Skip to content

chore(deps): bump the radix group with 7 updates - #10

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/radix-828f8d1d79
Apr 13, 2025
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/radix-828f8d1d79

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 13, 2025 •

Copy link
Copy Markdown
Contributor

Bumps the radix group with 7 updates:

Package From To
@radix-ui/react-alert-dialog 1.1.3 1.1.7
@radix-ui/react-avatar 1.1.2 1.1.4
@radix-ui/react-dropdown-menu 2.1.3 2.1.7
@radix-ui/react-icons 1.3.0 1.3.2
@radix-ui/react-label 2.1.1 2.1.3
@radix-ui/react-slot 1.1.1 1.2.0
@radix-ui/react-toast 1.2.3 1.2.7

Updates @radix-ui/react-alert-dialog from 1.1.3 to 1.1.7

Commits

Updates @radix-ui/react-avatar from 1.1.2 to 1.1.4

Commits

Updates @radix-ui/react-dropdown-menu from 2.1.3 to 2.1.7

Commits

Updates @radix-ui/react-icons from 1.3.0 to 1.3.2

Maintainer changes

This version was pushed to npm by chancestrickland, a new releaser for @​radix-ui/react-icons since your current version.


Updates @radix-ui/react-label from 2.1.1 to 2.1.3

Commits

Updates @radix-ui/react-slot from 1.1.1 to 1.2.0

Commits

Updates @radix-ui/react-toast from 1.2.3 to 1.2.7

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 13, 2025
@steebchen

Copy link
Copy Markdown
Member

@dependabot recreate

Bumps the radix group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [@radix-ui/react-alert-dialog](https://github.com/radix-ui/primitives) | `1.1.3` | `1.1.7` |
| [@radix-ui/react-avatar](https://github.com/radix-ui/primitives) | `1.1.2` | `1.1.4` |
| [@radix-ui/react-dropdown-menu](https://github.com/radix-ui/primitives) | `2.1.3` | `2.1.7` |
| @radix-ui/react-icons | `1.3.0` | `1.3.2` |
| [@radix-ui/react-label](https://github.com/radix-ui/primitives) | `2.1.1` | `2.1.3` |
| [@radix-ui/react-slot](https://github.com/radix-ui/primitives) | `1.1.1` | `1.2.0` |
| [@radix-ui/react-toast](https://github.com/radix-ui/primitives) | `1.2.3` | `1.2.7` |


Updates `@radix-ui/react-alert-dialog` from 1.1.3 to 1.1.7
- [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md)
- [Commits](https://github.com/radix-ui/primitives/commits)

Updates `@radix-ui/react-avatar` from 1.1.2 to 1.1.4
- [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md)
- [Commits](https://github.com/radix-ui/primitives/commits)

Updates `@radix-ui/react-dropdown-menu` from 2.1.3 to 2.1.7
- [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md)
- [Commits](https://github.com/radix-ui/primitives/commits)

Updates `@radix-ui/react-icons` from 1.3.0 to 1.3.2

Updates `@radix-ui/react-label` from 2.1.1 to 2.1.3
- [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md)
- [Commits](https://github.com/radix-ui/primitives/commits)

Updates `@radix-ui/react-slot` from 1.1.1 to 1.2.0
- [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md)
- [Commits](https://github.com/radix-ui/primitives/commits)

Updates `@radix-ui/react-toast` from 1.2.3 to 1.2.7
- [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md)
- [Commits](https://github.com/radix-ui/primitives/commits)

---
updated-dependencies:
- dependency-name: "@radix-ui/react-alert-dialog"
  dependency-version: 1.1.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: radix
- dependency-name: "@radix-ui/react-avatar"
  dependency-version: 1.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: radix
- dependency-name: "@radix-ui/react-dropdown-menu"
  dependency-version: 2.1.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: radix
- dependency-name: "@radix-ui/react-icons"
  dependency-version: 1.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: radix
- dependency-name: "@radix-ui/react-label"
  dependency-version: 2.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: radix
- dependency-name: "@radix-ui/react-slot"
  dependency-version: 1.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: radix
- dependency-name: "@radix-ui/react-toast"
  dependency-version: 1.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: radix
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/radix-828f8d1d79 branch from e393007 to 1fa80c5 Compare April 13, 2025 17:06
@github-actions
github-actions Bot enabled auto-merge (squash) April 13, 2025 17:06
@github-actions
github-actions Bot merged commit b0c2467 into main Apr 13, 2025
@github-actions
github-actions Bot deleted the dependabot/npm_and_yarn/radix-828f8d1d79 branch April 13, 2025 17:08
vicovaro pushed a commit to vicovaro/llmgateway that referenced this pull request Jul 28, 2026
Resolves the ten open CodeQL `actions/missing-workflow-permissions`
alerts (theopenco#89, theopenco#81, theopenco#37, theopenco#35, theopenco#10, theopenco#7, theopenco#6, theopenco#5, theopenco#4, theopenco#3) by giving every
flagged workflow job an explicit least-privilege `permissions` block, so
`GITHUB_TOKEN` no longer falls back to the repository default
(read-write for repos created before Feb 2023).

## Changes

| Workflow | Alerts | Change |
| --- | --- | --- |
| `run.yml` | theopenco#89 | workflow-level `contents: read` |
| `ci.yml` | theopenco#37, theopenco#6, theopenco#5, theopenco#4, theopenco#3 | workflow-level `contents: read`
(covers `quality` plus the four `run.yml` caller jobs) |
| `e2e.yml` | theopenco#81, #2 | workflow-level `contents: read` |
| `autofix.yml` | theopenco#35 | workflow-level `contents: read` |
| `images.yml` | theopenco#10, theopenco#7 | job-level `contents: read` on `setup` and
`trigger-infra-update` — the file's other jobs already scope their own
permissions, so this matches the existing style |

## Why `contents: read` is sufficient everywhere

Every flagged job only reads the repository; the writes in these
workflows are already done with dedicated PATs rather than the workflow
token:

- `autofix.yml` passes `token: ${{ secrets.GH_TOKEN }}` to the autofix
action, which is what pushes the fixup commit.
- `images.yml` → `trigger-infra-update` dispatches into a different
repository with `GH_TOKEN: ${{ secrets.GH_INFRA_TOKEN }}`.
- `images.yml` → `setup` just checks out and computes an image tag.
- `e2e.yml`'s `upload-artifact`/`download-artifact` steps operate on
same-run artifacts, which use the runtime artifact API and need no token
scope.
- `run.yml` sets `GITHUB_TOKEN` on the command step, but nothing in the
build/lint/setup scripts reads it — it only serves to raise API rate
limits during dependency resolution.

`run.yml` is a reusable workflow, so its `contents: read` is a subset of
what `ci.yml` now grants and does not conflict.

## Verification

- Parsed all 11 workflow files and audited the effective permissions of
every job: all are now covered at either the workflow or job level, with
none missing.
- `prettier` reports all five touched files unchanged (already correctly
formatted).

---
_Generated by [Claude
Code](https://claude.ai/code/session_01368Ax2WpJaKG32ySXDKKX7)_

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant