Skip to content
This repository has been archived by the owner on Dec 5, 2024. It is now read-only.

chore(deps): update all non-major dependencies #381

Merged
merged 2 commits into from
Mar 2, 2021

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 18, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@nuxt/http ^0.6.2 -> ^0.6.4 age adoption passing confidence
docus ^0.0.8 -> ^0.0.9 age adoption passing confidence
node 12.20.2 -> 12.21.0 age adoption passing confidence

Release Notes

nuxt/http

v0.6.4

Compare Source

v0.6.3

Compare Source

nuxtlabs/docus

v0.0.9

Compare Source

nodejs/node

v12.21.0

Compare Source

This is a security release.

Notable changes

Vulnerabilities fixed:

  • CVE-2021-22883: HTTP2 'unknownProtocol' cause Denial of Service by resource exhaustion
    • Affected Node.js versions are vulnerable to denial of service attacks when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
  • CVE-2021-22884: DNS rebinding in --inspect
    • Affected Node.js versions are vulnerable to denial of service attacks when the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.
  • CVE-2021-23840: OpenSSL - Integer overflow in CipherUpdate
Commits

Renovate configuration

📅 Schedule: At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Renovate will not automatically rebase this PR, because other commits have been found.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by WhiteSource Renovate. View repository job log here.

@vercel
Copy link

vercel bot commented Feb 18, 2021

This pull request is being automatically deployed with Vercel (learn more).
To see the status of your deployment, click below or on the icon next to each commit.

🔍 Inspect: https://vercel.com/nuxt-community/composition-api/3TbgEWggtuW5qwBPte6Cc2S9q729
✅ Preview: https://composition-api-git-renovate-all-minor-patch-nuxt-community.vercel.app

@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 2e406e5 to 52a4f8a Compare February 18, 2021 17:49
@renovate renovate bot changed the title chore(deps): update all non-major dependencies to ^7.12.17 chore(deps): update all non-major dependencies Feb 18, 2021
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 52a4f8a to 2e51002 Compare February 19, 2021 09:51
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 2e51002 to 3005a4c Compare February 19, 2021 17:52
mathe42
mathe42 previously approved these changes Feb 21, 2021
Copy link
Collaborator

@mathe42 mathe42 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 3005a4c to 3dab686 Compare February 22, 2021 14:37
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 3dab686 to 3455f11 Compare February 22, 2021 18:37
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 3455f11 to f0e09fb Compare February 22, 2021 20:58
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from f0e09fb to 49e734a Compare February 22, 2021 23:13
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 49e734a to a9778f6 Compare February 23, 2021 01:51
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from a9778f6 to 015ae85 Compare February 23, 2021 04:23
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 015ae85 to 9bc76d8 Compare February 23, 2021 10:59
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 9bc76d8 to e58e34a Compare February 23, 2021 13:03
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from e58e34a to e123fa2 Compare February 23, 2021 14:54
@renovate renovate bot changed the title chore(deps): update all non-major dependencies chore(deps): update node.js to v12.21.0 Feb 23, 2021
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 0b3e01e to ee66e9a Compare February 24, 2021 09:29
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from ee66e9a to e5f4578 Compare February 24, 2021 18:16
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from e5f4578 to 94caf73 Compare February 25, 2021 16:46
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 94caf73 to 7e00a21 Compare February 26, 2021 22:23
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 7e00a21 to 311c6b7 Compare February 27, 2021 00:57
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 311c6b7 to 346ecc3 Compare February 27, 2021 20:14
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 346ecc3 to 79dac61 Compare February 28, 2021 00:41
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 79dac61 to 15f43ae Compare February 28, 2021 20:17
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 15f43ae to 5d378f3 Compare March 1, 2021 10:04
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 5d378f3 to a55e8a1 Compare March 1, 2021 19:09
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from a55e8a1 to 9ff9cdf Compare March 1, 2021 22:55
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants