Closed dependabot[bot] closed 2 years ago
@dependabot merge
2022年4月29日(金) 6:10 dependabot[bot] @.***>:
This automated pull request fixes a security vulnerability https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/security/dependabot/11 (high severity).
Learn more about Dependabot security updates https://docs.github.com/github/managing-security-vulnerabilities/configuring-dependabot-security-updates.
Bumps async https://github.com/caolan/async from 2.6.3 to 2.6.4. Changelog
Sourced from async's changelog https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md.
v2.6.4
- Fix potential prototype pollution exploit (#1828 https://github-redirect.dependabot.com/caolan/async/issues/1828)
Commits
- c6bdaca https://github.com/caolan/async/commit/c6bdaca4f9175c14fc655d3783c6af6a883e6514 Version 2.6.4
- 8870da9 https://github.com/caolan/async/commit/8870da9d5022bab310413041b4079e10db3980b7 Update built files
- 4df6754 https://github.com/caolan/async/commit/4df6754ef4e96a742956df8782fee27242a2ea12 update changelog
- 8f7f903 https://github.com/caolan/async/commit/8f7f90342a6571ba1c197d747ebed30c368096d2 Fix prototype pollution vulnerability (#1828 https://github-redirect.dependabot.com/caolan/async/issues/1828)
- See full diff in compare view https://github.com/caolan/async/compare/v2.6.3...v2.6.4
Maintainer changes
This version was pushed to npm by hargasinski https://www.npmjs.com/~hargasinski, a new releaser for async since your current version.
[image: Dependabot compatibility score] https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/network/alerts .
You can view, comment on, or merge this pull request online at:
https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/pull/14 Commit Summary
- 343b9a9 https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/pull/14/commits/343b9a9dad578484e661331f207d39921d035558 chore(deps): bump async from 2.6.3 to 2.6.4
File Changes
(1 file https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/pull/14/files )
- M yarn.lock https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/pull/14/files#diff-51e4f558fae534656963876761c95b83b6ef5da5103c4adef6768219ed76c2de (12)
Patch Links:
- https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/pull/14.patch
https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/pull/14.diff
— Reply to this email directly, view it on GitHub https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/pull/14, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAAE2ATPLMWRHLSLFIOZXQDVHL5ERANCNFSM5UTYSNDQ . You are receiving this because you are subscribed to this thread.Message ID: @.***>
Bumps async from 2.6.3 to 2.6.4.
Changelog
Sourced from async's changelog.
Commits
c6bdaca
Version 2.6.48870da9
Update built files4df6754
update changelog8f7f903
Fix prototype pollution vulnerability (#1828)Maintainer changes
This version was pushed to npm by hargasinski, a new releaser for async since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/textlint-ja/textlint-rule-no-dropping-the-ra/network/alerts).