Skip to content
This repository was archived by the owner on May 5, 2023. It is now read-only.

chore(deps): update dependency qs to 6.5.3 [security]#414

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/npm-qs-vulnerability
Dec 6, 2022
Merged

chore(deps): update dependency qs to 6.5.3 [security]#414
renovate[bot] merged 1 commit into
masterfrom
renovate/npm-qs-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Dec 6, 2022

Copy link
Copy Markdown
Contributor

Mend Renovate

This PR contains the following updates:

Package Change
qs 6.5.1 -> 6.5.3

GitHub Vulnerability Alerts

CVE-2022-24999

qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[proto]=b&a[proto]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: qs@6.9.7" in its release description, is not vulnerable).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate

renovate Bot commented Dec 6, 2022

Copy link
Copy Markdown
Contributor Author

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate renovate Bot merged commit 846745a into master Dec 6, 2022
@renovate renovate Bot deleted the renovate/npm-qs-vulnerability branch December 6, 2022 20:25
@HT2Bot

HT2Bot commented Feb 27, 2023

Copy link
Copy Markdown
Member

🎉 This PR is included in version 3.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant