Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency xml2js to ^0.5.0 [SECURITY] #17

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented May 29, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
xml2js ^0.4.17 -> ^0.5.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-0842

xml2js versions before 0.5.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.


Release Notes

Leonidas-from-XIV/node-xml2js (xml2js)

v0.5.0

Compare Source

v0.4.23

Compare Source

v0.4.22

Compare Source

v0.4.21

Compare Source

v0.4.20

Compare Source

v0.4.19

Compare Source

v0.4.18

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jun 1, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 64192f5 to 9ee2d8c Compare June 1, 2023 16:50
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jun 10, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 9ee2d8c to 97c126c Compare June 10, 2023 05:45
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jun 11, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 97c126c to 93b2edc Compare June 11, 2023 02:22
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jun 14, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 93b2edc to 8c3d4a4 Compare June 14, 2023 02:44
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jun 16, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 8c3d4a4 to 4639984 Compare June 16, 2023 17:53
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jun 18, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 4639984 to 7e9c4f0 Compare June 18, 2023 17:21
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jun 22, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 7e9c4f0 to 0f00c8e Compare June 22, 2023 23:53
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jun 30, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 0f00c8e to 0ae7b52 Compare June 30, 2023 05:14
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jul 1, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 0ae7b52 to 7ef1dda Compare July 1, 2023 01:04
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jul 8, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 7ef1dda to 4f0dd83 Compare July 8, 2023 02:52
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jul 9, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 4f0dd83 to ed22ef2 Compare July 9, 2023 05:18
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jul 10, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch 2 times, most recently from e7f32d7 to 2eb8732 Compare July 11, 2023 20:45
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jul 11, 2023
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jul 18, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 2eb8732 to 0c0c843 Compare July 18, 2023 02:40
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jul 19, 2023
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 0c0c843 to 953bddf Compare July 19, 2023 05:17
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] May 23, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 8ce155e to 6b97d1b Compare June 5, 2024 05:39
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jun 5, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 6b97d1b to 390a824 Compare June 6, 2024 05:37
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jun 6, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 390a824 to 65435c6 Compare June 28, 2024 02:58
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jun 28, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 65435c6 to 33d00a4 Compare June 29, 2024 11:32
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jun 29, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 33d00a4 to 6660041 Compare July 14, 2024 14:51
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jul 14, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 6660041 to 8c533fa Compare July 15, 2024 05:58
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jul 15, 2024
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jul 24, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch 2 times, most recently from 95e53a1 to beea6d7 Compare July 26, 2024 08:49
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jul 26, 2024
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Jul 29, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from beea6d7 to 25903ce Compare July 29, 2024 02:36
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Jul 30, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 25903ce to a7823de Compare July 30, 2024 02:36
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Oct 10, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch 2 times, most recently from 65dbddb to 8188248 Compare October 13, 2024 13:54
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Oct 13, 2024
@renovate renovate bot changed the title Update dependency xml2js to ^0.5.0 [SECURITY] Update dependency xml2js to ^0.6.0 [SECURITY] Oct 29, 2024
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from 8188248 to ab06ef1 Compare October 29, 2024 05:33
@renovate renovate bot force-pushed the renovate/npm-xml2js-vulnerability branch from ab06ef1 to dc86fc1 Compare October 30, 2024 23:46
@renovate renovate bot changed the title Update dependency xml2js to ^0.6.0 [SECURITY] Update dependency xml2js to ^0.5.0 [SECURITY] Oct 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants