Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency hosted-git-info to 2.8.9 [SECURITY] #17

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented May 9, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change
hosted-git-info 2.8.8 -> 2.8.9

GitHub Vulnerability Alerts

CVE-2021-23362

The npm package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot assigned bduff9 May 9, 2021
@vercel
Copy link

vercel bot commented May 9, 2021

This pull request is being automatically deployed with Vercel (learn more).
To see the status of your deployment, click below or on the icon next to each commit.

🔍 Inspect: https://vercel.com/bduff9/nfl-pool-fe/22XM7QcJ9CBnJhVqmogoV51c6MRh
✅ Preview: https://nfl-pool-fe-git-renovate-npm-hosted-git-info-vulnerab-50dbee.vercel.app

@coveralls
Copy link

coveralls commented May 9, 2021

Pull Request Test Coverage Report for Build 829870033

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 28.392%

Totals Coverage Status
Change from base Build 829764384: 0.0%
Covered Lines: 108
Relevant Lines: 227

💛 - Coveralls

@cypress
Copy link

cypress bot commented May 9, 2021



Test summary

10 1 0 0


Run details

Project nfl-pool-fe
Status Failed
Commit 78a2054
Started May 11, 2021 12:40 AM
Ended May 11, 2021 12:41 AM
Duration 00:57 💡
OS Linux Ubuntu - 20.04
Browser Electron 89

View run in Cypress Dashboard ➡️

Failures are unavailable for this run. For more information, see the Cypress Dashboard


This comment has been generated by cypress-bot as a result of this project's GitHub integration settings. You can manage this integration in this project's settings in the Cypress Dashboard

@renovate
Copy link
Author

renovate bot commented Aug 5, 2021

Renovate Ignore Notification

As this PR has been closed unmerged, Renovate will now ignore this update (2.8.9). You will still receive a PR once a newer version is released, so if you wish to permanently ignore this dependency, please add it to the ignoreDeps array of your renovate config.

If this PR was closed by mistake or you changed your mind, you can simply rename this PR and you will soon get a fresh replacement PR opened.

@renovate renovate bot deleted the renovate/npm-hosted-git-info-vulnerability branch August 5, 2021 23:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants