classicvalues / JQuery-Mobile

JQuery based Website for MM113SPRING2022
MIT License
1 stars 1 forks source link

fix(deps): update dependency sails to v1.5.7 [security] #114

Open renovate[bot] opened 1 year ago

renovate[bot] commented 1 year ago

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
sails (source) 1.5.3 -> 1.5.7 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-38504

Impact

In Sails apps <=v1.5.6, an attacker can send a virtual request that will cause the node process to crash.

Patches

This behavior was fixed in Sails v1.5.7

Workarounds

Disable the sockets hook and remove the sails.io.js client

References

https://github.com/balderdashy/sails/pull/7287

Big thanks to @​ThomasRinsma at Codean!


Release Notes

balderdashy/sails (sails) ### [`v1.5.7`](https://redirect.github.com/balderdashy/sails/releases/tag/v1.5.7) [Compare Source](https://redirect.github.com/balderdashy/sails/compare/v1.5.6...v1.5.7) #### What's Changed - \[fix] update logic to display local URL by [@​DominusKelvin](https://redirect.github.com/DominusKelvin) in [https://github.com/balderdashy/sails/pull/7285](https://redirect.github.com/balderdashy/sails/pull/7285) - Upgrade `semver` dependency (v4.3.6 Β» v7.5.2) by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7288](https://redirect.github.com/balderdashy/sails/pull/7288) - Improve virtual request parsing by [@​mikermcneil](https://redirect.github.com/mikermcneil) in [https://github.com/balderdashy/sails/pull/7287](https://redirect.github.com/balderdashy/sails/pull/7287) Big thanks to [@​ThomasRinsma](https://redirect.github.com/ThomasRinsma) at [Codean](https://www.linkedin.com/company/codeanio/)! **Full Changelog**: https://github.com/balderdashy/sails/compare/v1.5.5...v1.5.7 ### [`v1.5.6`](https://redirect.github.com/balderdashy/sails/compare/v1.5.5...v1.5.6) [Compare Source](https://redirect.github.com/balderdashy/sails/compare/v1.5.5...v1.5.6) ### [`v1.5.5`](https://redirect.github.com/balderdashy/sails/releases/tag/v1.5.5) [Compare Source](https://redirect.github.com/balderdashy/sails/compare/v1.5.4...v1.5.5) #### What's Changed - ci: test builds on supported node versions by [@​alxndrsn](https://redirect.github.com/alxndrsn) in [https://github.com/balderdashy/sails/pull/7069](https://redirect.github.com/balderdashy/sails/pull/7069) - \[misc] Bring documentation into this repo by [@​rachaelshaw](https://redirect.github.com/rachaelshaw) in [https://github.com/balderdashy/sails/pull/7070](https://redirect.github.com/balderdashy/sails/pull/7070) - \[misc] Change name of documentation folder + update links by [@​rachaelshaw](https://redirect.github.com/rachaelshaw) in [https://github.com/balderdashy/sails/pull/7075](https://redirect.github.com/balderdashy/sails/pull/7075) - \[patch] fix typo in Events.md by [@​DominusKelvin](https://redirect.github.com/DominusKelvin) in [https://github.com/balderdashy/sails/pull/7086](https://redirect.github.com/balderdashy/sails/pull/7086) - \[misc]\[docs] Adding more info about the unique attribute setting by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7078](https://redirect.github.com/balderdashy/sails/pull/7078) - Update sails.config.connections.md by [@​anilbhanushali](https://redirect.github.com/anilbhanushali) in [https://github.com/balderdashy/sails/pull/7097](https://redirect.github.com/balderdashy/sails/pull/7097) - \[proposal] sails-linker.js.md by [@​jdsapariya18](https://redirect.github.com/jdsapariya18) in [https://github.com/balderdashy/sails/pull/7101](https://redirect.github.com/balderdashy/sails/pull/7101) - \[patch] fix node 14 warnings by upgrading prompt dependency by [@​DominusKelvin](https://redirect.github.com/DominusKelvin) in [https://github.com/balderdashy/sails/pull/7084](https://redirect.github.com/balderdashy/sails/pull/7084) - \[patch] change typo --no-front-end to --no-frontend in CLI flag help output by [@​DominusKelvin](https://redirect.github.com/DominusKelvin) in [https://github.com/balderdashy/sails/pull/7109](https://redirect.github.com/balderdashy/sails/pull/7109) - \[misc] Wrong wording in update.md by [@​anurbol](https://redirect.github.com/anurbol) in [https://github.com/balderdashy/sails/pull/7134](https://redirect.github.com/balderdashy/sails/pull/7134) - \[misc] Wrong wording in destroy.md by [@​anurbol](https://redirect.github.com/anurbol) in [https://github.com/balderdashy/sails/pull/7135](https://redirect.github.com/balderdashy/sails/pull/7135) - \[misc] Update mongo tutorial to show usage with latest sails-mongo adapter by [@​rachaelshaw](https://redirect.github.com/rachaelshaw) in [https://github.com/balderdashy/sails/pull/7074](https://redirect.github.com/balderdashy/sails/pull/7074) - \[patch] Updated "datastore configuration" link by [@​AlanConstantino](https://redirect.github.com/AlanConstantino) in [https://github.com/balderdashy/sails/pull/7079](https://redirect.github.com/balderdashy/sails/pull/7079) - \[patch] upgrade sails-hook-orm dependency by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7147](https://redirect.github.com/balderdashy/sails/pull/7147) - \[patch] fix data type in docs (should be optional) by [@​mikermcneil](https://redirect.github.com/mikermcneil) in [https://github.com/balderdashy/sails/pull/7151](https://redirect.github.com/balderdashy/sails/pull/7151) - \[patch] Fix node deprecation warnings by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7148](https://redirect.github.com/balderdashy/sails/pull/7148) - \[fixes [#​7107](https://redirect.github.com/balderdashy/sails/issues/7107)] Change trustProxy isNaN check to \_.isNaN by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7146](https://redirect.github.com/balderdashy/sails/pull/7146) - \[patch] Small text correction by [@​zsteinkamp](https://redirect.github.com/zsteinkamp) in [https://github.com/balderdashy/sails/pull/7158](https://redirect.github.com/balderdashy/sails/pull/7158) - Fix typo in sails-run.js by [@​eltociear](https://redirect.github.com/eltociear) in [https://github.com/balderdashy/sails/pull/7174](https://redirect.github.com/balderdashy/sails/pull/7174) - \[proposal] Add documentation regarding a breaking change in SSL connection syntax by [@​jarodccrowe](https://redirect.github.com/jarodccrowe) in [https://github.com/balderdashy/sails/pull/7175](https://redirect.github.com/balderdashy/sails/pull/7175) - \[patch] correct misspelt waterline by [@​DominusKelvin](https://redirect.github.com/DominusKelvin) in [https://github.com/balderdashy/sails/pull/7176](https://redirect.github.com/balderdashy/sails/pull/7176) - \[fixes [#​7168](https://redirect.github.com/balderdashy/sails/issues/7168)] Add support for latest version of connect-mongo by [@​ElizabethForest](https://redirect.github.com/ElizabethForest) in [https://github.com/balderdashy/sails/pull/7172](https://redirect.github.com/balderdashy/sails/pull/7172) - \[misc] Add note about undefined attributes to upgrading docs by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7181](https://redirect.github.com/balderdashy/sails/pull/7181) - \[fixes [#​7201](https://redirect.github.com/balderdashy/sails/issues/7201)] Bump up prompt to 1.2.1 by [@​dhwaneetbhatt](https://redirect.github.com/dhwaneetbhatt) in [https://github.com/balderdashy/sails/pull/7202](https://redirect.github.com/balderdashy/sails/pull/7202) - \[misc] Upgrade sort-route-addresses dependency by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7203](https://redirect.github.com/balderdashy/sails/pull/7203) - Update Permissions.md by [@​pbkompasz](https://redirect.github.com/pbkompasz) in [https://github.com/balderdashy/sails/pull/7219](https://redirect.github.com/balderdashy/sails/pull/7219) - Update Travis CI configuration by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7226](https://redirect.github.com/balderdashy/sails/pull/7226) - Update minimist dependency to v1.2.6 by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7242](https://redirect.github.com/balderdashy/sails/pull/7242) - update async dependency to 2.6.4 by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7244](https://redirect.github.com/balderdashy/sails/pull/7244) - Docs: Update session config docs by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7245](https://redirect.github.com/balderdashy/sails/pull/7245) - Upgrade ejs dependency to 3.1.7 by [@​eashaw](https://redirect.github.com/eashaw) in [https://github.com/balderdashy/sails/pull/7243](https://redirect.github.com/balderdashy/sails/pull/7243) - Update helpers.md docs to explain subfolders by [@​itsalaidbacklife](https://redirect.github.com/itsalaidbacklife) in [https://github.com/balderdashy/sails/pull/7263](https://redirect.github.com/balderdashy/sails/pull/7263) - bump expressjs to version 4.17.3 by [@​f3lang](https://redirect.github.com/f3lang) in [https://github.com/balderdashy/sails/pull/7268](https://redirect.github.com/balderdashy/sails/pull/7268) - Removed "Newsgroup" link by [@​Sampfluger88](https://redirect.github.com/Sampfluger88) in [https://github.com/balderdashy/sails/pull/7277](https://redirect.github.com/balderdashy/sails/pull/7277) - \[feat] Implement custom inspect on sails.helpers by [@​DominusKelvin](https://redirect.github.com/DominusKelvin) in [https://github.com/balderdashy/sails/pull/7282](https://redirect.github.com/balderdashy/sails/pull/7282) #### New Contributors - [@​alxndrsn](https://redirect.github.com/alxndrsn) made their first contribution in [https://github.com/balderdashy/sails/pull/7069](https://redirect.github.com/balderdashy/sails/pull/7069) - [@​DominusKelvin](https://redirect.github.com/DominusKelvin) made their first contribution in [https://github.com/balderdashy/sails/pull/7086](https://redirect.github.com/balderdashy/sails/pull/7086) - [@​anilbhanushali](https://redirect.github.com/anilbhanushali) made their first contribution in [https://github.com/balderdashy/sails/pull/7097](https://redirect.github.com/balderdashy/sails/pull/7097) - [@​jdsapariya18](https://redirect.github.com/jdsapariya18) made their first contribution in [https://github.com/balderdashy/sails/pull/7101](https://redirect.github.com/balderdashy/sails/pull/7101) - [@​anurbol](https://redirect.github.com/anurbol) made their first contribution in [https://github.com/balderdashy/sails/pull/7134](https://redirect.github.com/balderdashy/sails/pull/7134) - [@​AlanConstantino](https://redirect.github.com/AlanConstantino) made their first contribution in [https://github.com/balderdashy/sails/pull/7079](https://redirect.github.com/balderdashy/sails/pull/7079) - [@​zsteinkamp](https://redirect.github.com/zsteinkamp) made their first contribution in [https://github.com/balderdashy/sails/pull/7158](https://redirect.github.com/balderdashy/sails/pull/7158) - [@​eltociear](https://redirect.github.com/eltociear) made their first contribution in [https://github.com/balderdashy/sails/pull/7174](https://redirect.github.com/balderdashy/sails/pull/7174) - [@​jarodccrowe](https://redirect.github.com/jarodccrowe) made their first contribution in [https://github.com/balderdashy/sails/pull/7175](https://redirect.github.com/balderdashy/sails/pull/7175) - [@​ElizabethForest](https://redirect.github.com/ElizabethForest) made their first contribution in [https://github.com/balderdashy/sails/pull/7172](https://redirect.github.com/balderdashy/sails/pull/7172) - [@​dhwaneetbhatt](https://redirect.github.com/dhwaneetbhatt) made their first contribution in [https://github.com/balderdashy/sails/pull/7202](https://redirect.github.com/balderdashy/sails/pull/7202) - [@​pbkompasz](https://redirect.github.com/pbkompasz) made their first contribution in [https://github.com/balderdashy/sails/pull/7219](https://redirect.github.com/balderdashy/sails/pull/7219) - [@​itsalaidbacklife](https://redirect.github.com/itsalaidbacklife) made their first contribution in [https://github.com/balderdashy/sails/pull/7263](https://redirect.github.com/balderdashy/sails/pull/7263) - [@​f3lang](https://redirect.github.com/f3lang) made their first contribution in [https://github.com/balderdashy/sails/pull/7268](https://redirect.github.com/balderdashy/sails/pull/7268) - [@​Sampfluger88](https://redirect.github.com/Sampfluger88) made their first contribution in [https://github.com/balderdashy/sails/pull/7277](https://redirect.github.com/balderdashy/sails/pull/7277) **Full Changelog**: https://github.com/balderdashy/sails/compare/v1.4.0...v1.5.5 ### [`v1.5.4`](https://redirect.github.com/balderdashy/sails/compare/v1.5.3...v1.5.4) [Compare Source](https://redirect.github.com/balderdashy/sails/compare/v1.5.3...v1.5.4)

Configuration

πŸ“… Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

β™» Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

πŸ”• Ignore: Close this PR and you won't be reminded about this update again.



This PR was generated by Mend Renovate. View the repository job log.