Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Chore: update dependency semver to 7.5.2 [SECURITY] #457

Merged
merged 1 commit into from
Jun 24, 2023

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jun 23, 2023

Mend Renovate

This PR contains the following updates:

Package Change
semver 7.5.1 -> 7.5.2

GitHub Vulnerability Alerts

CVE-2022-25883

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the security label Jun 23, 2023
@codecov-commenter
Copy link

Codecov Report

Merging #457 (db9ac23) into main (865fa1c) will not change coverage.
The diff coverage is n/a.

@@           Coverage Diff           @@
##             main     #457   +/-   ##
=======================================
  Coverage   93.00%   93.00%           
=======================================
  Files          70       70           
  Lines        4119     4119           
  Branches      856      856           
=======================================
  Hits         3831     3831           
  Misses        274      274           
  Partials       14       14           

@renovate renovate bot merged commit 5f4502a into main Jun 24, 2023
@renovate renovate bot deleted the renovate/npm-semver-vulnerability branch June 24, 2023 00:28
@github-actions
Copy link

🔒 Inactive pull request lock

This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Oct 17, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant