ricokahler / flair

a lean, component-centric style system for React components
MIT License
19 stars 0 forks source link

Update dependency path-parse to 1.0.7 [SECURITY] - autoclosed #153

Closed renovate[bot] closed 1 year ago

renovate[bot] commented 3 years ago

Mend Renovate

This PR contains the following updates:

Package Change
path-parse 1.0.6 -> 1.0.7

GitHub Vulnerability Alerts

CVE-2021-23343

Affected versions of npm package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

đŸšĻ Automerge: Disabled by config. Please merge this manually once you are satisfied.

â™ģ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

github-actions[bot] commented 3 years ago

Size Change: 0 B

Total Size: 19 kB

ℹī¸ View Unchanged | Filename | Size | | :--- | :---: | | `dist/babel-plugin-plugin/index.js` | 1.44 kB | | `dist/collect/index.js` | 4.6 kB | | `dist/common/index.esm.js` | 617 B | | `dist/common/index.js` | 743 B | | `dist/core/index.esm.js` | 697 B | | `dist/core/index.js` | 1.09 kB | | `dist/flair/index.esm.js` | 93 B | | `dist/flair/index.js` | 370 B | | `dist/loader/index.js` | 280 B | | `dist/ssr/index.esm.js` | 1.23 kB | | `dist/ssr/index.js` | 2.91 kB | | `dist/standalone/index.esm.js` | 1.62 kB | | `dist/standalone/index.js` | 3.29 kB |

compressed-size-action