-
Notifications
You must be signed in to change notification settings - Fork 3
fix(deps): update dependency dustjs-linkedin to v3 [security] #100
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
This update seems to work after manual testing, but it does break the peer requirement from dustjs-helper: See also issue LinkedInAttic/dustjs-helpers#148 |
144c800 to
5c0ad45
Compare
dea562b to
635c158
Compare
9c4387c to
a817663
Compare
4e0fd04 to
6e581e1
Compare
|
This cannot be merged because of:
Ref #35 (comment) |
6e581e1 to
7c98121
Compare
7c98121 to
60d502c
Compare
0c978fd to
5cbacda
Compare
5cbacda to
058b197
Compare
058b197 to
8f1738b
Compare
79e5822 to
d4ef613
Compare
d4ef613 to
8488f2a
Compare
906e1db to
a092a86
Compare
a092a86 to
f6e3a21
Compare
a047507 to
46e4160
Compare
46e4160 to
b202386
Compare
b202386 to
1aaf773
Compare
a005494 to
da226d6
Compare
5c69a77 to
7be30a2
Compare
0368a68 to
ee780f7
Compare
cc9a18b to
3cfef65
Compare
3cfef65 to
65e4a08
Compare
65e4a08 to
bf354cc
Compare
9c3d087 to
cabf624
Compare
a737e0c to
0c1344a
Compare
0c1344a to
d061ee7
Compare
d061ee7 to
c987be3
Compare
c987be3 to
3625039
Compare
This PR contains the following updates:
2.7.5->3.0.0GitHub Vulnerability Alerts
CVE-2021-4264
A vulnerability was found in LinkedIn dustjs prior to version 3.0.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.0 can address this issue. The name of the patch is ddb6523832465d38c9d80189e9de60519ac307c3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216464.
Release Notes
linkedin/dustjs (dustjs-linkedin)
v3.0.0Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.