Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency flat to v5 [SECURITY] #1063

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Jan 23, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
flat ^4.0.0 -> ^5.0.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2020-36632

flat helps flatten/unflatten nested Javascript objects. A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible to initiate the attack remotely. Upgrading to version 5.0.1 can address this issue. The name of the patch is 20ef0ef55dfa028caddaedbcb33efbdb04d18e13. It is recommended to upgrade the affected component. The identifier VDB-216777 was assigned to this vulnerability.


Release Notes

hughsk/flat (flat)

v5.0.1

Compare Source

v5.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/London, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner January 23, 2023 13:50
@renovate renovate bot added the dependencies Pull requests that update a dependency file label Jan 23, 2023
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from be14d0e to f7c4bc4 Compare February 7, 2023 15:04
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from f7c4bc4 to d3a6d8f Compare February 28, 2023 13:23
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from d3a6d8f to 3ba333d Compare February 28, 2023 18:07
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from 3ba333d to 010ba8c Compare May 25, 2023 11:09
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from 010ba8c to dc0ff44 Compare May 25, 2023 14:53
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from dc0ff44 to 60200f4 Compare May 25, 2023 18:15
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from 60200f4 to 9c018c0 Compare May 25, 2023 23:05
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from 9c018c0 to f466c92 Compare May 31, 2023 07:48
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from f466c92 to 3f1f6c0 Compare June 1, 2023 13:58
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from 3f1f6c0 to 85df463 Compare June 2, 2023 13:02
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from 85df463 to e3e6158 Compare June 21, 2023 16:16
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from e3e6158 to fb26973 Compare June 22, 2023 09:56
@renovate renovate bot force-pushed the renovate/npm-flat-vulnerability branch from b0ba84a to fc289ab Compare February 13, 2024 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file ns:divorce prd:div rel:div-pfe-pr-1063
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants