-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update dependency semver-regex to 3.1.4 [security] - abandoned #471
base: master
Are you sure you want to change the base?
Conversation
Codecov Report
@@ Coverage Diff @@
## master #471 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 1 1
Lines 4 4
=========================================
Hits 4 4 Continue to review full report at Codecov.
|
bf0a012
to
d193522
Compare
e43bb95
to
02ca3bd
Compare
f514cff
to
8773ddb
Compare
194737a
to
ff1f339
Compare
7dea48b
to
db49be6
Compare
5b70844
to
e11e1bf
Compare
e11e1bf
to
dcab50c
Compare
1de83f5
to
5b82a89
Compare
5b82a89
to
6343ecf
Compare
Autoclosing SkippedThis PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error. |
This PR contains the following updates:
3.1.2
->3.1.4
GitHub Vulnerability Alerts
CVE-2021-3795
npm
semver-regex
is vulnerable to Inefficient Regular Expression ComplexityCVE-2021-43307
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.