Open renovate[bot] opened 1 month ago
This PR contains the following updates:
1.9.1
1.12.1
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
underscore
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
This PR contains the following updates:
1.9.1
->1.12.1
GitHub Vulnerability Alerts
CVE-2021-23358
The package
underscore
from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.Release Notes
jashkenas/underscore (underscore)
### [`v1.12.1`](https://togithub.com/jashkenas/underscore/compare/1.12.0...1.12.1) [Compare Source](https://togithub.com/jashkenas/underscore/compare/1.12.0...1.12.1) ### [`v1.12.0`](https://togithub.com/jashkenas/underscore/compare/1.11.0...1.12.0) [Compare Source](https://togithub.com/jashkenas/underscore/compare/1.11.0...1.12.0) ### [`v1.11.0`](https://togithub.com/jashkenas/underscore/compare/1.10.2...1.11.0) [Compare Source](https://togithub.com/jashkenas/underscore/compare/1.10.2...1.11.0) ### [`v1.10.2`](https://togithub.com/jashkenas/underscore/compare/1.10.1...1.10.2) [Compare Source](https://togithub.com/jashkenas/underscore/compare/1.10.1...1.10.2) ### [`v1.10.1`](https://togithub.com/jashkenas/underscore/compare/1.10.0...1.10.1) [Compare Source](https://togithub.com/jashkenas/underscore/compare/1.10.0...1.10.1) ### [`v1.10.0`](https://togithub.com/jashkenas/underscore/compare/1.9.2...1.10.0) [Compare Source](https://togithub.com/jashkenas/underscore/compare/1.9.2...1.10.0) ### [`v1.9.2`](https://togithub.com/jashkenas/underscore/compare/1.9.1...1.9.2) [Compare Source](https://togithub.com/jashkenas/underscore/compare/1.9.1...1.9.2)Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.