Carlo Costino
5a4402fd8b
Merge pull request #1905 from GSA/dependabot/npm_and_yarn/rollup-4.21.1
...
Bump rollup from 4.21.0 to 4.21.1
2024-08-27 12:33:34 -04:00
dependabot[bot]
87d4911f89
Bump rollup from 4.21.0 to 4.21.1
...
Bumps [rollup](https://github.com/rollup/rollup ) from 4.21.0 to 4.21.1.
- [Release notes](https://github.com/rollup/rollup/releases )
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rollup/rollup/compare/v4.21.0...v4.21.1 )
---
updated-dependencies:
- dependency-name: rollup
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-08-26 23:42:40 +00:00
dependabot[bot]
5b14a4ea90
Bump @babel/preset-env from 7.25.3 to 7.25.4
...
Bumps [@babel/preset-env](https://github.com/babel/babel/tree/HEAD/packages/babel-preset-env ) from 7.25.3 to 7.25.4.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v7.25.4/packages/babel-preset-env )
---
updated-dependencies:
- dependency-name: "@babel/preset-env"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-08-22 23:36:50 +00:00
dependabot[bot]
27c6098cc8
Bump better-npm-audit from 3.7.3 to 3.8.3
...
Bumps [better-npm-audit](https://github.com/jeemok/better-npm-audit ) from 3.7.3 to 3.8.3.
- [Release notes](https://github.com/jeemok/better-npm-audit/releases )
- [Changelog](https://github.com/jeemok/better-npm-audit/blob/master/CHANGELOG.md )
- [Commits](https://github.com/jeemok/better-npm-audit/compare/v3.7.3...v3.8.3 )
---
updated-dependencies:
- dependency-name: better-npm-audit
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-08-21 16:26:19 +00:00
dependabot[bot]
1d03d73642
Bump rollup from 4.20.0 to 4.21.0
...
Bumps [rollup](https://github.com/rollup/rollup ) from 4.20.0 to 4.21.0.
- [Release notes](https://github.com/rollup/rollup/releases )
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rollup/rollup/compare/v4.20.0...v4.21.0 )
---
updated-dependencies:
- dependency-name: rollup
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-08-19 15:52:59 +00:00
dependabot[bot]
932963beb5
Bump @uswds/uswds from 3.8.1 to 3.8.2
...
Bumps [@uswds/uswds](https://github.com/uswds/uswds ) from 3.8.1 to 3.8.2.
- [Release notes](https://github.com/uswds/uswds/releases )
- [Commits](https://github.com/uswds/uswds/compare/v3.8.1...v3.8.2 )
---
updated-dependencies:
- dependency-name: "@uswds/uswds"
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-08-13 02:28:57 +00:00
Beverly Nguyen
aa1a738463
uninstalled sockeio client
2024-08-12 15:05:24 -07:00
alexjanousekGSA
57ee345451
Removed chart js
2024-08-12 15:29:35 -06:00
alexjanousekGSA
393ba67878
Added d3
2024-08-09 10:48:39 -06:00
alexjanousekGSA
9b768846cb
Updated rollup
2024-08-08 14:32:33 -06:00
alexjanousekGSA
25f75a98ec
Replaced stream queue
2024-08-08 14:01:05 -06:00
alexjanousekGSA
cc310d8a23
Added simple package updates
2024-08-08 13:58:33 -06:00
alexjanousekGSA
f8e85e5fa6
Added new package to see if it breaks pipeline
2024-08-07 21:58:55 -06:00
Jonathan Bobel
4af04ff183
Merge branch 'main' of https://github.com/GSA/notifications-admin into 1484-dashboard-visualizations
...
# Conflicts:
# package-lock.json
# package.json
2024-07-23 11:39:49 -04:00
Jonathan Bobel
f0b4fbe732
Updating an optional dependency
2024-07-17 13:02:04 -04:00
alexjanousekGSA
34e08d9290
Updated gulp and replaced png logo with svg
2024-07-08 10:45:05 -06:00
Jonathan Bobel
2e20b20912
Updates to the test
2024-07-05 15:23:34 -04:00
alexjanousekGSA
e189ac3d1a
Updated govuk-fe-toolkit
2024-07-03 13:48:03 -06:00
alexjanousekGSA
6c1ae0efba
Merge branch 'main' into 1682-update-remaining-outdated-npm-dependencies
2024-07-03 13:17:24 -06:00
alexjanousekGSA
8d30589882
Updated morphdom
2024-07-02 12:40:58 -06:00
alexjanousekGSA
feb879be53
Removed package that seems to be unused that caused a security concern
2024-07-02 10:49:09 -06:00
Kenneth Kehl
aa02e65c1f
revert upgrade of gulp
2024-06-18 11:25:05 -07:00
Kenneth Kehl
8f985f2429
update gulp to 5.0.0
2024-06-18 11:17:01 -07:00
Kenneth Kehl
b1624c25dc
more updated
2024-06-18 07:49:20 -07:00
Kenneth Kehl
9817f9e434
revert gulp
2024-06-17 14:41:31 -07:00
Kenneth Kehl
00ab6f5122
hmm
2024-06-17 14:36:06 -07:00
Kenneth Kehl
5544400212
fix vulnerability
2024-06-17 14:27:59 -07:00
Kenneth Kehl
c491b4152c
initial
2024-06-17 13:55:25 -07:00
Beverly Nguyen
e5a9eed626
installing socketio
2024-06-05 14:56:22 -07:00
Beverly Nguyen
6855a6ebe4
installing chart.js via npm
2024-05-15 15:35:39 -07:00
dependabot[bot]
353383d323
Bump postcss and @uswds/compile
...
Bumps [postcss](https://github.com/postcss/postcss ) to 8.4.31 and updates ancestor dependency [@uswds/compile](https://github.com/uswds/uswds-compile ). These dependencies need to be updated together.
Updates `postcss` from 7.0.39 to 8.4.31
- [Release notes](https://github.com/postcss/postcss/releases )
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md )
- [Commits](https://github.com/postcss/postcss/compare/7.0.39...8.4.31 )
Updates `@uswds/compile` from 1.0.0 to 1.1.0
- [Release notes](https://github.com/uswds/uswds-compile/releases )
- [Commits](https://github.com/uswds/uswds-compile/compare/v1.0.0...v1.1.0 )
---
updated-dependencies:
- dependency-name: postcss
dependency-type: indirect
- dependency-name: "@uswds/compile"
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-12-13 17:11:55 +00:00
Jonathan Bobel
7ba937b14a
Updated sass-embedded to see if this fixes the dependency error
2023-11-01 11:14:02 -04:00
Jonathan Bobel
54eb8df9f7
- Added new flag imagery for favicon and related images
...
- Removed preloaded fonts - legacy UK site stuff
- Added the ability to run pa11y scan with npm run pa11y-ci
2023-09-20 13:52:54 -04:00
Jonathan Bobel
84d436baf2
Adding back in sass-embedded
2023-08-28 16:36:35 -04:00
Jonathan Bobel
42c4670c89
Removing more sass includes to see if this addresses my issue
2023-08-28 16:33:25 -04:00
Jonathan Bobel
c7b756e46c
Removing sass
2023-08-28 16:25:01 -04:00
Jonathan Bobel
8ab550a22f
Radio buttons and list edits
2023-08-25 15:31:44 -04:00
Jonathan Bobel
eaf3681ae1
Initial USWDS install
2023-04-24 14:57:35 -04:00
stvnrlly
8a415bc31b
remove leaflet - it was for broadcasts
2022-12-14 13:30:27 -05:00
stvnrlly
219dc7b2ec
update package.json for gsa
2022-11-29 08:55:22 -05:00
Ryan Ahearn
bb2d57b27b
Update tests to use most recent jest and supporting libraries
2022-10-27 11:12:39 -04:00
Ryan Ahearn
98b772f959
Separate test and lint steps
2022-10-27 11:10:13 -04:00
Ryan Ahearn
f9cacac204
Update js dependencies
2022-10-26 14:15:49 +00:00
Ryan Ahearn
fa7b1a41b8
Add python and npm audits to checks.yml
2022-08-25 16:55:33 -04:00
Ben Thorner
51f9b0cef0
Fix missing audit task in package.json
...
This was intended to go in [^1] but I think it got lost in a rebase.
[^1]: https://github.com/alphagov/notifications-admin/pull/4237
2022-05-10 11:33:24 +01:00
Ben Thorner
b348e8ed03
Add better-npm-audit to check production packages
...
This is the same as [^1].
[^1]: https://github.com/alphagov/document-download-frontend/pull/120
2022-05-09 12:05:42 +01:00
Ben Thorner
da7dd3a852
Fix incorrect group for NPM dependencies
...
This means we can use tools like "npm audit" to look for security
vulnerabilities we definitely need to fix as they could pose a
direct risk to users. I've checked each of them with @tombye and
also against an external set of principles [^1].
Note: I've skimmed through the package-lock.json to check the only
changes are to add "dev: true", as well as a few integrity hashes.
[^1]: https://betterprogramming.pub/is-this-a-dependency-or-a-devdependency-678e04a55a5c
2022-05-06 12:31:10 +01:00
Ben Thorner
b6321ef4ae
Remove unused "del" package
...
This was added in [^1] and later removed in [^2].
[^1]: e1dc6ddaef
[^2]: https://github.com/alphagov/notifications-admin/pull/3198
2022-05-05 14:51:19 +01:00
Tom Byers
77f7d1453c
Replace domdiff library with morphdom
...
We added domdiff to replace the DiffDOM library
here:
87f54d1e88
DiffDOM had updated its code to be written to the
ECMAScript 6 (ES6) standard and so needed extra
work to work with the older browsers in our
support matrix. This was recorded as an issue
here:
https://www.pivotaltracker.com/n/projects/1443052/stories/165380360
Domdiff didn't work (see below for more details)
so this replaces it with the morphdom library.
Morphdom supports the same browsers as us and is
relied on by a range of large open source
projects:
https://github.com/patrick-steele-idem/morphdom#what-projects-are-using-morphdom
It was tricky to find alternatives to DiffDOM so
if we have to source alternatives in future, other
options could be:
- https://github.com/choojs/nanomorph
- https://diffhtml.org/index.html (using its
outerHTML method)
Why domdiff didn't work
Turns out that domdiff was replacing the page HTML
with the HTML from the AJAX response every time,
not just when they differed. This isn't a bug.
Domdiff is bare bones enough that it compares old
DOM nodes to new DOM nodes with ===. With our
code, this always results to false because our new
nodes are made from HTML strings from AJAX
response so are never the same node as the old
one.
2022-01-27 11:37:53 +00:00
Tom Byers
c61698753f
Remove version restrictions for NPM
...
We do need NPM to be run above those versions but
I'd rather enforce that here after I'm sure this
app will run on images that have a valid version.
2021-09-22 12:05:47 +01:00