Closed renovate[bot] closed 3 years ago
This PR contains the following updates:
4.0.0
4.0.1
The npm package y18n before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution.
y18n
const y18n = require('y18n')(); y18n.setLocale('__proto__'); y18n.updateLocale({polluted: true}); console.log(polluted); // true
Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later.
:date: Schedule: "" (UTC).
:vertical_traffic_light: Automerge: Disabled by config. Please merge this manually once you are satisfied.
:recycle: Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
:no_bell: Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by WhiteSource Renovate. View repository job log here.
:tada: This PR is included in version 2.0.1 :tada:
The release is available on:
Your semantic-release bot :package::rocket:
This PR contains the following updates:
4.0.0
->4.0.1
GitHub Vulnerability Alerts
CVE-2020-7774
Overview
The npm package
y18n
before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution.POC
Recommendation
Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later.
Configuration
:date: Schedule: "" (UTC).
:vertical_traffic_light: Automerge: Disabled by config. Please merge this manually once you are satisfied.
:recycle: Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
:no_bell: Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by WhiteSource Renovate. View repository job log here.