1)
- `ljharb/actions main`
.github/workflows/rebase.yml (2)
- `actions/checkout v3` → [Updates: `v7`]
- `ljharb/rebase master`.github/workflows/require-allow-edits.yml (1)
- `ljharb/require-allow-edits main`
npm (1)
package.json (12)
- `@nodesecure/ossf-scorecard-sdk ^3.2.1` → [Updates: `^4.0.0`]
- `@ljharb/eslint-config ^21.1.1` → [Updates: `^22.0.0`]
- `aud ^2.0.4` → [Updates: `^3.0.0`]
- `auto-changelog ^2.4.0`
- `eslint =8.8.0` → [Updates: `=8.57.1`, `=10.10.0`]
- `in-publish ^2.0.1`
- `mock-property ^1.0.3`
- `npmignore ^0.3.1`
- `nyc ^10.3.2` → [Updates: `^18.0.0`]
- `safe-publish-latest ^2.0.0`
- `tape ^5.7.5`
- `node ^20.13.1 || >= 22`
---
- [ ] Check this box to trigger a request for Renovate to run again on this repository
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with package.json and the listed files under .github/workflows, then review the Renovate dashboard entries and linked dependency documentation. Done would mean selecting and completing a defined dependency update, with the relevant checks passing; this issue does not identify one specific update or test.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, javascript
- Domain
- cli, devops, tooling
- Issue type
- Refactor
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100