ricokahler / flair

a lean, component-centric style system for React components
MIT License
19 stars 0 forks source link

Update dependency normalize-url to 4.5.1 [SECURITY] - autoclosed #151

Closed renovate[bot] closed 3 years ago

renovate[bot] commented 3 years ago

WhiteSource Renovate

This PR contains the following updates:

Package Change
normalize-url 3.3.0 -> 4.5.1
normalize-url 1.9.1 -> 4.5.1

GitHub Vulnerability Alerts

CVE-2021-33502

The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.


Configuration

📅 Schedule: "" (UTC).

đŸšĻ Automerge: Disabled by config. Please merge this manually once you are satisfied.

â™ģ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.



This PR has been generated by WhiteSource Renovate. View repository job log here.

github-actions[bot] commented 3 years ago

Size Change: 0 B

Total Size: 19 kB

ℹī¸ View Unchanged | Filename | Size | Change | | :--- | :---: | :---: | | `dist/babel-plugin-plugin/index.js` | 1.44 kB | 0 B | | `dist/collect/index.js` | 4.6 kB | 0 B | | `dist/common/index.esm.js` | 617 B | 0 B | | `dist/common/index.js` | 743 B | 0 B | | `dist/core/index.esm.js` | 697 B | 0 B | | `dist/core/index.js` | 1.09 kB | 0 B | | `dist/flair/index.esm.js` | 93 B | 0 B | | `dist/flair/index.js` | 370 B | 0 B | | `dist/loader/index.js` | 280 B | 0 B | | `dist/ssr/index.esm.js` | 1.23 kB | 0 B | | `dist/ssr/index.js` | 2.91 kB | 0 B | | `dist/standalone/index.esm.js` | 1.62 kB | 0 B | | `dist/standalone/index.js` | 3.29 kB | 0 B |

compressed-size-action