Closed renovate[bot] closed 2 years ago
This PR contains the following updates:
4.0.0
4.0.1
The npm package y18n before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution.
y18n
const y18n = require('y18n')(); y18n.setLocale('__proto__'); y18n.updateLocale({polluted: true}); console.log(polluted); // true
Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later.
đ Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
đĻ Automerge: Disabled by config. Please merge this manually once you are satisfied.
âģ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
đ Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.
Size Change: 0 B
Total Size: 19 kB
compressed-size-action
This PR contains the following updates:
4.0.0
->4.0.1
GitHub Vulnerability Alerts
CVE-2020-7774
Overview
The npm package
y18n
before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution.POC
Recommendation
Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later.
Configuration
đ Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
đĻ Automerge: Disabled by config. Please merge this manually once you are satisfied.
âģ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
đ Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.