Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 26, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Type Update Change
json devDependencies pin ^9.0.4 -> 9.0.6

GitHub Vulnerability Alerts

CVE-2020-7712

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

📌 Important: Renovate will wait until you have merged this Pin PR before creating any upgrade PRs for the affected packages. Add the preset :preserveSemverRanges to your config if you instead don't wish to pin dependencies.


Configuration

📅 Schedule: "" in timezone America/New_York.

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot added the security Pull requests that address a security vulnerability label Jul 26, 2021
@renovate renovate bot force-pushed the renovate/npm-json-vulnerability branch from 18012ae to 6555875 Compare July 26, 2021 23:13
@renovate renovate bot changed the title chore(deps): pin dependency json to v9.0.6 [security] chore(deps): update dependency json to v10 [security] Jul 26, 2021
@renovate renovate bot force-pushed the renovate/npm-json-vulnerability branch from 6555875 to 4369cec Compare July 26, 2021 23:19
@renovate renovate bot changed the title chore(deps): update dependency json to v10 [security] chore(deps): pin dependency json to v9.0.6 [security] Jul 26, 2021
@renovate renovate bot force-pushed the renovate/npm-json-vulnerability branch from 4369cec to 41d14be Compare July 26, 2021 23:32
@renovate renovate bot force-pushed the renovate/npm-json-vulnerability branch from 41d14be to bb7229d Compare July 26, 2021 23:34
@cwillisf cwillisf added the dependencies Pull requests that update a dependency file label Jul 26, 2021
@cwillisf cwillisf merged commit bce6246 into develop Jul 26, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants