Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jun 23, 2023

This PR contains the following updates:

Package Change Age Confidence
semver 5.6.0 -> 5.7.2 age confidence

GitHub Vulnerability Alerts

CVE-2022-25883

Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.


Release Notes

npm/node-semver (semver)

v5.7.2

Compare Source

Bug Fixes

v5.7.1

Compare Source

v5.7.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

renovate-approve[bot]
renovate-approve bot previously approved these changes Jun 23, 2023
@CLAassistant
Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@renovate renovate bot changed the title Update dependency semver to v7 [SECURITY] Update dependency semver to v7 [SECURITY] - autoclosed Jul 10, 2023
@renovate renovate bot closed this Jul 10, 2023
@renovate renovate bot deleted the renovate/npm-semver-vulnerability branch July 10, 2023 22:32
@renovate renovate bot changed the title Update dependency semver to v7 [SECURITY] - autoclosed Update dependency semver to v7 [SECURITY] Jul 11, 2023
@renovate renovate bot restored the renovate/npm-semver-vulnerability branch July 11, 2023 22:13
@renovate renovate bot reopened this Jul 11, 2023
@renovate renovate bot changed the title Update dependency semver to v7 [SECURITY] Update dependency semver to v5.7.2 [SECURITY] Jul 11, 2023
@renovate renovate bot force-pushed the renovate/npm-semver-vulnerability branch from 7bab4e9 to 491c11d Compare July 11, 2023 22:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants