Skip to content

Update dependency pdfkit to v0.8.7.2 [SECURITY]#951

Merged
renovate[bot] merged 1 commit intomasterfrom
renovate/rubygems-pdfkit-vulnerability
Nov 3, 2022
Merged

Update dependency pdfkit to v0.8.7.2 [SECURITY]#951
renovate[bot] merged 1 commit intomasterfrom
renovate/rubygems-pdfkit-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 3, 2022

Mend Renovate

This PR contains the following updates:

Package Update Change
pdfkit patch 0.8.7 -> 0.8.7.2

GitHub Vulnerability Alerts

CVE-2022-25765

The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized.

Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Nov 3, 2022
@viezly
Copy link

viezly bot commented Nov 3, 2022

Pull request by bot. No need to analyze

@renovate renovate bot merged commit 788b317 into master Nov 3, 2022
@renovate renovate bot deleted the renovate/rubygems-pdfkit-vulnerability branch November 3, 2022 04:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants