amilajack / popcorn-time-desktop

🍿 πŸ• 🎞 A Modern Popcorn Time Client
MIT License
468 stars 109 forks source link

Update dependency axios to v0.18.1 [SECURITY] - autoclosed #590

Closed renovate[bot] closed 5 years ago

renovate[bot] commented 5 years ago

This PR contains the following updates:

Package Type Update Change
axios dependencies patch 0.18.0 -> 0.18.1

GitHub Vulnerability Alerts

CVE-2019-10742

Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.


Release Notes

axios/axios ### [`v0.18.1`](https://togithub.com/axios/axios/releases/v0.18.1) [Compare Source](https://togithub.com/axios/axios/compare/v0.18.0...v0.18.1) Security Fix: - Destroy stream on exceeding maxContentLength (fixes [#​1098](https://togithub.com/axios/axios/issues/1098)) ([#​1485](https://togithub.com/axios/axios/issues/1485)) - Gadzhi Gadzhiev

Renovate configuration

:date: Schedule: "" (UTC).

:vertical_traffic_light: Automerge: Enabled.

:recycle: Rebasing: Whenever PR becomes conflicted, or if you modify the PR title to begin with "rebase!".

:no_bell: Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Renovate Bot. View repository job log here.