Skip to content

Bump @typescript-eslint/eslint-plugin from 4.16.1 to 6.15.0 in /research-hub-web - #446

Open
dependabot[bot] wants to merge 2154 commits into
masterfrom
dependabot/npm_and_yarn/research-hub-web/typescript-eslint/eslint-plugin-6.15.0
Open

Bump @typescript-eslint/eslint-plugin from 4.16.1 to 6.15.0 in /research-hub-web#446
dependabot[bot] wants to merge 2154 commits into
masterfrom
dependabot/npm_and_yarn/research-hub-web/typescript-eslint/eslint-plugin-6.15.0

Bump @typescript-eslint/eslint-plugin in /research-hub-web

aae9d0a
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Apr 2, 2026 in 5s

4 new alerts including 4 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 4 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 36 in .github/workflows/linting.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 33 in .github/workflows/sentry.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 27 in .github/workflows/sentry.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action or reusable workflow Medium

Unpinned 3rd party Action 'Sentry Release' step
Uses Step
uses 'getsentry/action-release' with ref 'v1.1.6', not a pinned commit hash

Check warning on line 53 in hub-search-proxy/handler.js

See this annotation in the file changed.

Code scanning / CodeQL

Log injection Medium

Log entry depends on a
user-provided value
.