-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update dependency jszip to v3.8.0 [security] #110
base: master
Are you sure you want to change the base?
Conversation
Kudos, SonarCloud Quality Gate passed! |
94a501b
to
c8e5877
Compare
Kudos, SonarCloud Quality Gate passed! |
c8e5877
to
a62925c
Compare
Kudos, SonarCloud Quality Gate passed! |
a62925c
to
b8dbc16
Compare
Kudos, SonarCloud Quality Gate passed! |
b08fdaa
to
5ba91f5
Compare
Quality Gate passedKudos, no new issues were introduced! 0 New issues |
5ba91f5
to
98f9706
Compare
Quality Gate passedIssues Measures |
This PR contains the following updates:
3.7.1
->3.8.0
GitHub Vulnerability Alerts
CVE-2022-48285
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
Release Notes
Stuk/jszip (jszip)
v3.8.0
Compare Source
loadAsync
, to avoid "zip slip" attacks. The original filename is available on each zip entry asunsafeOriginalName
. See the documentation. Many thanks to McCaulay Hudson for reporting.Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.