beeequeue / yuna

ツ An anime player.
https://yuna.moe
GNU Affero General Public License v3.0
571 stars 42 forks source link

Update dependency browserslist to v4.16.5 [SECURITY] #977

Closed renovate[bot] closed 3 years ago

renovate[bot] commented 3 years ago

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
browserslist 4.16.0 -> 4.16.5 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-23364

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.


Release Notes

browserslist/browserslist ### [`v4.16.5`](https://togithub.com/browserslist/browserslist/blob/master/CHANGELOG.md#​4165) [Compare Source](https://togithub.com/browserslist/browserslist/compare/4.16.4...4.16.5) - Fixed unsafe RegExp (by Yeting Li). ### [`v4.16.4`](https://togithub.com/browserslist/browserslist/blob/master/CHANGELOG.md#​4164) [Compare Source](https://togithub.com/browserslist/browserslist/compare/4.16.3...4.16.4) - Fixed unsafe RegExp. - Added artifactory support to `--update-db` (by Ittai Baratz). ### [`v4.16.3`](https://togithub.com/browserslist/browserslist/blob/master/CHANGELOG.md#​4163) [Compare Source](https://togithub.com/browserslist/browserslist/compare/4.16.2...4.16.3) - Fixed `--update-db`. ### [`v4.16.2`](https://togithub.com/browserslist/browserslist/blob/master/CHANGELOG.md#​4162) [Compare Source](https://togithub.com/browserslist/browserslist/compare/4.16.1...4.16.2) - Fixed `--update-db` (by [@​ialarmedalien](https://togithub.com/ialarmedalien)). ### [`v4.16.1`](https://togithub.com/browserslist/browserslist/blob/master/CHANGELOG.md#​4161) [Compare Source](https://togithub.com/browserslist/browserslist/compare/4.16.0...4.16.1) - Fixed Chrome 4 with `mobileToDesktop` (by Aron Woost).

Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by WhiteSource Renovate. View repository job log here.