Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency commonmarker to v0.23.10 [SECURITY] #27

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Apr 12, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
commonmarker 0.23.8 -> 0.23.10 age adoption passing confidence

GitHub Vulnerability Alerts

GHSA-48wp-p9qv-4j64

Impact

Several quadratic complexity bugs in commonmarker's underlying cmark-gfm library may lead to unbounded resource exhaustion and subsequent denial of service.

The following vulnerabilities were addressed:

For more information, consult the release notes for version 0.23.0.gfm.10 and 0.23.0.gfm.11.

Mitigation

Users are advised to upgrade to commonmarker version 0.23.9.

GHSA-7vh7-fw88-wj87

Impact

Several quadratic complexity bugs in commonmarker's underlying cmark-gfm library may lead to unbounded resource exhaustion and subsequent denial of service.

The following vulnerabilities were addressed:

For more information, consult the release notes for version 0.29.0.gfm.12.

Mitigation

Users are advised to upgrade to commonmarker version 0.23.10.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/rubygems-commonmarker-vulnerability branch from f429bf3 to 5ca917d Compare August 8, 2023 23:16
@renovate renovate bot changed the title Update dependency commonmarker to v0.23.9 [SECURITY] Update dependency commonmarker to v0.23.10 [SECURITY] Aug 8, 2023
@renovate renovate bot force-pushed the renovate/rubygems-commonmarker-vulnerability branch 3 times, most recently from f04c622 to a396d14 Compare August 17, 2023 01:21
@renovate renovate bot force-pushed the renovate/rubygems-commonmarker-vulnerability branch from a396d14 to 3de7994 Compare December 27, 2023 14:04
@renovate renovate bot changed the title Update dependency commonmarker to v0.23.10 [SECURITY] Update dependency commonmarker to v0.23.10 [SECURITY] - autoclosed Jul 24, 2024
@renovate renovate bot closed this Jul 24, 2024
@renovate renovate bot deleted the renovate/rubygems-commonmarker-vulnerability branch July 24, 2024 10:56
@renovate renovate bot changed the title Update dependency commonmarker to v0.23.10 [SECURITY] - autoclosed Update dependency commonmarker to v0.23.10 [SECURITY] Jul 28, 2024
@renovate renovate bot reopened this Jul 28, 2024
@renovate renovate bot restored the renovate/rubygems-commonmarker-vulnerability branch July 28, 2024 13:53
@renovate renovate bot force-pushed the renovate/rubygems-commonmarker-vulnerability branch from 3de7994 to 786e6f7 Compare July 28, 2024 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
0 participants