Skip to content

chore(deps): update dependency webpack to 5.76.0 [security] - autoclosed#1975

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-webpack-vulnerability
Closed

chore(deps): update dependency webpack to 5.76.0 [security] - autoclosed#1975
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-webpack-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Mar 14, 2023

Mend Renovate

This PR contains the following updates:

Package Change
webpack 5.75.0 -> 5.76.0

GitHub Vulnerability Alerts

CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@tumainimosha
Copy link
Copy Markdown

Any ETA for this update in the package?

@renovate renovate Bot changed the title chore(deps): update dependency webpack to 5.76.0 [security] chore(deps): update dependency webpack to 5.76.0 [security] - autoclosed Mar 17, 2023
@renovate renovate Bot closed this Mar 17, 2023
@renovate renovate Bot deleted the renovate/npm-webpack-vulnerability branch March 17, 2023 11:49
@dqiubread
Copy link
Copy Markdown

I see that this PR is closed, did this change every get fixed as part of another PR?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants