Open renovate[bot] opened 3 years ago
Merging #155 (d140484) into master (7e6cad0) will not change coverage. The diff coverage is
n/a
.
@@ Coverage Diff @@
## master #155 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 1 1
Lines 36 37 +1
Branches 6 6
=========================================
+ Hits 36 37 +1
Impacted Files | Coverage Ξ | |
---|---|---|
index.js | 100.00% <0.00%> (ΓΈ) |
This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.
This PR contains the following updates:
9.0.2
->13.1.2
GitHub Vulnerability Alerts
CVE-2020-7608
Affected versions of
yargs-parser
are vulnerable to prototype pollution. Arguments are not properly sanitized, allowing an attacker to modify the prototype ofObject
, causing the addition or modification of an existing property that will exist on all objects.Parsing the argument
--foo.__proto__.bar baz'
adds abar
property with valuebaz
to all objects. This is only exploitable if attackers have control over the arguments being passed toyargs-parser
.Recommendation
Upgrade to versions 13.1.2, 15.0.1, 18.1.1 or later.
Configuration
π Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
π¦ Automerge: Disabled by config. Please merge this manually once you are satisfied.
β» Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
π Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.