fix(deps): update dependency debug to v4.3.1 [security] #226
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.0.0->4.3.1Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
GitHub Vulnerability Alerts
CVE-2017-16137
Affected versions of
debugare vulnerable to regular expression denial of service when untrusted user input is passed into theoformatter.As it takes 50,000 characters to block the event loop for 2 seconds, this issue is a low severity issue.
This was later re-introduced in version v3.2.0, and then repatched in versions 3.2.7 and 4.3.1.
Recommendation
Version 2.x.x: Update to version 2.6.9 or later.
Version 3.1.x: Update to version 3.1.0 or later.
Version 3.2.x: Update to version 3.2.7 or later.
Version 4.x.x: Update to version 4.3.1 or later.
Release Notes
debug-js/debug (debug)
v4.3.1Compare Source
Patch release 4.3.1
v4.3.0Compare Source
Minor release
debugInstance.destroy(). Future major versions will not have this method; please remove it from your codebases as it currently does nothing.v4.2.0Compare Source
Minor Release
console.debugin the browser only when it is available (#600)"engines"key to package.jsonselectColor(#747)supports-coloras an optional peer dependencyv4.1.1Compare Source
This backport fixes a bug in coveralls configuration as well as the
.extend()function.Patches
d0e498f)57ef085)v4.1.0Compare Source
Minor Changes
4236585)7ef8b41)Massive thank you to @mblarsen and @outsideris for knocking out two long-awaited changes.
v4.0.1Compare Source
This patch restores browserify functionality as well as keeping the intended functionality with Unpkg.com.
Patches
99c95e3Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.