Skip to content

fix(deps): update dependency semver to v7.5.2 [security] - #165

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-semver-vulnerability
Closed

fix(deps): update dependency semver to v7.5.2 [security]#165
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-semver-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jun 30, 2023

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
semver 7.3.7 -> 7.5.2 age confidence

GitHub Vulnerability Alerts

CVE-2022-25883

Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.


Release Notes

npm/node-semver (semver)

v7.5.2

Compare Source

Bug Fixes

v7.5.1

Compare Source

Bug Fixes

v7.5.0

Compare Source

Features
Bug Fixes

v7.4.0

Compare Source

Features
Bug Fixes
Documentation

v7.3.8

Compare Source

Bug Fixes
Documentation
7.3.7 (2022-04-11)
Bug Fixes
Dependencies
7.3.6 (2022-04-05)
Bug Fixes
Documentation
  • clarify * range behavior (cb1ca1d)
Dependencies

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from roikoren755 as a code owner June 30, 2023 04:05
@changeset-bot

changeset-bot Bot commented Jun 30, 2023

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 296be48

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@renovate renovate Bot changed the title fix(deps): update dependency semver to v7.5.2 [security] fix(deps): update dependency semver to v7.5.2 [security] - autoclosed Jul 11, 2023
@renovate renovate Bot closed this Jul 11, 2023
@renovate
renovate Bot deleted the renovate/npm-semver-vulnerability branch July 11, 2023 01:17
@renovate renovate Bot changed the title fix(deps): update dependency semver to v7.5.2 [security] - autoclosed fix(deps): update dependency semver to v7.5.2 [security] Jul 13, 2023
@renovate renovate Bot reopened this Jul 13, 2023
@renovate
renovate Bot restored the renovate/npm-semver-vulnerability branch July 13, 2023 09:30
@renovate
renovate Bot force-pushed the renovate/npm-semver-vulnerability branch from 46d6b16 to 52561f9 Compare July 13, 2023 09:31
@sonarqubecloud

Copy link
Copy Markdown

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@renovate renovate Bot changed the title fix(deps): update dependency semver to v7.5.2 [security] fix(deps): update dependency semver to v7.5.2 [security] - autoclosed Dec 8, 2024
@renovate renovate Bot closed this Dec 8, 2024
@renovate
renovate Bot deleted the renovate/npm-semver-vulnerability branch December 8, 2024 18:30
@renovate renovate Bot changed the title fix(deps): update dependency semver to v7.5.2 [security] - autoclosed fix(deps): update dependency semver to v7.5.2 [security] Dec 8, 2024
@renovate renovate Bot reopened this Dec 8, 2024
@renovate
renovate Bot force-pushed the renovate/npm-semver-vulnerability branch from 9537404 to 52561f9 Compare December 8, 2024 21:24
@sonarqubecloud

sonarqubecloud Bot commented Dec 8, 2024

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/npm-semver-vulnerability branch from 52561f9 to 296be48 Compare August 10, 2025 14:59
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant