fix(deps): update dependency tough-cookie to v4 [security]#1004
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
fix(deps): update dependency tough-cookie to v4 [security]#1004renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
38082f9 to
38e9d4c
Compare
38e9d4c to
e3e6622
Compare
70a9dd9 to
9a81936
Compare
9a81936 to
7f83c30
Compare
9799602 to
561e722
Compare
51c19bc to
c60d611
Compare
dc5fffa to
49d90ef
Compare
be88498 to
4558285
Compare
fa1df1d to
96a233d
Compare
96a233d to
9b50823
Compare
014a6b4 to
7fc4dff
Compare
36b94e0 to
44b1fd8
Compare
386669d to
bb7e919
Compare
bb7e919 to
87647f5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.5.0→^4.0.0GitHub Vulnerability Alerts
CVE-2023-26136
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in
rejectPublicSuffixes=falsemode. This issue arises from the manner in which the objects are initialized.Release Notes
salesforce/tough-cookie (tough-cookie)
v4.1.3: 4.1.3Compare Source
Security fix for Prototype Pollution discovery in #282. This is a minor release, although output from the
inspectutility is affected by this change, we felt this change was important enough to be pushed into the next patch.v4.1.2: 4.1.2 -- Patch and Bugfix ReleaseCompare Source
What's Changed
Full Changelog: salesforce/tough-cookie@v4.1.1...v4.1.2
v4.1.1: 4.1.1Compare Source
Patch Release
What's Changed
Full Changelog: salesforce/tough-cookie@v4.1.0...v4.1.1
v4.1.0: 4.1.0Compare Source
v4.1.0
Minor release, focused mainly on resolving reported issues and some minor feature work.
What's Changed
allowSpecialUseDomainoption by @colincasey in #225New Contributors
Full Changelog: salesforce/tough-cookie@v4.0.0...v4.1.0
v4.0.0: Version 4.0.0Compare Source
Breaking Changes (Major Version)
universalify,eslintandprettier)pslandasyncfindCookies()- callback fn has to be last in order to comply withuniversalify.call()to do inheritance using function prototypesMinor Changes
v3.0.1Compare Source
v3.0.0Compare Source
Configuration
📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.