Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Chore: update dependency word-wrap to 1.2.4 [SECURITY] #488

Merged
merged 1 commit into from
Jul 19, 2023

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 19, 2023

Mend Renovate

This PR contains the following updates:

Package Change
word-wrap 1.2.3 -> 1.2.4

GitHub Vulnerability Alerts

CVE-2023-26115

All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the security label Jul 19, 2023
@renovate renovate bot enabled auto-merge (squash) July 19, 2023 03:15
@codecov-commenter
Copy link

Codecov Report

Merging #488 (7eb6428) into main (aec12ec) will not change coverage.
The diff coverage is n/a.

@@           Coverage Diff           @@
##             main     #488   +/-   ##
=======================================
  Coverage   93.29%   93.29%           
=======================================
  Files          71       71           
  Lines        4146     4146           
  Branches      870      870           
=======================================
  Hits         3868     3868           
  Misses        264      264           
  Partials       14       14           

@renovate renovate bot merged commit 7ae6cd0 into main Jul 19, 2023
@renovate renovate bot deleted the renovate/npm-word-wrap-vulnerability branch July 19, 2023 03:21
@github-actions
Copy link

🧪 Branch Testing

This pull request can be tested locally with the following command:

npm exec --yes -- "github:emmercm/igir#renovate/npm-word-wrap-vulnerability" [commands..] [options]

@github-actions
Copy link

🔒 Inactive pull request lock

This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Oct 16, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant