Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency sidekiq to v6.5.10 [security] #397

Merged
merged 1 commit into from
Oct 25, 2024

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 14, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
sidekiq (source, changelog) 6.5.8 -> 6.5.10 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-26141

Versions of the package sidekiq before 7.1.3 and 6.5.10 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.


Release Notes

sidekiq/sidekiq (sidekiq)

v6.5.10

Compare Source

v6.5.9

Compare Source

  • Ensure Sidekiq.options[:environment] == RAILS_ENV [#​5932]

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Amsterdam, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Sep 14, 2023
@renovate renovate bot changed the title chore(deps): update dependency sidekiq to v7 [security] chore(deps): update dependency sidekiq to v6.5.10 [security] Oct 5, 2023
@renovate renovate bot force-pushed the renovate/rubygems-sidekiq-vulnerability branch from 8f24a6e to 11f1de5 Compare October 5, 2023 14:05
@renovate renovate bot force-pushed the renovate/rubygems-sidekiq-vulnerability branch from 11f1de5 to a670096 Compare November 16, 2023 12:43
@renovate renovate bot force-pushed the renovate/rubygems-sidekiq-vulnerability branch from a670096 to 98b4c83 Compare February 4, 2024 11:11
@renovate renovate bot changed the title chore(deps): update dependency sidekiq to v6.5.10 [security] chore(deps): update dependency sidekiq to v6.5.10 [security] - autoclosed Feb 24, 2024
@renovate renovate bot closed this Feb 24, 2024
@renovate renovate bot deleted the renovate/rubygems-sidekiq-vulnerability branch February 24, 2024 03:12
@renovate renovate bot changed the title chore(deps): update dependency sidekiq to v6.5.10 [security] - autoclosed chore(deps): update dependency sidekiq to v6.5.10 [security] Feb 24, 2024
@renovate renovate bot reopened this Feb 24, 2024
@renovate renovate bot restored the renovate/rubygems-sidekiq-vulnerability branch February 24, 2024 08:09
@renovate renovate bot force-pushed the renovate/rubygems-sidekiq-vulnerability branch from 98b4c83 to df9a07e Compare February 24, 2024 08:09
@renovate renovate bot force-pushed the renovate/rubygems-sidekiq-vulnerability branch from df9a07e to 0aa673d Compare March 24, 2024 15:20
@renovate renovate bot force-pushed the renovate/rubygems-sidekiq-vulnerability branch from 0aa673d to 83b1fb3 Compare October 23, 2024 21:18
@lodewiges lodewiges added this pull request to the merge queue Oct 25, 2024
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to a conflict with the base branch Oct 25, 2024
@renovate renovate bot force-pushed the renovate/rubygems-sidekiq-vulnerability branch from 83b1fb3 to 3530ca8 Compare October 25, 2024 09:22
@lodewiges lodewiges added this pull request to the merge queue Oct 25, 2024
Merged via the queue into staging with commit 6ae5487 Oct 25, 2024
3 checks passed
@lodewiges lodewiges deleted the renovate/rubygems-sidekiq-vulnerability branch October 25, 2024 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file status:ready to merge
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant