Skip to content
This repository was archived by the owner on Aug 12, 2023. It is now read-only.

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 16, 2020

This PR contains the following updates:

Package Type Update Change
lodash (source) dependencies patch 4.17.15 -> 4.17.19

GitHub Vulnerability Alerts

CVE-2020-8203

Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The function zipObjectDeep allows a malicious user to modify the prototype of Object if the property identifiers are user-supplied. Being affected by this issue requires zipping objects based on user-provided property arrays.

This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances.


Release Notes

lodash/lodash

v4.17.19

v4.17.16

Compare Source


Renovate configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by WhiteSource Renovate. View repository job log here.

@codecov
Copy link

codecov bot commented Jul 16, 2020

Codecov Report

Merging #427 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #427   +/-   ##
=======================================
  Coverage   63.56%   63.56%           
=======================================
  Files         136      136           
  Lines        1872     1872           
  Branches      192      192           
=======================================
  Hits         1190     1190           
  Misses        627      627           
  Partials       55       55           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update b785ab7...1c7bf42. Read the comment docs.

@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 4 times, most recently from eab9f9d to 24d84ae Compare July 25, 2020 17:23
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 3 times, most recently from 7e05415 to 742c8c5 Compare July 26, 2020 17:13
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 2 times, most recently from 765466d to 2b58a1c Compare August 2, 2020 09:52
@renovate renovate bot changed the title Update dependency lodash to v4.17.19 [SECURITY] fix(deps): update dependency lodash to v4.17.19 [security] Aug 2, 2020
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 2 times, most recently from 184eb8b to 1d562ac Compare August 2, 2020 17:36
@renovate renovate bot changed the title fix(deps): update dependency lodash to v4.17.19 [security] Update dependency lodash to v4.17.19 [SECURITY] Aug 2, 2020
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 6 times, most recently from d53b95a to f249275 Compare August 12, 2020 17:48
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 8 times, most recently from 678e95d to 9b3d453 Compare August 16, 2020 16:50
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 9b3d453 to 28d23ac Compare August 23, 2020 08:57
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 28d23ac to a451ddc Compare September 5, 2020 17:26
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 5 times, most recently from 3435835 to 6aaf61b Compare September 19, 2020 17:44
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 3 times, most recently from bcec80b to 296ecdf Compare September 27, 2020 14:43
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 6 times, most recently from 118afb9 to 104b47a Compare October 5, 2020 14:33
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 3 times, most recently from 576a1f3 to 4355777 Compare October 6, 2020 18:41
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 8 times, most recently from e4bdec7 to 2fa2fd7 Compare October 20, 2020 16:05
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 2fa2fd7 to 1c7bf42 Compare October 22, 2020 19:06
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant