-
Notifications
You must be signed in to change notification settings - Fork 14
fix(deps): update dependency underscore to ~1.12.0 [security] #358
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-underscore-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
f51adf5 to
b277634
Compare
f83832f to
dd4835e
Compare
dd4835e to
c36893b
Compare
c36893b to
d2bec8a
Compare
d9be4f0 to
00c56ae
Compare
9501556 to
d30518e
Compare
4400898 to
8538593
Compare
aae56ed to
6f937ca
Compare
6f937ca to
a0512ff
Compare
a0512ff to
37f6866
Compare
37f6866 to
704ac98
Compare
9b5ea19 to
7d8f9f0
Compare
c8be84b to
12b8b72
Compare
6a016bf to
95062d5
Compare
95062d5 to
be113a8
Compare
76fc692 to
9eb68ec
Compare
9eb68ec to
2be5edd
Compare
2be5edd to
8ae07ad
Compare
8ae07ad to
4433c53
Compare
4433c53 to
5cdef16
Compare
5cdef16 to
3fcadbe
Compare
fb1d810 to
399ac54
Compare
399ac54 to
e3f73bb
Compare
e3f73bb to
44ee094
Compare
44ee094 to
70f622e
Compare
f1fe88e to
74cb397
Compare
74cb397 to
f65668b
Compare
f65668b to
93a504d
Compare
93a504d to
0eff117
Compare
9a2345f to
6fa7011
Compare
e84af87 to
2935ead
Compare
f8bf68a to
0d33c3b
Compare
0d33c3b to
902d2df
Compare
902d2df to
29768eb
Compare
29768eb to
a639d83
Compare
1dda658 to
f6bc35a
Compare
f6bc35a to
5d5c5c2
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
~1.8.3->~1.12.0GitHub Vulnerability Alerts
CVE-2021-23358
The package
underscorefrom 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.Release Notes
jashkenas/underscore (underscore)
v1.12.1Compare Source
v1.12.0Compare Source
v1.11.0Compare Source
v1.10.2Compare Source
v1.10.1Compare Source
v1.10.0Compare Source
v1.9.2Compare Source
v1.9.1Compare Source
v1.9.0Compare Source
Configuration
📅 Schedule: Branch creation - "" in timezone America/New_York, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.