-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency karma to v6 [SECURITY] #23
base: master
Are you sure you want to change the base?
Conversation
Micro-Learning Topic: Open redirect (Detected by phrase)Matched on "Open Redirect"This vulnerability refers to the ability of an attacker to arbitrarily perform a redirection (external) or forward (internal) against the system. It arises due to insufficient validation or sanitisation of inputs used to perform a redirect or forward and may result in privilege escalation (in the case of a forward) or may be used to launch phishing attacks against users (in the case of redirects). Try this challenge in Secure Code WarriorMicro-Learning Topic: Cross-site scripting (Detected by phrase)Matched on "cross-site scripting"Reflected cross-site scripting vulnerabilities occur when unescaped input is displayed in the resulting page displayed to the user. When HTML or script is included in the input, it will be processed by a user's browser as HTML or script and can alter the appearance of the page or execute malicious scripts in their user context. Try this challenge in Secure Code Warrior |
9aa5020
to
fa168dc
Compare
fa168dc
to
0e54d13
Compare
c4513ad
to
2f8bd2c
Compare
636e522
to
3bd04c9
Compare
610d18b
to
4a5e74e
Compare
dc82c88
to
4552d25
Compare
b3b261f
to
be6a3af
Compare
be6a3af
to
bbff81a
Compare
93477db
to
29c2c2b
Compare
2928e54
to
b9eb20b
Compare
ac92a32
to
5f910e9
Compare
5f910e9
to
5e444ba
Compare
b7145ef
to
e310bae
Compare
0c5dead
to
72f1b96
Compare
fe30e7d
to
8bb5fa2
Compare
907bdba
to
8bb5fa2
Compare
ce7e5ec
to
7dc5ba8
Compare
38d762f
to
4b728bc
Compare
312abdd
to
80d90a2
Compare
e46e2bb
to
a9a70e1
Compare
ccba29e
to
e80f7ff
Compare
e80f7ff
to
3736df5
Compare
3736df5
to
8e93066
Compare
This PR contains the following updates:
~0.13.3
->~6.3.16
GitHub Vulnerability Alerts
CVE-2022-0437
karma prior to version 6.3.14 contains a cross-site scripting vulnerability.
CVE-2021-23495
Karma before 6.3.16 is vulnerable to Open Redirect due to missing validation of the return_url query parameter.
Release Notes
karma-runner/karma (karma)
v6.3.16
Compare Source
Bug Fixes
v6.3.15
Compare Source
Bug Fixes
v6.3.14
Compare Source
Bug Fixes
singleRun
andautoWatch
arefalse
(69cfc76)returnUrl
query param (839578c)v6.3.13
Compare Source
Bug Fixes
v6.3.12
Compare Source
Bug Fixes
v6.3.11
Compare Source
Bug Fixes
v6.3.10
Compare Source
Bug Fixes
v6.3.9
Compare Source
Bug Fixes
v6.3.8
Compare Source
Bug Fixes
v6.3.7
Compare Source
Bug Fixes
v6.3.6
Compare Source
Bug Fixes
v6.3.5
Compare Source
Bug Fixes
v6.3.4
Compare Source
Bug Fixes
v6.3.3
Compare Source
Bug Fixes
v6.3.2
Compare Source
Bug Fixes
v6.3.1
Compare Source
Bug Fixes
v6.3.0
Compare Source
Features
config.set()
call in karma.conf.js (#3660) (4c9097a)v6.2.0
Compare Source
Features
6.1.2 (2021-03-09)
Bug Fixes
6.1.1 (2021-02-12)
Bug Fixes
v6.1.2
Compare Source
Bug Fixes
v6.1.1
Compare Source
Bug Fixes
v6.1.0
Compare Source
Features
karma.config.parseConfig
error handling (#3635) (9dba1e2)6.0.4 (2021-02-01)
Bug Fixes
6.0.3 (2021-01-27)
Bug Fixes
6.0.2 (2021-01-25)
Bug Fixes
6.0.1 (2021-01-20)
Bug Fixes
customFileHandlers
provider (#3624) (25d9abb)v6.0.4
Compare Source
Bug Fixes
v6.0.3
Compare Source
Bug Fixes
v6.0.2
Compare Source
Bug Fixes
v6.0.1
Compare Source
Bug Fixes
customFileHandlers
provider (#3624) (25d9abb)v6.0.0
Compare Source
Bug Fixes
Features
BREAKING CHANGES
require('karma').server.start()
andrequire('karma').Server.start()
variants were removed from the public API. Instead use canonical form:dart
file type has been removed without a replacement.customFileHandlers
DI token has been removed. Usemiddleware
to achieve similar functionality.customScriptTypes
DI token has been removed. It had no effect, so no replacement is provided.5.2.3 (2020-09-25)
Bug Fixes
5.2.2 (2020-09-08)
Bug Fixes
5.2.1 (2020-09-02)
Bug Fixes
v5.2.3
Compare Source
Bug Fixes
v5.2.2
Compare Source
Bug Fixes
v5.2.1
Compare Source
Bug Fixes
v5.2.0
Compare Source
Bug Fixes
Features
5.1.1 (2020-07-28)
Bug Fixes
v5.1.1
Compare Source
Bug Fixes
v5.1.0
Compare Source
Features
5.0.9 (2020-05-19)
Bug Fixes
5.0.8 (2020-05-18)
Bug Fixes
5.0.7 (2020-05-16)
Bug Fixes
5.0.6 (2020-05-16)
Bug Fixes
5.0.5 (2020-05-07)
Bug Fixes
5.0.4 (2020-04-30)
Bug Fixes
5.0.3 (2020-04-29)
Bug Fixes
5.0.2 (2020-04-16)
Bug Fixes
5.0.1 (2020-04-10)
Bug Fixes
v5.0.9
Compare Source
Bug Fixes
v5.0.8
Compare Source
Bug Fixes
v5.0.7
Compare Source
Bug Fixes
v5.0.6
Compare Source
Bug Fixes
v5.0.5
Compare Source
Bug Fixes
v5.0.4
Compare Source
Bug Fixes
v5.0.3
Compare Source
Bug Fixes
v5.0.2
Compare Source
Bug Fixes
v5.0.1
Compare Source
Bug Fixes
v5.0.0
Compare Source
Bug Fixes
Code Refactoring
Continuous Integration
Features
DEFAULT_LISTEN_ADDR
constant (#3443) (057d527), closes #2479BREAKING CHANGES
4.4.1 (2019-10-18)
Bug Fixes
v4.4.1
Compare Source
Bug Fixes
v4.4.0
Compare Source
Bug Fixes
Features
v4.3.0
Compare Source
Bug Fixes
test:client
silently failing on Travis (#3343) (1489e9a), closes /travis-ci.org/karma-runner/karma/jobs/537027667#L1046Features
v4.2.0
Compare Source
Bug Fixes
v4.1.0
Compare Source
Bug Fixes
4.0.1 (2019-02-28)
Bug Fixes
v4.0.1
Compare Source
Bug Fixes
v4.0.0
Compare Source
Bug Fixes
Chores
BREAKING CHANGES
3.1.4 (2018-12-17)
Bug Fixes
3.1.3 (2018-12-01)
Bug Fixes
3.1.2 (2018-12-01)
Bug Fixes
Features
3.1.1 (2018-10-23)
Bug Fixes
v3.1.4
Compare Source
Bug Fixes
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.