Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
⬆️ Update dependency happy-dom to v15.10.2 [SECURITY] (#5412)
This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [happy-dom](https://redirect.github.com/capricorn86/happy-dom) | [`15.9.0` -> `15.10.2`](https://renovatebot.com/diffs/npm/happy-dom/15.9.0/15.10.2) | [![age](https://developer.mend.io/api/mc/badges/age/npm/happy-dom/15.10.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/happy-dom/15.10.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/happy-dom/15.9.0/15.10.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/happy-dom/15.9.0/15.10.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | ### GitHub Vulnerability Alerts #### [CVE-2024-51757](https://redirect.github.com/capricorn86/happy-dom/security/advisories/GHSA-96g7-g7g9-jxw8) ### Impact Consumers of the NPM package `happy-dom` ### Patches The security vulnerability has been patched in v15.10.2 ### Workarounds No easy workarounds to my knowledge ### References [#​1585](https://redirect.github.com/capricorn86/happy-dom/issues/1585) --- ### happy-dom allows for server side code to be executed by a <script> tag [CVE-2024-51757](https://nvd.nist.gov/vuln/detail/CVE-2024-51757) / [GHSA-96g7-g7g9-jxw8](https://redirect.github.com/advisories/GHSA-96g7-g7g9-jxw8) <details> <summary>More information</summary> #### Details ##### Impact Consumers of the NPM package `happy-dom` ##### Patches The security vulnerability has been patched in v15.10.2 ##### Workarounds No easy workarounds to my knowledge ##### References [#​1585](https://redirect.github.com/capricorn86/happy-dom/issues/1585) #### Severity - CVSS Score: Unknown - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N` #### References - [https://github.com/capricorn86/happy-dom/security/advisories/GHSA-96g7-g7g9-jxw8](https://redirect.github.com/capricorn86/happy-dom/security/advisories/GHSA-96g7-g7g9-jxw8) - [https://nvd.nist.gov/vuln/detail/CVE-2024-51757](https://nvd.nist.gov/vuln/detail/CVE-2024-51757) - [https://github.com/capricorn86/happy-dom/issues/1585](https://redirect.github.com/capricorn86/happy-dom/issues/1585) - [https://github.com/capricorn86/happy-dom/pull/1586](https://redirect.github.com/capricorn86/happy-dom/pull/1586) - [https://github.com/capricorn86/happy-dom/commit/5ee0b1676d4ce20cc2a70d1c9c8d6f1e3f57efac](https://redirect.github.com/capricorn86/happy-dom/commit/5ee0b1676d4ce20cc2a70d1c9c8d6f1e3f57efac) - [https://github.com/capricorn86/happy-dom/commit/d23834c232f1cf5519c9418b073f1dcec6b2f0fd](https://redirect.github.com/capricorn86/happy-dom/commit/d23834c232f1cf5519c9418b073f1dcec6b2f0fd) - [https://github.com/capricorn86/happy-dom](https://redirect.github.com/capricorn86/happy-dom) - [https://github.com/capricorn86/happy-dom/releases/tag/v15.10.2](https://redirect.github.com/capricorn86/happy-dom/releases/tag/v15.10.2) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-96g7-g7g9-jxw8) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>capricorn86/happy-dom (happy-dom)</summary> ### [`v15.10.2`](https://redirect.github.com/capricorn86/happy-dom/compare/v15.10.1...d23834c232f1cf5519c9418b073f1dcec6b2f0fd) [Compare Source](https://redirect.github.com/capricorn86/happy-dom/compare/v15.10.1...v15.10.2) ### [`v15.10.1`](https://redirect.github.com/capricorn86/happy-dom/compare/v15.10.0...5ee0b1676d4ce20cc2a70d1c9c8d6f1e3f57efac) [Compare Source](https://redirect.github.com/capricorn86/happy-dom/compare/v15.10.0...v15.10.1) ### [`v15.10.0`](https://redirect.github.com/capricorn86/happy-dom/compare/v15.9.0...1625d4080339190682bc76bbe79ea26132accfda) [Compare Source](https://redirect.github.com/capricorn86/happy-dom/compare/v15.9.0...v15.10.0) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/dubzzz/fast-check). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xNDIuNyIsInVwZGF0ZWRJblZlciI6IjM4LjE0Mi43IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
- Loading branch information