-
Notifications
You must be signed in to change notification settings - Fork 80
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency @braintree/sanitize-url to 6.0.0 [SECURITY] - abandoned #881
base: master
Are you sure you want to change the base?
Update dependency @braintree/sanitize-url to 6.0.0 [SECURITY] - abandoned #881
Conversation
Codecov Report
@@ Coverage Diff @@
## master #881 +/- ##
=========================================
Coverage 89.41% 89.41%
Complexity 1942 1942
=========================================
Files 325 325
Lines 8628 8628
Branches 1288 1288
=========================================
Hits 7715 7715
Misses 651 651
Partials 262 262
Flags with carried forward coverage won't be shown. Click here to find out more. Continue to review full report at Codecov.
|
b92e246
to
6fd4ec7
Compare
6fd4ec7
to
943cf8e
Compare
560d760
to
4fa13e0
Compare
a5e8db1
to
36186b9
Compare
36186b9
to
2665b8a
Compare
Autoclosing SkippedThis PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error. |
This PR contains the following updates:
5.0.2
->6.0.0
⚠ Dependency Lookup Warnings ⚠
Warnings were logged while processing this repo. Please check the logs for more information.
GitHub Vulnerability Alerts
CVE-2021-23648
The package
@braintree/sanitize-url
before 6.0.0 is vulnerable to Cross-site Scripting (XSS) due to improper sanitization in thesanitizeUrl
function.Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Renovate will not automatically rebase this PR, because other commits have been found.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.