Skip to content
This repository has been archived by the owner on Jan 16, 2024. It is now read-only.

fix(deps): update dependency underscore to v1.12.1 [security] #66

Merged
merged 1 commit into from
Jun 5, 2021

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 13, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
underscore (source) 1.9.1 -> 1.12.1 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-23358

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.


Release Notes

jashkenas/underscore

v1.12.1

Compare Source

v1.12.0

Compare Source

v1.11.0

Compare Source

v1.10.2

Compare Source

v1.10.1

Compare Source

v1.10.0

Compare Source

v1.9.2

Compare Source


Configuration

📅 Schedule: "" in timezone America/Toronto.

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot added the CVE label May 13, 2021
@renovate renovate bot force-pushed the renovate/npm-underscore-vulnerability branch 6 times, most recently from b6191e5 to f406f12 Compare June 5, 2021 19:47
@renovate renovate bot force-pushed the renovate/npm-underscore-vulnerability branch from f406f12 to 5def37e Compare June 5, 2021 19:51
@kunalnagar kunalnagar merged commit b7566d7 into master Jun 5, 2021
@kunalnagar kunalnagar deleted the renovate/npm-underscore-vulnerability branch June 5, 2021 20:42
kunalnagar pushed a commit that referenced this pull request Jun 5, 2021
[skip ci]

### [1.0.8](v1.0.7...v1.0.8) (2021-06-05)

### Bug Fixes

* **deps:** update dependency underscore to v1.12.1 [security] ([#66](#66)) ([b7566d7](b7566d7))

### Chores

* **deps:** update dependency @types/node-fetch to v2.5.10 ([#67](#67)) ([e9c17b1](e9c17b1))
* **deps:** update dependency eslint to v7.28.0 ([#69](#69)) ([5f2a831](5f2a831))
* **deps:** update dependency eslint-config-prettier to v8.3.0 ([#71](#71)) ([0a01190](0a01190))
* **deps:** update dependency lint-staged to v11 ([#60](#60)) ([ba058e7](ba058e7))
* **deps:** update dependency mem to v8 ([#61](#61)) ([793a73e](793a73e))
* **deps:** update dependency prettier to v2.3.1 ([#64](#64)) ([e1b1622](e1b1622))
* **deps:** update dependency sort-package-json to v1.50.0 ([#56](#56)) ([5b538b5](5b538b5))
* **deps:** update dependency typescript to v4.3.2 ([#68](#68)) ([06b6ae9](06b6ae9))
* **deps:** update dependency yargs-parser to v20 ([#63](#63)) ([0f8ad74](0f8ad74))
@kunalnagar
Copy link
Member

🎉 This PR is included in version 1.0.8 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants