Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency semver to ~7.5.2 [security] #58

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Aug 3, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
semver ~7.3.0 -> ~7.5.2 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-25883

Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.


Release Notes

npm/node-semver (semver)

v7.5.2

Compare Source

Bug Fixes

v7.5.1

Compare Source

Bug Fixes

v7.5.0

Compare Source

Features
Bug Fixes

v7.4.0

Compare Source

Features
Bug Fixes
Documentation

v7.3.8

Compare Source

Bug Fixes
Documentation
7.3.7 (2022-04-11)
Bug Fixes
Dependencies
7.3.6 (2022-04-05)
Bug Fixes
Documentation
  • clarify * range behavior (cb1ca1d)
Dependencies

v7.3.7

Compare Source

v7.3.6

Compare Source

v7.3.5

Compare Source

v7.3.4

Compare Source

v7.3.3

Compare Source

v7.3.2

Compare Source

v7.3.1

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate-bot renovate-bot requested a review from a team August 3, 2023 06:58
@renovate-bot renovate-bot requested a review from a team as a code owner August 3, 2023 06:58
@trusted-contributions-gcf trusted-contributions-gcf bot added the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Aug 3, 2023
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.5.0 [security] Aug 9, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 7e5d7ea to e947492 Compare August 9, 2023 13:47
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Aug 9, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from e947492 to c790f22 Compare August 9, 2023 18:13
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from c790f22 to 7050dcf Compare August 22, 2023 18:52
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.5.0 [security] Aug 22, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 7050dcf to 385377d Compare August 22, 2023 23:26
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Aug 22, 2023
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.5.0 [security] Aug 27, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch 2 times, most recently from 16f5c5b to 6aae597 Compare August 27, 2023 14:51
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Aug 27, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 6aae597 to 988abe9 Compare September 19, 2023 15:12
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.5.0 [security] Sep 19, 2023
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Sep 19, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 988abe9 to 1072856 Compare September 19, 2023 18:33
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.5.0 [security] Oct 1, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch 2 times, most recently from c7cae88 to 47e7961 Compare October 1, 2023 09:31
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Oct 1, 2023
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.5.0 [security] Oct 9, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 47e7961 to 9a37224 Compare October 9, 2023 10:16
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Oct 9, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 9a37224 to 013f87f Compare October 9, 2023 12:59
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.5.0 [security] Oct 15, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 013f87f to b5fc236 Compare October 15, 2023 09:22
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Oct 15, 2023
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from f2fb051 to 42b7b78 Compare March 24, 2024 17:40
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.6.0 [security] Apr 1, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch 2 times, most recently from fc01a95 to 1168e97 Compare April 1, 2024 21:29
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.6.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Apr 1, 2024
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.6.0 [security] Apr 14, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 1168e97 to c47a1f5 Compare April 14, 2024 09:40
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.6.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Apr 14, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch 2 times, most recently from 76a0a36 to a3d110e Compare April 21, 2024 08:48
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.6.0 [security] Apr 21, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from a3d110e to c61a1e2 Compare April 21, 2024 09:11
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.6.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Apr 21, 2024
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.6.0 [security] Apr 25, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from c61a1e2 to e1a350f Compare April 25, 2024 07:19
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.6.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] Apr 25, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from e1a350f to 5bbdd44 Compare April 25, 2024 09:40
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.6.0 [security] May 1, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch 2 times, most recently from b0077ab to 15fa984 Compare May 1, 2024 13:43
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.6.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] May 1, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 15fa984 to 30f6eed Compare May 9, 2024 08:39
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.6.0 [security] May 9, 2024
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.6.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] May 9, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch 2 times, most recently from 13aca6e to 8f46063 Compare May 15, 2024 17:26
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.5.2 [security] fix(deps): update dependency semver to ~7.6.0 [security] May 15, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-semver-vulnerability branch from 8f46063 to f562b74 Compare May 15, 2024 23:48
@renovate-bot renovate-bot changed the title fix(deps): update dependency semver to ~7.6.0 [security] fix(deps): update dependency semver to ~7.5.2 [security] May 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kokoro:force-run Add this label to force Kokoro to re-run the tests.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant