Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Dec 22, 2022

This PR contains the following updates:

Package Change Age Confidence
dustjs-linkedin (source) 2.7.5 -> 3.0.0 age confidence

GitHub Vulnerability Alerts

CVE-2021-4264

A vulnerability was found in LinkedIn dustjs prior to version 3.0.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.0 can address this issue. The name of the patch is ddb6523832465d38c9d80189e9de60519ac307c3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216464.


Release Notes

linkedin/dustjs (dustjs-linkedin)

v3.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@mikaello
Copy link
Owner

This update seems to work after manual testing, but it does break the peer requirement from dustjs-helper: warning " > dustjs-helpers@1.7.4" has incorrect peer dependency "dustjs-linkedin@2.7 - 2.8".

See also issue LinkedInAttic/dustjs-helpers#148

@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 144c800 to 5c0ad45 Compare December 26, 2022 01:31
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 3 times, most recently from dea562b to 635c158 Compare January 9, 2023 01:35
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 3 times, most recently from 9c4387c to a817663 Compare January 23, 2023 05:02
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 2 times, most recently from 4e0fd04 to 6e581e1 Compare February 6, 2023 00:10
@mikaello
Copy link
Owner

mikaello commented Feb 6, 2023

This cannot be merged because of:

This update seems to work after manual testing, but it does break the peer requirement from dustjs-helper: warning " > dustjs-helpers@1.7.4" has incorrect peer dependency "dustjs-linkedin@2.7 - 2.8".

See also issue LinkedInAttic/dustjs-helpers#148

Ref #35 (comment)

@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 6e581e1 to 7c98121 Compare February 6, 2023 05:56
@renovate renovate bot changed the title fix(deps): update dependency dustjs-linkedin to v3 [security] fix(deps): update dependency dustjs-linkedin to v3 [security] - autoclosed Feb 17, 2023
@renovate renovate bot closed this Feb 17, 2023
@renovate renovate bot deleted the renovate/npm-dustjs-linkedin-vulnerability branch February 17, 2023 03:17
@renovate renovate bot changed the title fix(deps): update dependency dustjs-linkedin to v3 [security] - autoclosed fix(deps): update dependency dustjs-linkedin to v3 [security] Feb 17, 2023
@renovate renovate bot reopened this Feb 17, 2023
@renovate renovate bot restored the renovate/npm-dustjs-linkedin-vulnerability branch February 17, 2023 07:58
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 7c98121 to 60d502c Compare February 20, 2023 00:54
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 2 times, most recently from 0c978fd to 5cbacda Compare March 13, 2023 01:54
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 5cbacda to 058b197 Compare March 13, 2023 15:32
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 058b197 to 8f1738b Compare March 30, 2023 21:55
@renovate renovate bot changed the title fix(deps): update dependency dustjs-linkedin to v3 [security] fix(deps): update dependency dustjs-linkedin to v3 [security] - autoclosed Apr 4, 2023
@renovate renovate bot closed this Apr 4, 2023
@renovate renovate bot deleted the renovate/npm-dustjs-linkedin-vulnerability branch April 4, 2023 01:39
@renovate renovate bot changed the title fix(deps): update dependency dustjs-linkedin to v3 [security] - autoclosed fix(deps): update dependency dustjs-linkedin to v3 [security] Apr 4, 2023
@renovate renovate bot reopened this Apr 4, 2023
@renovate renovate bot restored the renovate/npm-dustjs-linkedin-vulnerability branch April 4, 2023 08:54
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 79e5822 to d4ef613 Compare March 24, 2025 05:35
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from d4ef613 to 8488f2a Compare March 31, 2025 06:47
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 2 times, most recently from 906e1db to a092a86 Compare April 21, 2025 10:43
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from a092a86 to f6e3a21 Compare June 2, 2025 05:12
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 2 times, most recently from a047507 to 46e4160 Compare June 16, 2025 06:34
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 46e4160 to b202386 Compare June 23, 2025 05:35
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from b202386 to 1aaf773 Compare June 30, 2025 07:07
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 2 times, most recently from a005494 to da226d6 Compare July 14, 2025 05:53
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 3 times, most recently from 5c69a77 to 7be30a2 Compare July 28, 2025 05:36
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 2 times, most recently from 0368a68 to ee780f7 Compare August 11, 2025 05:33
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 3 times, most recently from cc9a18b to 3cfef65 Compare August 18, 2025 05:32
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 3cfef65 to 65e4a08 Compare August 25, 2025 04:51
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 65e4a08 to bf354cc Compare September 8, 2025 06:34
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 3 times, most recently from 9c3d087 to cabf624 Compare September 22, 2025 20:08
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch 2 times, most recently from a737e0c to 0c1344a Compare October 6, 2025 04:51
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from 0c1344a to d061ee7 Compare October 20, 2025 04:56
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from d061ee7 to c987be3 Compare November 3, 2025 05:15
@renovate renovate bot force-pushed the renovate/npm-dustjs-linkedin-vulnerability branch from c987be3 to 3625039 Compare November 7, 2025 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants