twlevelup / watch_edition

LevelUp Build project for prototyping simple smart watch apps
http://levelup.thoughtworks.com
16 stars 15 forks source link

Update dependency url-parse [SECURITY] #497

Closed renovate[bot] closed 2 years ago

renovate[bot] commented 2 years ago

WhiteSource Renovate

This PR contains the following updates:

Package Change
url-parse 1.5.6 -> 1.5.8
url-parse 1.5.3 -> 1.5.6

GitHub Vulnerability Alerts

CVE-2022-0639

url-parse prior to version 1.5.7 is vulnerable to Authorization Bypass Through User-Controlled Key. Url-parse is not able to verify broken protocol. This will allow to bypass hostname validation.

CVE-2022-0686

url-parse prior to version 1.5.8 is vulnerable to Authorization Bypass Through User-Controlled Key.

CVE-2022-0512

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Enabled.

â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.



This PR has been generated by WhiteSource Renovate. View repository job log here.