-
Notifications
You must be signed in to change notification settings - Fork 312
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Incomplete multi-character sanitization on utils.js getQueryParam function #443
Comments
Thanks for the heads up. This should be fixed in release v2.55.1. |
github-merge-queue bot
referenced
this issue
in camunda/camunda
Aug 28, 2024
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [@babel/preset-env](https://babel.dev/docs/en/next/babel-preset-env) ([source](https://togithub.com/babel/babel/tree/HEAD/packages/babel-preset-env)) | [`7.25.3` -> `7.25.4`](https://renovatebot.com/diffs/npm/@babel%2fpreset-env/7.25.3/7.25.4) | [![age](https://developer.mend.io/api/mc/badges/age/npm/@babel%2fpreset-env/7.25.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@babel%2fpreset-env/7.25.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@babel%2fpreset-env/7.25.3/7.25.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@babel%2fpreset-env/7.25.3/7.25.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [@tanstack/react-query](https://tanstack.com/query) ([source](https://togithub.com/TanStack/query/tree/HEAD/packages/react-query)) | [`5.52.0` -> `5.52.2`](https://renovatebot.com/diffs/npm/@tanstack%2freact-query/5.52.0/5.52.2) | [![age](https://developer.mend.io/api/mc/badges/age/npm/@tanstack%2freact-query/5.52.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@tanstack%2freact-query/5.52.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@tanstack%2freact-query/5.52.0/5.52.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@tanstack%2freact-query/5.52.0/5.52.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [@tanstack/react-query-devtools](https://tanstack.com/query) ([source](https://togithub.com/TanStack/query/tree/HEAD/packages/react-query-devtools)) | [`5.52.0` -> `5.52.2`](https://renovatebot.com/diffs/npm/@tanstack%2freact-query-devtools/5.52.0/5.52.2) | [![age](https://developer.mend.io/api/mc/badges/age/npm/@tanstack%2freact-query-devtools/5.52.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@tanstack%2freact-query-devtools/5.52.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@tanstack%2freact-query-devtools/5.52.0/5.52.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@tanstack%2freact-query-devtools/5.52.0/5.52.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [@types/node](https://togithub.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node) ([source](https://togithub.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)) | [`20.16.1` -> `20.16.2`](https://renovatebot.com/diffs/npm/@types%2fnode/20.16.1/20.16.2) | [![age](https://developer.mend.io/api/mc/badges/age/npm/@types%2fnode/20.16.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@types%2fnode/20.16.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@types%2fnode/20.16.1/20.16.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@types%2fnode/20.16.1/20.16.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [eslint-plugin-react-refresh](https://togithub.com/ArnaudBarre/eslint-plugin-react-refresh) | [`0.4.10` -> `0.4.11`](https://renovatebot.com/diffs/npm/eslint-plugin-react-refresh/0.4.10/0.4.11) | [![age](https://developer.mend.io/api/mc/badges/age/npm/eslint-plugin-react-refresh/0.4.11?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/eslint-plugin-react-refresh/0.4.11?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/eslint-plugin-react-refresh/0.4.10/0.4.11?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/eslint-plugin-react-refresh/0.4.10/0.4.11?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [mixpanel-browser](https://togithub.com/mixpanel/mixpanel-js) | [`2.55.0` -> `2.55.1`](https://renovatebot.com/diffs/npm/mixpanel-browser/2.55.0/2.55.1) | [![age](https://developer.mend.io/api/mc/badges/age/npm/mixpanel-browser/2.55.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/mixpanel-browser/2.55.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/mixpanel-browser/2.55.0/2.55.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/mixpanel-browser/2.55.0/2.55.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [postcss-custom-properties](https://togithub.com/csstools/postcss-plugins/tree/main/plugins/postcss-custom-properties#readme) ([source](https://togithub.com/csstools/postcss-plugins/tree/HEAD/plugins/postcss-custom-properties)) | [`13.3.10` -> `13.3.12`](https://renovatebot.com/diffs/npm/postcss-custom-properties/13.3.10/13.3.12) | [![age](https://developer.mend.io/api/mc/badges/age/npm/postcss-custom-properties/13.3.12?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/postcss-custom-properties/13.3.12?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/postcss-custom-properties/13.3.10/13.3.12?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/postcss-custom-properties/13.3.10/13.3.12?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [stylis](https://togithub.com/thysultan/stylis.js) | [`4.3.2` -> `4.3.4`](https://renovatebot.com/diffs/npm/stylis/4.3.2/4.3.4) | [![age](https://developer.mend.io/api/mc/badges/age/npm/stylis/4.3.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/stylis/4.3.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/stylis/4.3.2/4.3.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/stylis/4.3.2/4.3.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | --- ### Release Notes <details> <summary>babel/babel (@​babel/preset-env)</summary> ### [`v7.25.4`](https://togithub.com/babel/babel/blob/HEAD/CHANGELOG.md#v7254-2024-08-22) [Compare Source](https://togithub.com/babel/babel/compare/v7.25.3...v7.25.4) ##### 🐛 Bug Fix - `babel-traverse` - [#​16756](https://togithub.com/babel/babel/pull/16756) fix: Skip computed key when renaming ([@​liuxingbaoyu](https://togithub.com/liuxingbaoyu)) - `babel-helper-create-class-features-plugin`, `babel-plugin-proposal-decorators` - [#​16755](https://togithub.com/babel/babel/pull/16755) fix: Decorator 2018-09 may throw an exception ([@​liuxingbaoyu](https://togithub.com/liuxingbaoyu)) - `babel-types` - [#​16710](https://togithub.com/babel/babel/pull/16710) Visit AST fields nodes according to their syntactical order ([@​nicolo-ribaudo](https://togithub.com/nicolo-ribaudo)) - `babel-generator` - [#​16709](https://togithub.com/babel/babel/pull/16709) Print semicolon after TS `export namespace as A` ([@​nicolo-ribaudo](https://togithub.com/nicolo-ribaudo)) ##### 💅 Polish - `babel-generator`, `babel-plugin-proposal-decorators`, `babel-plugin-proposal-destructuring-private`, `babel-plugin-proposal-pipeline-operator`, `babel-plugin-transform-class-properties`, `babel-plugin-transform-destructuring`, `babel-plugin-transform-optional-chaining`, `babel-plugin-transform-private-methods`, `babel-plugin-transform-private-property-in-object`, `babel-plugin-transform-typescript`, `babel-runtime-corejs2`, `babel-runtime`, `babel-traverse` - [#​16722](https://togithub.com/babel/babel/pull/16722) Avoid unnecessary parens around sequence expressions ([@​nicolo-ribaudo](https://togithub.com/nicolo-ribaudo)) - `babel-generator`, `babel-plugin-transform-class-properties` - [#​16714](https://togithub.com/babel/babel/pull/16714) Avoid unnecessary parens around exported arrow functions ([@​nicolo-ribaudo](https://togithub.com/nicolo-ribaudo)) - `babel-generator`, `babel-plugin-proposal-decorators`, `babel-plugin-proposal-destructuring-private`, `babel-plugin-transform-object-rest-spread` - [#​16712](https://togithub.com/babel/babel/pull/16712) Avoid printing unnecessary parens around object destructuring ([@​nicolo-ribaudo](https://togithub.com/nicolo-ribaudo)) ##### 🔬 Output optimization - `babel-generator` - [#​16740](https://togithub.com/babel/babel/pull/16740) Avoid extra spaces between comments/regexps in compact mode ([@​nicolo-ribaudo](https://togithub.com/nicolo-ribaudo)) </details> <details> <summary>TanStack/query (@​tanstack/react-query)</summary> ### [`v5.52.2`](https://togithub.com/TanStack/query/compare/v5.52.1...v5.52.2) [Compare Source](https://togithub.com/TanStack/query/compare/v5.52.1...v5.52.2) ### [`v5.52.1`](https://togithub.com/TanStack/query/releases/tag/v5.52.1) [Compare Source](https://togithub.com/TanStack/query/compare/v5.52.0...v5.52.1) Version 5.52.1 - 8/22/24, 4:37 PM #### Changes ##### Fix - react-query: Add missing React 19 peer dependency. ([#​7937](https://togithub.com/TanStack/query/issues/7937)) ([`ca2e306`](https://togithub.com/TanStack/query/commit/ca2e306)) by [@​kbumsik](https://togithub.com/kbumsik) ##### Docs - make copyable example useful by default ([#​7928](https://togithub.com/TanStack/query/issues/7928)) ([`639363c`](https://togithub.com/TanStack/query/commit/639363c)) by Lanre Adelowo #### Packages - [@​tanstack/react-query](https://togithub.com/tanstack/react-query)[@​5](https://togithub.com/5).52.1 - [@​tanstack/react-query-devtools](https://togithub.com/tanstack/react-query-devtools)[@​5](https://togithub.com/5).52.1 - [@​tanstack/react-query-persist-client](https://togithub.com/tanstack/react-query-persist-client)[@​5](https://togithub.com/5).52.1 - [@​tanstack/react-query-next-experimental](https://togithub.com/tanstack/react-query-next-experimental)[@​5](https://togithub.com/5).52.1 </details> <details> <summary>TanStack/query (@​tanstack/react-query-devtools)</summary> ### [`v5.52.2`](https://togithub.com/TanStack/query/releases/tag/v5.52.2) [Compare Source](https://togithub.com/TanStack/query/compare/v5.52.1...v5.52.2) Version 5.52.2 - 8/26/24, 5:54 PM #### Changes ##### Fix - types: error booleans shouldn"t permanently be typed as `false` ([#​7956](https://togithub.com/TanStack/query/issues/7956)) ([`b93941d`](https://togithub.com/TanStack/query/commit/b93941d)) by Dominik Dorfmeister ##### Chore - remove unused .all-contributorsrc ([#​7949](https://togithub.com/TanStack/query/issues/7949)) ([`8cf7e2f`](https://togithub.com/TanStack/query/commit/8cf7e2f)) by [@​manudeli](https://togithub.com/manudeli) - angular-query: add type tests for injectQuery ([#​7947](https://togithub.com/TanStack/query/issues/7947)) ([`73258c6`](https://togithub.com/TanStack/query/commit/73258c6)) by Arnoud ##### Examples - svelte-query: fix svelte auto-refetching styling ([#​7951](https://togithub.com/TanStack/query/issues/7951)) ([`519759d`](https://togithub.com/TanStack/query/commit/519759d)) by Lachlan Collins #### Packages - [@​tanstack/query-core](https://togithub.com/tanstack/query-core)[@​5](https://togithub.com/5).52.2 - [@​tanstack/react-query](https://togithub.com/tanstack/react-query)[@​5](https://togithub.com/5).52.2 - [@​tanstack/solid-query](https://togithub.com/tanstack/solid-query)[@​5](https://togithub.com/5).52.2 - [@​tanstack/angular-query-experimental](https://togithub.com/tanstack/angular-query-experimental)[@​5](https://togithub.com/5).52.2 - [@​tanstack/query-broadcast-client-experimental](https://togithub.com/tanstack/query-broadcast-client-experimental)[@​5](https://togithub.com/5).52.2 - [@​tanstack/query-persist-client-core](https://togithub.com/tanstack/query-persist-client-core)[@​5](https://togithub.com/5).52.2 - [@​tanstack/query-sync-storage-persister](https://togithub.com/tanstack/query-sync-storage-persister)[@​5](https://togithub.com/5).52.2 - [@​tanstack/react-query-devtools](https://togithub.com/tanstack/react-query-devtools)[@​5](https://togithub.com/5).52.2 - [@​tanstack/react-query-persist-client](https://togithub.com/tanstack/react-query-persist-client)[@​5](https://togithub.com/5).52.2 - [@​tanstack/react-query-next-experimental](https://togithub.com/tanstack/react-query-next-experimental)[@​5](https://togithub.com/5).52.2 - [@​tanstack/solid-query-devtools](https://togithub.com/tanstack/solid-query-devtools)[@​5](https://togithub.com/5).52.2 - [@​tanstack/solid-query-persist-client](https://togithub.com/tanstack/solid-query-persist-client)[@​5](https://togithub.com/5).52.2 - [@​tanstack/svelte-query](https://togithub.com/tanstack/svelte-query)[@​5](https://togithub.com/5).52.2 - [@​tanstack/svelte-query-devtools](https://togithub.com/tanstack/svelte-query-devtools)[@​5](https://togithub.com/5).52.2 - [@​tanstack/svelte-query-persist-client](https://togithub.com/tanstack/svelte-query-persist-client)[@​5](https://togithub.com/5).52.2 - [@​tanstack/vue-query](https://togithub.com/tanstack/vue-query)[@​5](https://togithub.com/5).52.2 - [@​tanstack/vue-query-devtools](https://togithub.com/tanstack/vue-query-devtools)[@​5](https://togithub.com/5).52.2 - [@​tanstack/angular-query-devtools-experimental](https://togithub.com/tanstack/angular-query-devtools-experimental)[@​5](https://togithub.com/5).52.2 - [@​tanstack/query-async-storage-persister](https://togithub.com/tanstack/query-async-storage-persister)[@​5](https://togithub.com/5).52.2 ### [`v5.52.1`](https://togithub.com/TanStack/query/compare/v5.52.0...v5.52.1) [Compare Source](https://togithub.com/TanStack/query/compare/v5.52.0...v5.52.1) </details> <details> <summary>ArnaudBarre/eslint-plugin-react-refresh (eslint-plugin-react-refresh)</summary> ### [`v0.4.11`](https://togithub.com/ArnaudBarre/eslint-plugin-react-refresh/blob/HEAD/CHANGELOG.md#0411) [Compare Source](https://togithub.com/ArnaudBarre/eslint-plugin-react-refresh/compare/v0.4.10...v0.4.11) - Ignore type exports (ex. `export type foo = string;`) (fixes [#​47](https://togithub.com/ArnaudBarre/eslint-plugin-react-refresh/issues/47)) </details> <details> <summary>mixpanel/mixpanel-js (mixpanel-browser)</summary> ### [`v2.55.1`](https://togithub.com/mixpanel/mixpanel-js/releases/tag/v2.55.1): Misc fixes and updates [Compare Source](https://togithub.com/mixpanel/mixpanel-js/compare/v2.55.0...v2.55.1) - Adds a minimum recording length option for session recording. For example, `{record_min_ms: 4000}` won't send any recordings that are less than 4 seconds long. The maximum value allowed is 8000. - Added a fix for session recordings being sent with an empty start time. - Fixes and improvements for request batcher to support offline queueing and retry. - Fix for query param parsing/escaping ([https://github.com/mixpanel/mixpanel-js/issues/443](https://togithub.com/mixpanel/mixpanel-js/issues/443)). - Support for more UTM tags / click IDs ([https://github.com/mixpanel/mixpanel-js/pull/442](https://togithub.com/mixpanel/mixpanel-js/pull/442)). </details> <details> <summary>csstools/postcss-plugins (postcss-custom-properties)</summary> ### [`v13.3.12`](https://togithub.com/csstools/postcss-plugins/blob/HEAD/plugins/postcss-custom-properties/CHANGELOG.md#13312) [Compare Source](https://togithub.com/csstools/postcss-plugins/compare/50e5adeae1f89962a281abb1f92df30f90c0530b...c47ed8613c66af3dde68fc4b0a32bb7e0da660c4) *July 6, 2024* - Updated [`@csstools/css-tokenizer`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/css-tokenizer) to [`2.4.1`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/css-tokenizer/CHANGELOG.md#241) (patch) - Updated [`@csstools/css-parser-algorithms`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/css-parser-algorithms) to [`2.7.1`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/css-parser-algorithms/CHANGELOG.md#271) (patch) - Updated [`@csstools/cascade-layer-name-parser`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/cascade-layer-name-parser) to [`1.0.13`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/cascade-layer-name-parser/CHANGELOG.md#1013) (patch) ### [`v13.3.11`](https://togithub.com/csstools/postcss-plugins/blob/HEAD/plugins/postcss-custom-properties/CHANGELOG.md#13311) [Compare Source](https://togithub.com/csstools/postcss-plugins/compare/2753dad5bdf2318fbe319a3607178c33ad9fb31a...50e5adeae1f89962a281abb1f92df30f90c0530b) *June 29, 2024* - Updated [`@csstools/css-tokenizer`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/css-tokenizer) to [`2.3.2`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/css-tokenizer/CHANGELOG.md#232) (patch) - Updated [`@csstools/css-parser-algorithms`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/css-parser-algorithms) to [`2.7.0`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/css-parser-algorithms/CHANGELOG.md#270) (minor) - Updated [`@csstools/cascade-layer-name-parser`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/cascade-layer-name-parser) to [`1.0.12`](https://togithub.com/csstools/postcss-plugins/tree/main/packages/cascade-layer-name-parser/CHANGELOG.md#1012) (patch) </details> <details> <summary>thysultan/stylis.js (stylis)</summary> ### [`v4.3.4`](https://togithub.com/thysultan/stylis.js/compare/0b51a356efa21b30069b807169bce056d94f34da...f7bbabecb4801659bf6c3223b52d5dc7460ca6f3) [Compare Source](https://togithub.com/thysultan/stylis.js/compare/0b51a356efa21b30069b807169bce056d94f34da...f7bbabecb4801659bf6c3223b52d5dc7460ca6f3) ### [`v4.3.3`](https://togithub.com/thysultan/stylis.js/compare/v4.3.2...0b51a356efa21b30069b807169bce056d94f34da) [Compare Source](https://togithub.com/thysultan/stylis.js/compare/v4.3.2...0b51a356efa21b30069b807169bce056d94f34da) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://togithub.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View the [repository job log](https://developer.mend.io/github/camunda/camunda). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4yNi4xIiwidXBkYXRlZEluVmVyIjoiMzguNTYuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiYXV0b21lcmdlIl19-->
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Our company enforced a CodeQL scan against our built bundle. And an incomplete multi-character sanitization error is reported from this line
mixpanel-js/src/utils.js
Line 965 in 93df8eb
This should be easily fixed by adding a 'g' in regex
The text was updated successfully, but these errors were encountered: