Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): [security] bump node-fetch from 2.6.0 to 2.6.1 #319

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot-preview[bot]
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Sep 11, 2020

Bumps node-fetch from 2.6.0 to 2.6.1. This update includes a security fix.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

The size option isn't honored after following a redirect in node-fetch

Impact

Node Fetch did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure.

For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.

Patches

We released patched versions for both stable and beta channels:

  • For v2: 2.6.1
  • For v3: 3.0.0-beta.9

Workarounds

None, it is strongly recommended to update as soon as possible.

For more information

If you have any questions or comments about this advisory:

Affected versions: < 2.6.1

Release notes

Sourced from node-fetch's releases.

v2.6.1

This is an important security release. It is strongly recommended to update as soon as possible.

See CHANGELOG for details.

Changelog

Sourced from node-fetch's changelog.

v2.6.1

This is an important security release. It is strongly recommended to update as soon as possible.

  • Fix: honor the size option after following a redirect.
Commits
  • b5e2e41 update version number
  • 2358a6c Honor the size option after following a redirect and revert data uri support
  • 8c197f8 docs: Fix typos and grammatical errors in README.md (#686)
  • 1e99050 fix: Change error message thrown with redirect mode set to error (#653)
  • 244e6f6 docs: Show backers in README
  • 6a5d192 fix: Properly parse meta tag when parameters are reversed (#682)
  • 47a24a0 chore: Add opencollective badge
  • 7b13662 chore: Add funding link
  • 5535c2e fix: Check for global.fetch before binding it (#674)
  • 1d5778a docs: Add Discord badge
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by akepinski, a new releaser for node-fetch since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot will not automatically merge this PR because it includes a security patch update to a production dependency.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Sep 11, 2020
@coveralls
Copy link

coveralls commented Sep 11, 2020

Pull Request Test Coverage Report for Build 1979

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 100.0%

Totals Coverage Status
Change from base Build 1977: 0.0%
Covered Lines: 8
Relevant Lines: 8

💛 - Coveralls

@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 6 times, most recently from cebeb2a to 44c6d69 Compare September 17, 2020 17:12
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 3 times, most recently from f33a072 to 7cdf26e Compare September 22, 2020 17:01
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 2 times, most recently from 2455024 to 6198915 Compare September 25, 2020 18:49
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 4 times, most recently from 736ea30 to 768a08d Compare October 13, 2020 17:01
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 4 times, most recently from 71ec855 to 822d606 Compare October 22, 2020 06:16
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 3 times, most recently from f58bb23 to aa36da0 Compare October 30, 2020 20:38
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch from aa36da0 to 397b581 Compare November 10, 2020 18:01
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 4 times, most recently from 910f754 to 931c83f Compare November 20, 2020 18:01
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 4 times, most recently from 356fab7 to afbc0fb Compare November 26, 2020 18:01
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 4 times, most recently from 91cffae to 325fc49 Compare December 3, 2020 18:07
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 7 times, most recently from 67945f2 to 715ce44 Compare December 14, 2020 18:01
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch from 715ce44 to 53263e6 Compare December 16, 2020 18:01
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 3 times, most recently from dc11cb5 to 5d51ca8 Compare December 31, 2020 18:01
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch 2 times, most recently from 3a54be0 to e2c33c5 Compare January 5, 2021 18:01
Bumps [node-fetch](https://github.com/bitinn/node-fetch) from 2.6.0 to 2.6.1. **This update includes a security fix.**
- [Release notes](https://github.com/bitinn/node-fetch/releases)
- [Changelog](https://github.com/node-fetch/node-fetch/blob/master/docs/CHANGELOG.md)
- [Commits](node-fetch/node-fetch@v2.6.0...v2.6.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/node-fetch-2.6.1 branch from e2c33c5 to 150bac3 Compare January 7, 2021 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant