Closed renovate[bot] closed 5 years ago
This PR contains the following updates:
4.17.11
4.17.13
Affected versions of lodash are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
:date: Schedule: "" in timezone Asia/Tokyo.
:vertical_traffic_light: Automerge: Enabled.
:recycle: Rebasing: Whenever PR is stale, or if you modify the PR title to begin with "rebase!".
rebase!
:no_bell: Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot. View repository job log here.
This PR contains the following updates:
4.17.11
->4.17.13
GitHub Vulnerability Alerts
CVE-2019-10744
Affected versions of lodash are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Release Notes
lodash/lodash
### [`v4.17.13`](https://togithub.com/lodash/lodash/compare/4.17.12...4.17.13) [Compare Source](https://togithub.com/lodash/lodash/compare/4.17.11...4.17.13)Renovate configuration
:date: Schedule: "" in timezone Asia/Tokyo.
:vertical_traffic_light: Automerge: Enabled.
:recycle: Rebasing: Whenever PR is stale, or if you modify the PR title to begin with "
rebase!
".:no_bell: Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot. View repository job log here.