Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency @rails/webpacker to v5.2.2 (main) #1956

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Apr 29, 2024

This PR contains the following updates:

Package Type Update Change
@rails/webpacker dependencies patch 5.2.1 -> 5.2.2

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score CVE Reachability
High High 8.2 CVE-2021-32803

Unreachable

High High 8.2 CVE-2021-32804

Unreachable

High High 8.2 CVE-2021-37701

Unreachable

High High 8.2 CVE-2021-37712

Unreachable

High High 8.2 CVE-2021-37713

Unreachable

High High 7.5 CVE-2021-3807

Unreachable

High High 7.5 CVE-2022-24999

Unreachable

High High 7.5 CVE-2023-34104

Unreachable

High High 7.5 CVE-2024-41818

Unreachable

High High 7.5 WS-2021-0152

Unreachable

Medium Medium 6.5 CVE-2019-6284

Unreachable

Medium Medium 6.5 CVE-2023-26136

Unreachable

Medium Medium 6.5 CVE-2023-26920

Unreachable

Medium Medium 5.3 CVE-2020-24025

Unreachable

Medium Medium 5.3 CVE-2021-29060

Unreachable

Medium Medium 5.3 CVE-2022-25858

Unreachable


Release Notes

rails/webpacker (@​rails/webpacker)

v5.2.2

Compare Source

  • Bump deps and remove node-sass #​2997.

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Apr 29, 2024
Copy link
Author

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: yarn.lock
error Command "up" not found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by Mend
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants