Conversation
|
Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information |
|
Important Auto Review SkippedBot user detected. To trigger a single review, invoke the Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media? TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (invoked as PR comments)
Additionally, you can add CodeRabbit Configration File (
|
This PR contains the following updates:
^4.6.0->^7.0.0Release Notes
helmetjs/helmet (helmet)
v7.1.0Compare Source
Added
helmet.crossOriginEmbedderPolicynow supports theunsafe-nonedirective. See #477v7.0.0Compare Source
Changed
Cross-Origin-Embedder-Policymiddleware is now disabled by default. See #411Removed
Expect-CTis no longer part of Helmet. If you still need it, you can use theexpect-ctpackage. See #378v6.2.0Compare Source
strictTransportSecurityfor theStrict-Transport-Securityheader, instead ofhsts)v6.1.5Compare Source
Fixed
v6.1.4Compare Source
Fixed
v6.1.3Compare Source
Fixed
v6.1.2Compare Source
Fixed
mainto package to help with some build toolsv6.1.1Compare Source
Fixed
v6.1.0Compare Source
Changed
v6.0.1Compare Source
Fixed
crossOriginEmbedderPolicydid not accept options at the top level. See #390v6.0.0Compare Source
Changed
helmet.contentSecurityPolicyno longer setsblock-all-mixed-contentdirective by defaulthelmet.expectCtis no longer set by default. It can, however, be explicitly enabled. It will be removed in Helmet 7. See #310helmet.frameguardno longer offers a specific error when trying to useALLOW-FROM; it just says that it is unsupported. Only the error message has changedRemoved
v5.1.1Compare Source
Changed
v5.1.0Compare Source
Added
Cross-Origin-Embedder-Policy: supportcredentiallesspolicy. See #365Content-Security-PolicyandContent-Security-Policy-Report-OnlyChanged
Origin-Agent-Clusterv5.0.2Compare Source
Changed
v5.0.1Compare Source
Changed
Removed
v5.0.0Compare Source
Added
import helmet from "helmet"andimport { frameguard } from "helmet"). See #320Changed
helmet.contentSecurityPolicy:useDefaultsoption now defaults totruehelmet.contentSecurityPolicy:form-actiondirective is now set to'self'by defaulthelmet.crossOriginEmbedderPolicyis enabled by defaulthelmet.crossOriginOpenerPolicyis enabled by defaulthelmet.crossOriginResourcePolicyis enabled by defaulthelmet.originAgentClusteris enabled by defaulthelmet.frameguard: add TypeScript editor autocomplete. See #322helmet()function is slightly fasterRemoved
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.