Skip to content
This repository has been archived by the owner on Mar 5, 2023. It is now read-only.

Update dependency mem to 4.0.0 [SECURITY] #104

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 4, 2022

Mend Renovate

This PR contains the following updates:

Package Change
mem 1.1.0 -> 4.0.0

GitHub Vulnerability Alerts

GHSA-4xcv-9jjx-gfj3

Versions of mem prior to 4.0.0 are vulnerable to Denial of Service (DoS). The package fails to remove old values from the cache even after a value passes its maxAge property. This may allow attackers to exhaust the system's memory if they are able to abuse the application logging.

Recommendation

Upgrade to version 4.0.0 or later.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-mem-vulnerability branch 9 times, most recently from 2974ed6 to ec890a9 Compare March 9, 2022 17:14
@renovate renovate bot force-pushed the renovate/npm-mem-vulnerability branch from ec890a9 to 46ed1ac Compare March 13, 2022 06:04
@renovate renovate bot force-pushed the renovate/npm-mem-vulnerability branch 4 times, most recently from 75737e0 to 44bc2a1 Compare March 30, 2022 16:15
@renovate renovate bot force-pushed the renovate/npm-mem-vulnerability branch from 44bc2a1 to ad8db9f Compare May 2, 2022 15:44
@renovate renovate bot force-pushed the renovate/npm-mem-vulnerability branch from ad8db9f to 286cb0c Compare May 24, 2022 07:19
@renovate renovate bot changed the title Update dependency mem to 4.0.0 [SECURITY] Update dependency mem to 4.0.0 [SECURITY] - autoclosed Aug 22, 2022
@renovate renovate bot closed this Aug 22, 2022
@renovate renovate bot deleted the renovate/npm-mem-vulnerability branch August 22, 2022 21:07
@renovate renovate bot changed the title Update dependency mem to 4.0.0 [SECURITY] - autoclosed Update dependency mem to 4.0.0 [SECURITY] Aug 23, 2022
@renovate renovate bot reopened this Aug 23, 2022
@renovate renovate bot restored the renovate/npm-mem-vulnerability branch August 23, 2022 00:43
@renovate renovate bot force-pushed the renovate/npm-mem-vulnerability branch 4 times, most recently from bf44505 to 186e9c8 Compare October 1, 2022 21:56
@renovate renovate bot force-pushed the renovate/npm-mem-vulnerability branch 2 times, most recently from 3f3c03a to 0238aa7 Compare November 16, 2022 20:25
@renovate renovate bot force-pushed the renovate/npm-mem-vulnerability branch from 0238aa7 to 28ce4e4 Compare March 5, 2023 08:00
@renovate renovate bot force-pushed the renovate/npm-mem-vulnerability branch from 28ce4e4 to 1fcdfbd Compare March 5, 2023 08:50
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants