luismayta / landslide-theme

Landslide Theme
GNU Lesser General Public License v3.0
2 stars 0 forks source link

ci(deps): Update dependency node-sass to v4 [SECURITY] #12

Closed renovate[bot] closed 3 years ago

renovate[bot] commented 3 years ago

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
node-sass ~3.13.1 -> ~4.14.1 age adoption passing confidence

:warning: MAJOR MAJOR MAJOR :warning:

GitHub Vulnerability Alerts

GHSA-9v62-24cr-58cx

Affected versions of node-sass are vulnerable to Denial of Service (DoS). Crafted objects passed to the renderSync function may trigger C++ assertions in CustomImporterBridge::get_importer_entry and CustomImporterBridge::post_process_return_value that crash the Node process. This may allow attackers to crash the system's running Node process and lead to Denial of Service.

Recommendation

Upgrade to version 4.13.1 or later


Release Notes

sass/node-sass ### [`v4.14.1`](https://togithub.com/sass/node-sass/releases/v4.14.1) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.14.0...v4.14.1) ##### Community - Add GitHub Actions for Alpine CI ([@​nschonni](https://togithub.com/nschonni), [#​2823](https://togithub.com/sass/node-sass/issues/2823)) ##### Fixes - Bump sass-graph@2.2.5 ([@​xzyfer](https://togithub.com/xzyfer), [#​2912](https://togithub.com/sass/node-sass/issues/2912)) ##### Supported Environments | OS | Architecture | Node | | ------------ | ------------ | ------------------------------------------------------------------------------ | | Windows | x86 & x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 | | OSX | x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 | | Linux\* | x86 & x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8**, 9**, 10**^, 11**^, 12**^, 13**^, 14\*\*^ | | Alpine Linux | x64 | 6, 8, 10, 11, 12, 13, 14 | | FreeBSD | i386 amd64 | 10, 12, 13 | \*Linux support refers to Ubuntu, Debian, and CentOS 5+ \*\* Not available on CentOS 5 ^ Only available on x64 ### [`v4.14.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v4140) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.13.1...v4.14.0) ### [`v4.13.1`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v4131) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.13.0...v4.13.1) ### [`v4.13.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v4130) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.12.0...v4.13.0) ### [`v4.12.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v4120) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.11.0...v4.12.0) ### [`v4.11.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v4110) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.10.0...v4.11.0) ### [`v4.10.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v4100) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.9.4...v4.10.0) ### [`v4.9.4`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v494) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.9.3...v4.9.4) ### [`v4.9.3`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v493) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.9.2...v4.9.3) ### [`v4.9.2`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v492) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.9.1...v4.9.2) ### [`v4.9.1`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v491) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.9.0...v4.9.1) ### [`v4.9.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v490) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.8.3...v4.9.0) ### [`v4.8.3`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v483) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.8.2...v4.8.3) ### [`v4.8.2`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v482) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.8.1...v4.8.2) ### [`v4.8.1`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v481) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.7.2...v4.8.1) ### [`v4.7.2`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v472) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.7.1...v4.7.2) ### [`v4.7.1`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v471) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.6.1...v4.7.1) ### [`v4.6.1`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v461) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.6.0...v4.6.1) ### [`v4.6.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v460) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.5.3...v4.6.0) ### [`v4.5.3`](https://togithub.com/sass/node-sass/releases/v4.5.3) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.5.2...v4.5.3) ##### Fixes - Installation error on Node 8 ([@​xzyfer](https://togithub.com/xzyfer), [#​1969](https://togithub.com/sass/node-sass/issues/1969)) ##### Supported Environments | OS | Architecture | Node | | ------------ | ------------ | ---------------------------------- | | Windows | x86 & x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8 | | OSX | x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8 | | Linux\* | x86 & x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8 | | Alpine | x64 | 4, 6, 7, 8 | | FreeBSD 10+ | i386 | 4, 6, 8 | | FreeBSD 10+ | amd64 | 4, 6, 8 | \*Linux support refers to Ubuntu, Debian, and CentOS 5 ### [`v4.5.2`](https://togithub.com/sass/node-sass/releases/v4.5.2) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.5.1...v4.5.2) ##### Fixes - Installation error on Node 8 ([@​mscdex](https://togithub.com/mscdex), [#​1934](https://togithub.com/sass/node-sass/issues/1934)) ##### Supported Environments | OS | Architecture | Node | | ------- | ------------ | ------------------------------- | | Windows | x86 & x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6,7 | | OSX | x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7 | | Linux\* | x86 & x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7 | | Alpine | x64 | 4, 6, 7 | \*Linux support refers to Ubuntu, Debian, and CentOS 5 ### [`v4.5.1`](https://togithub.com/sass/node-sass/releases/v4.5.1) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.5.0...v4.5.1) ##### Fixes - Fix instructions about rebuilding the binary ([@​xzyfer](https://togithub.com/xzyfer), [#​1885](https://togithub.com/sass/node-sass/issues/1885)) - Add binding.js to Coveralls coverage ([@​nschonni](https://togithub.com/nschonni), [#​1902](https://togithub.com/sass/node-sass/issues/1902)) - Update request version to avoid npm warn ([@​arzafran](https://togithub.com/arzafran), [#​1915](https://togithub.com/sass/node-sass/issues/1915)) - Update link for VS 2013 download ([@​hweeks](https://togithub.com/hweeks), [#​1921](https://togithub.com/sass/node-sass/issues/1921)) - Make binding tests less fragile ([@​xzyfer](https://togithub.com/xzyfer), [#​1929](https://togithub.com/sass/node-sass/issues/1929)) - Don't throw when being run on Node 8 ([@​xzyfer](https://togithub.com/xzyfer), [#​1929](https://togithub.com/sass/node-sass/issues/1929)) * * * ##### Supported Environments | OS | Architecture | Node | | ------- | ------------ | ------------------------------- | | Windows | x86 & x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6,7 | | OSX | x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7 | | Linux\* | x86 & x64 | 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7 | | Alpine | x64 | 4, 6, 7 | \*Linux support refers to Ubuntu, Debian, and CentOS 5 ### [`v4.5.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v450) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.4.0...v4.5.0) ### [`v4.4.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v440) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.3.0...v4.4.0) ### [`v4.3.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v430) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.2.0...v4.3.0) ### [`v4.2.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v420) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.1.1...v4.2.0) ### [`v4.1.1`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v411) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.1.0...v4.1.1) ### [`v4.1.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v410) [Compare Source](https://togithub.com/sass/node-sass/compare/v4.0.0...v4.1.0) ### [`v4.0.0`](https://togithub.com/sass/node-sass/blob/master/CHANGELOG.md#v400) [Compare Source](https://togithub.com/sass/node-sass/compare/v3.13.1...v4.0.0)

Configuration

:date: Schedule: "" in timezone America/Lima.

:vertical_traffic_light: Automerge: Enabled.

:recycle: Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

:no_bell: Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by WhiteSource Renovate. View repository job log here.