Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency url-parse to v1.5.8 [security] #20386

Merged
merged 1 commit into from
Mar 1, 2022

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 28, 2022

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
url-parse 1.5.6 -> 1.5.8 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-0639

url-parse prior to version 1.5.7 is vulnerable to Authorization Bypass Through User-Controlled Key. Url-parse is not able to verify broken protocol. This will allow to bypass hostname validation.

CVE-2022-0686

url-parse prior to version 1.5.8 is vulnerable to Authorization Bypass Through User-Controlled Key.


Release Notes

unshiftio/url-parse

v1.5.8

Compare Source

v1.5.7

Compare Source


Configuration

📅 Schedule: "" in timezone America/New_York.

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot requested a review from a team as a code owner February 28, 2022 05:51
@renovate renovate bot added renovate Triggered by renovatebot type: dependencies labels Feb 28, 2022
@cypress-bot
Copy link
Contributor

cypress-bot bot commented Feb 28, 2022

See the guidelines for reviewing dependency updates for info on how to review dependency update PRs.

@renovate renovate bot requested review from jennifer-shehane and removed request for a team February 28, 2022 05:51
@cypress
Copy link

cypress bot commented Feb 28, 2022



Test summary

19278 0 218 0Flakiness 0


Run details

Project cypress
Status Passed
Commit 20b8660
Started Mar 1, 2022 5:18 PM
Ended Mar 1, 2022 5:30 PM
Duration 11:34 💡
OS Linux Debian - 10.10
Browser Multiple

View run in Cypress Dashboard ➡️


This comment has been generated by cypress-bot as a result of this project's GitHub integration settings. You can manage this integration in this project's settings in the Cypress Dashboard

emilyrohrbough
emilyrohrbough previously approved these changes Feb 28, 2022
@renovate renovate bot force-pushed the renovate/npm-url-parse-vulnerability branch 3 times, most recently from 2188619 to 067140d Compare March 1, 2022 14:36
@renovate renovate bot force-pushed the renovate/npm-url-parse-vulnerability branch from 067140d to 20b8660 Compare March 1, 2022 17:13
@renovate renovate bot merged commit 47ee6e2 into develop Mar 1, 2022
@renovate renovate bot deleted the renovate/npm-url-parse-vulnerability branch March 1, 2022 21:48
@cypress-bot
Copy link
Contributor

cypress-bot bot commented Mar 14, 2022

Released in 9.5.2.

This comment thread has been locked. If you are still experiencing this issue after upgrading to
Cypress v9.5.2, please open a new issue.

@cypress-bot cypress-bot bot locked as resolved and limited conversation to collaborators Mar 14, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
renovate Triggered by renovatebot type: dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants