Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency serialize-javascript to v6.0.2 [security] #466

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 15, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
serialize-javascript 6.0.1 -> 6.0.2 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-11831

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.


Release Notes

yahoo/serialize-javascript (serialize-javascript)

v6.0.2

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (squash) February 15, 2025 02:49
Copy link

vercel bot commented Feb 15, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
blog ✅ Ready (Inspect) Visit Preview 💬 Add feedback Feb 24, 2025 4:48pm

Copy link

changeset-bot bot commented Feb 15, 2025

⚠️ No Changeset found

Latest commit: 33d66b1

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@renovate renovate bot changed the title fix(deps): update dependency serialize-javascript to v6.0.2 [security] fix(deps): update dependency serialize-javascript to v6.0.2 [security] - autoclosed Feb 21, 2025
@renovate renovate bot closed this Feb 21, 2025
auto-merge was automatically disabled February 21, 2025 22:33

Pull request was closed

@renovate renovate bot deleted the renovate/npm-serialize-javascript-vulnerability branch February 21, 2025 22:33
@renovate renovate bot changed the title fix(deps): update dependency serialize-javascript to v6.0.2 [security] - autoclosed fix(deps): update dependency serialize-javascript to v6.0.2 [security] Feb 24, 2025
@renovate renovate bot reopened this Feb 24, 2025
@renovate renovate bot force-pushed the renovate/npm-serialize-javascript-vulnerability branch from e58c444 to 33d66b1 Compare February 24, 2025 16:46
@renovate renovate bot enabled auto-merge (squash) February 24, 2025 22:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants