lingo.dev@0.138.1
·
20 commits
to main
since this release
Patch Changes
-
#2164
79b1c8fThanks @ohmoses! - Added dependency overrides to patch vulnerabilities:- picomatch@>=4 <4.0.4: 4.0.4
- qs@>=6.14.0 <6.14.1: 6.14.1
- "@unhead/vue": ">=2.1.15 <3"
- postcss@>=8 <8.5.10: 8.5.10
- ajv@>=6 <6.14.0: 6.14.0
- launch-editor@<2.14.1: 2.14.1
- js-yaml@>=3 <3.15.0: 3.15.0
- js-yaml@>=4 <4.2.0: 4.2.0
- joi@>=18 <18.2.1: 18.2.1
-
#2166
045642bThanks @cherkanovart! - Resolve high-severity CodeQL code-scanning findings (security hardening):org-idgit-remote parsing now extracts the URL host and matches the platform by exact host or subdomain suffix (host === "github.com" || host.endsWith(".github.com"), etc.) instead of a substringincludes()check. This fixesjs/incomplete-url-substring-sanitization(cli, compiler, new-compiler) while still recognizing official alt-SSH hosts likessh.github.com/altssh.gitlab.comand rejecting look-alikes likegithub.com.evil.com. Platform labels for all real remote forms are preserved.- Removed a dead
.replace("\n", "")in the XML loader (an earlier\s+collapse already strips newlines), which also clears thejs/incomplete-sanitizationfinding there.
-
#2165
aefeb08Thanks @ohmoses! - Overriden the qs dependency to patch a vulnerability -
Updated dependencies [
79b1c8f]:- @lingo.dev/_sdk@0.17.2
- @lingo.dev/_locales@0.3.4
- @lingo.dev/_spec@0.49.3