Skip to content

Bump cypress from 7.7.0 to 13.6.2 in /research-hub-web - #449

Open
dependabot[bot] wants to merge 2154 commits into
masterfrom
dependabot/npm_and_yarn/research-hub-web/cypress-13.6.2
Open

Bump cypress from 7.7.0 to 13.6.2 in /research-hub-web#449
dependabot[bot] wants to merge 2154 commits into
masterfrom
dependabot/npm_and_yarn/research-hub-web/cypress-13.6.2

Bump cypress from 7.7.0 to 13.6.2 in /research-hub-web

bd8e842
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Apr 2, 2026 in 4s

4 new alerts including 4 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 4 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 36 in .github/workflows/linting.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 33 in .github/workflows/sentry.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 27 in .github/workflows/sentry.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action or reusable workflow Medium

Unpinned 3rd party Action 'Sentry Release' step
Uses Step
uses 'getsentry/action-release' with ref 'v1.1.6', not a pinned commit hash

Check warning on line 53 in hub-search-proxy/handler.js

See this annotation in the file changed.

Code scanning / CodeQL

Log injection Medium

Log entry depends on a
user-provided value
.