TreyM-WSS / concord

Concord - workflow orchestration and continuous deployment management
https://concord.walmartlabs.com
Other
0 stars 1 forks source link

Update dependency ansi_up to v5 #244

Open mend-for-github-com[bot] opened 1 year ago

mend-for-github-com[bot] commented 1 year ago

This PR contains the following updates:

Package Type Update Change
ansi_up dependencies major 4.0.4 -> 5.0.0

By merging this PR, the below issues will be automatically resolved and closed:

Severity CVSS Score CVE GitHub Issue
Medium 6.1 CVE-2021-3377 #138

Release Notes

drudru/ansi_up (ansi_up) ### [`v5.0.0`](https://togithub.com/drudru/ansi_up/releases/tag/v5.0.0): Security fix for OSC URLs [Compare Source](https://togithub.com/drudru/ansi_up/compare/v4.0.4...v5.0.0) If you had a malformed URL when using the OSC URL sequence, it would not be properly escaped. Also, html escaping is now mandatory. The 'escape_for_html' property was removed. As a result, we increased the MAJOR version to 5.