Skip to content

Commit

Permalink
⬆️ Update dependency happy-dom to v15.10.2 [SECURITY] (#5412)
Browse files Browse the repository at this point in the history
This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [happy-dom](https://redirect.github.com/capricorn86/happy-dom) |
[`15.9.0` ->
`15.10.2`](https://renovatebot.com/diffs/npm/happy-dom/15.9.0/15.10.2) |
[![age](https://developer.mend.io/api/mc/badges/age/npm/happy-dom/15.10.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/happy-dom/15.10.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/happy-dom/15.9.0/15.10.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/happy-dom/15.9.0/15.10.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

### GitHub Vulnerability Alerts

####
[CVE-2024-51757](https://redirect.github.com/capricorn86/happy-dom/security/advisories/GHSA-96g7-g7g9-jxw8)

### Impact
Consumers of the NPM package `happy-dom`

### Patches
The security vulnerability has been patched in v15.10.2

### Workarounds
No easy workarounds to my knowledge

### References

[#​1585](https://redirect.github.com/capricorn86/happy-dom/issues/1585)

---

### happy-dom allows for server side code to be executed by a <script>
tag
[CVE-2024-51757](https://nvd.nist.gov/vuln/detail/CVE-2024-51757) /
[GHSA-96g7-g7g9-jxw8](https://redirect.github.com/advisories/GHSA-96g7-g7g9-jxw8)

<details>
<summary>More information</summary>

#### Details
##### Impact
Consumers of the NPM package `happy-dom`

##### Patches
The security vulnerability has been patched in v15.10.2

##### Workarounds
No easy workarounds to my knowledge

##### References

[#&#8203;1585](https://redirect.github.com/capricorn86/happy-dom/issues/1585)

#### Severity
- CVSS Score: Unknown
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N`

#### References
-
[https://github.com/capricorn86/happy-dom/security/advisories/GHSA-96g7-g7g9-jxw8](https://redirect.github.com/capricorn86/happy-dom/security/advisories/GHSA-96g7-g7g9-jxw8)
-
[https://nvd.nist.gov/vuln/detail/CVE-2024-51757](https://nvd.nist.gov/vuln/detail/CVE-2024-51757)
-
[https://github.com/capricorn86/happy-dom/issues/1585](https://redirect.github.com/capricorn86/happy-dom/issues/1585)
-
[https://github.com/capricorn86/happy-dom/pull/1586](https://redirect.github.com/capricorn86/happy-dom/pull/1586)
-
[https://github.com/capricorn86/happy-dom/commit/5ee0b1676d4ce20cc2a70d1c9c8d6f1e3f57efac](https://redirect.github.com/capricorn86/happy-dom/commit/5ee0b1676d4ce20cc2a70d1c9c8d6f1e3f57efac)
-
[https://github.com/capricorn86/happy-dom/commit/d23834c232f1cf5519c9418b073f1dcec6b2f0fd](https://redirect.github.com/capricorn86/happy-dom/commit/d23834c232f1cf5519c9418b073f1dcec6b2f0fd)
-
[https://github.com/capricorn86/happy-dom](https://redirect.github.com/capricorn86/happy-dom)
-
[https://github.com/capricorn86/happy-dom/releases/tag/v15.10.2](https://redirect.github.com/capricorn86/happy-dom/releases/tag/v15.10.2)

This data is provided by
[OSV](https://osv.dev/vulnerability/GHSA-96g7-g7g9-jxw8) and the [GitHub
Advisory Database](https://redirect.github.com/github/advisory-database)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>capricorn86/happy-dom (happy-dom)</summary>

###
[`v15.10.2`](https://redirect.github.com/capricorn86/happy-dom/compare/v15.10.1...d23834c232f1cf5519c9418b073f1dcec6b2f0fd)

[Compare
Source](https://redirect.github.com/capricorn86/happy-dom/compare/v15.10.1...v15.10.2)

###
[`v15.10.1`](https://redirect.github.com/capricorn86/happy-dom/compare/v15.10.0...5ee0b1676d4ce20cc2a70d1c9c8d6f1e3f57efac)

[Compare
Source](https://redirect.github.com/capricorn86/happy-dom/compare/v15.10.0...v15.10.1)

###
[`v15.10.0`](https://redirect.github.com/capricorn86/happy-dom/compare/v15.9.0...1625d4080339190682bc76bbe79ea26132accfda)

[Compare
Source](https://redirect.github.com/capricorn86/happy-dom/compare/v15.9.0...v15.10.0)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/dubzzz/fast-check).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xNDIuNyIsInVwZGF0ZWRJblZlciI6IjM4LjE0Mi43IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
  • Loading branch information
renovate[bot] authored Nov 8, 2024
1 parent 2da9ef1 commit 846d63d
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -11012,13 +11012,13 @@ __metadata:
linkType: hard

"happy-dom@npm:^15.9.0":
version: 15.9.0
resolution: "happy-dom@npm:15.9.0"
version: 15.10.2
resolution: "happy-dom@npm:15.10.2"
dependencies:
entities: "npm:^4.5.0"
webidl-conversions: "npm:^7.0.0"
whatwg-mimetype: "npm:^3.0.0"
checksum: 10c0/1b63ada1a99d9b66d11b4ea3d800a61e2ae56e3d3cae133f002b916ba1d17962b4cf809caa87ae1c1c80335dd6ec82eea8a535c88bee3d3a85b87f630964cab8
checksum: 10c0/b0403c4c53021da25989b320f2a6c0ab760cc538f10e403df9d2f14b0a7d20b1be961192c95322b335dc71fa27941e7e8b883b2d79d7c9c51215a97b3e3097a6
languageName: node
linkType: hard

Expand Down

0 comments on commit 846d63d

Please sign in to comment.