Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency https-proxy-agent to version .x 🌟 #4242

Merged
merged 2 commits into from
Jul 10, 2019

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 19, 2019

This PR contains the following updates:

Package Type Update Change
https-proxy-agent devDependencies major 1.0.0 -> 2.2.0

GitHub Vulnerability Alerts

CVE-2018-3736

https-proxy-agent passes unsanitized options to Buffer(arg) resulting in DoS and uninitialized memory leak.

GHSA-qrg3-f6h6-vq8q / WS-2018-0072

Versions of https-proxy-agent before 2.2.0 are vulnerable to a denial of service. This is due to unsanitized options (proxy.auth) being passed to Buffer().


Release Notes

TooTallNate/node-https-proxy-agent

v2.2.0

Compare Source

==================

  • Add "engines" to package.json - requires Node.js >= 4.5.0
  • Use Buffer.from()

Renovate configuration

📅 Schedule: "" in timezone America/New_York.

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or if you modify the PR title to begin with "rebase!".

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot. View repository job log here.

@renovate renovate bot added renovate Triggered by renovatebot type: dependencies labels May 19, 2019
@jennifer-shehane jennifer-shehane self-requested a review May 20, 2019 04:18
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch 2 times, most recently from adf1685 to 9d249bc Compare May 21, 2019 04:18
@renovate renovate bot changed the title chore(deps): Update dependency https-proxy-agent to version .x 🌟 chore(deps): update dependency https-proxy-agent to version .x 🌟 May 21, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch 2 times, most recently from 213289e to 3d7c596 Compare May 21, 2019 15:10
@renovate renovate bot changed the title chore(deps): update dependency https-proxy-agent to version .x 🌟 chore(deps): Update dependency https-proxy-agent to version .x 🌟 May 21, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch 9 times, most recently from ee90b94 to b8eb752 Compare May 24, 2019 15:56
@renovate renovate bot changed the title chore(deps): Update dependency https-proxy-agent to version .x 🌟 chore(deps): update dependency https-proxy-agent to version .x 🌟 May 24, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch from b8eb752 to dd9800e Compare May 24, 2019 17:09
@renovate renovate bot changed the title chore(deps): update dependency https-proxy-agent to version .x 🌟 chore(deps): Update dependency https-proxy-agent to version .x 🌟 May 24, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch 2 times, most recently from 79bba36 to 8ca539a Compare May 29, 2019 08:18
@renovate renovate bot changed the title chore(deps): Update dependency https-proxy-agent to version .x 🌟 chore(deps): update dependency https-proxy-agent to version .x 🌟 May 29, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch 2 times, most recently from c33a99f to 393fd95 Compare May 29, 2019 09:23
@renovate renovate bot changed the title chore(deps): update dependency https-proxy-agent to version .x 🌟 chore(deps): update dependency https-proxy-agent to version .x 🌟 Jun 1, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch 2 times, most recently from d2ceb2c to 4dd175d Compare June 3, 2019 08:14
@renovate renovate bot changed the title chore(deps): update dependency https-proxy-agent to version .x 🌟 chore(deps): update dependency https-proxy-agent to version .x 🌟 Jun 3, 2019
@renovate renovate bot changed the title chore(deps): update dependency https-proxy-agent to version .x 🌟 chore(deps): Update dependency https-proxy-agent to version .x 🌟 Jul 2, 2019
@renovate renovate bot changed the title chore(deps): Update dependency https-proxy-agent to version .x 🌟 chore(deps): Update dependency https-proxy-agent to version .x 🌟 Jul 3, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch from e51786d to 4c77e19 Compare July 3, 2019 05:14
@renovate renovate bot changed the title chore(deps): Update dependency https-proxy-agent to version .x 🌟 chore(deps): update dependency https-proxy-agent to version .x 🌟 Jul 3, 2019
@renovate renovate bot changed the title chore(deps): update dependency https-proxy-agent to version .x 🌟 chore(deps): update dependency https-proxy-agent to version .x 🌟 Jul 3, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch 2 times, most recently from a576c03 to 150cfaa Compare July 3, 2019 13:16
@renovate renovate bot changed the title chore(deps): update dependency https-proxy-agent to version .x 🌟 chore(deps): Update dependency https-proxy-agent to version .x 🌟 Jul 3, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch from 150cfaa to 068c90d Compare July 3, 2019 14:21
@renovate renovate bot changed the title chore(deps): Update dependency https-proxy-agent to version .x 🌟 chore(deps): Update dependency https-proxy-agent to version .x 🌟 Jul 3, 2019
@renovate renovate bot changed the title chore(deps): Update dependency https-proxy-agent to version .x 🌟 chore(deps): Update dependency https-proxy-agent to version .x 🌟 Jul 8, 2019
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch 3 times, most recently from fc050bc to 0bfa7c8 Compare July 9, 2019 08:14
@renovate renovate bot force-pushed the renovate/npm-https-proxy-agent-vulnerability branch from 0bfa7c8 to 45ff8ba Compare July 9, 2019 14:12
@renovate renovate bot changed the title chore(deps): Update dependency https-proxy-agent to version .x 🌟 chore(deps): update dependency https-proxy-agent to version .x 🌟 Jul 10, 2019
Copy link
Member

@jennifer-shehane jennifer-shehane left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Requires node v4+, which is ok in server package 👍
  • new Buffer() is deprecated and unsafe. Need to use Buffer.from(), which I don't see in use anywhere.

@jennifer-shehane jennifer-shehane requested a review from flotwig July 10, 2019 04:49
@jennifer-shehane
Copy link
Member

jennifer-shehane commented Jul 10, 2019

@flotwig Can you take a look at this? This appears to be consistently failing in a test that is using the https-proxy-agent with a certificate error. I do see a couple of certificate issues open in their repo - but these have been opened long before this release, so I'm not sure why this update exhibits a change. Commit diff: https://github.com/TooTallNate/node-https-proxy-agent/compare/1.0.0...2.2.0

@flotwig
Copy link
Contributor

flotwig commented Jul 10, 2019

Looks like with this update rejectUnauthorized: false becomes required for self-signed certs to work. Updated tests to use rejectUnauthorized: false and now tests should pass

@renovate
Copy link
Contributor Author

renovate bot commented Jul 10, 2019

PR has been edited

👷 This PR has received other commits, so Renovate will stop updating it to avoid conflicts or other problems. If you wish to abandon your changes and have Renovate start over you may click the "rebase" checkbox in the PR body/description.

@flotwig flotwig merged commit b86e35c into develop Jul 10, 2019
@renovate renovate bot deleted the renovate/npm-https-proxy-agent-vulnerability branch July 10, 2019 16:14
@jennifer-shehane jennifer-shehane restored the renovate/npm-https-proxy-agent-vulnerability branch July 23, 2019 16:58
@renovate renovate bot deleted the renovate/npm-https-proxy-agent-vulnerability branch July 23, 2019 17:02
@cypress-bot
Copy link
Contributor

cypress-bot bot commented Jul 29, 2019

Released in 3.4.1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
renovate Triggered by renovatebot type: dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants