Open renovate[bot] opened 1 month ago
Latest commit: dcf82ab1ac541279f22efc538877de4d01531eea
Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.
Click here to learn what changesets are, and how to add one.
Click here if you're a maintainer who wants to add a changeset to this PR
Preview URLs:
This PR contains the following updates:
7.119.0
->7.119.1
GitHub Vulnerability Alerts
GHSA-593m-55hh-j8gv
Impact
In case a Prototype Pollution vulnerability is present in a user's application or bundled libraries, the Sentry SDK could potentially serve as a gadget to exploit that vulnerability. The exploitability depends on the specific details of the underlying Prototype Pollution issue.
Patches
The issue was patched in all Sentry JavaScript SDKs starting from the 8.33.0 version. Also, the fix was backported to SDK v7 in 7.119.1.
References
Release Notes
getsentry/sentry-javascript (@sentry/browser)
### [`v7.119.1`](https://redirect.github.com/getsentry/sentry-javascript/releases/tag/7.119.1) [Compare Source](https://redirect.github.com/getsentry/sentry-javascript/compare/7.119.0...7.119.1) - fix(browser/v7): Ensure wrap() only returns functions ([#13838](https://redirect.github.com/getsentry/sentry-javascript/issues/13838) backport) Work in this release contributed by [@legobeat](https://redirect.github.com/legobeat). Thank you for your contribution!Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.