Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency cached-path-relative to v1.1.0 [SECURITY] #953

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jan 27, 2022

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
cached-path-relative 1.0.2 -> 1.1.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-23518

The package cached-path-relative before 1.1.0 is vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as proto, the attribute of the object is accessed instead of a path. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573


Release Notes

ashaffer/cached-path-relative (cached-path-relative)

v1.1.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from 85b88a9 to 73942c0 Compare March 7, 2022 14:59
@renovate renovate bot changed the title Update dependency cached-path-relative to v1.1.0 [SECURITY] Update dependency cached-path-relative to v1.1.0 [SECURITY] - autoclosed Mar 11, 2022
@renovate renovate bot closed this Mar 11, 2022
@renovate renovate bot deleted the renovate/npm-cached-path-relative-vulnerability branch March 11, 2022 23:21
@renovate renovate bot changed the title Update dependency cached-path-relative to v1.1.0 [SECURITY] - autoclosed Update dependency cached-path-relative to v1.1.0 [SECURITY] Mar 15, 2022
@renovate renovate bot reopened this Mar 15, 2022
@renovate renovate bot restored the renovate/npm-cached-path-relative-vulnerability branch March 15, 2022 19:32
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from 73942c0 to cad0943 Compare March 15, 2022 21:41
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch 3 times, most recently from d4aff29 to 87b8dc4 Compare April 8, 2022 18:07
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from 87b8dc4 to 68afbf5 Compare May 6, 2022 23:33
@CLAassistant
Copy link

CLAassistant commented May 11, 2022

CLA assistant check
All committers have signed the CLA.

@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from 68afbf5 to d314e88 Compare May 12, 2022 15:22
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from d314e88 to 548fe5f Compare September 25, 2022 18:16
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch 4 times, most recently from a0c7f0a to 296f7ac Compare October 10, 2022 20:50
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from 296f7ac to d54d45e Compare October 13, 2022 19:36
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from d54d45e to 52a5f4a Compare October 21, 2022 15:46
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from 52a5f4a to 70f0ad7 Compare November 28, 2022 21:39
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch 3 times, most recently from 00e21ec to 138cebe Compare October 22, 2023 21:09
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from 138cebe to 34412af Compare October 30, 2023 14:58
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from 34412af to 5e924e3 Compare November 23, 2023 17:59
@renovate renovate bot force-pushed the renovate/npm-cached-path-relative-vulnerability branch from 5e924e3 to 5b9d746 Compare October 24, 2024 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants