Skip to content
This repository was archived by the owner on Jan 31, 2023. It is now read-only.

Conversation

@renovate
Copy link

@renovate renovate bot commented Oct 19, 2021

Mend Renovate

This PR contains the following updates:

Package Change
semver-regex 3.1.2 -> 3.1.4

GitHub Vulnerability Alerts

CVE-2021-3795

npm semver-regex is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-43307

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method


Configuration

📅 Schedule: Branch creation - "" in timezone America/New_York, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-semver-regex-vulnerability branch from fff5151 to 6fd0fca Compare March 26, 2022 16:01
@renovate renovate bot changed the title chore(deps): update dependency semver-regex to 3.1.3 [security] chore(deps): update dependency semver-regex to 3.1.3 [security] - autoclosed Apr 27, 2022
@renovate renovate bot closed this Apr 27, 2022
@renovate renovate bot deleted the renovate/npm-semver-regex-vulnerability branch April 27, 2022 12:02
@renovate renovate bot changed the title chore(deps): update dependency semver-regex to 3.1.3 [security] - autoclosed chore(deps): update dependency semver-regex to 3.1.3 [security] Apr 27, 2022
@renovate renovate bot restored the renovate/npm-semver-regex-vulnerability branch April 27, 2022 14:26
@renovate renovate bot reopened this Apr 27, 2022
@renovate renovate bot changed the title chore(deps): update dependency semver-regex to 3.1.3 [security] chore(deps): update dependency semver-regex to 3.1.3 [security] - autoclosed Apr 27, 2022
@renovate renovate bot closed this Apr 27, 2022
@renovate renovate bot deleted the renovate/npm-semver-regex-vulnerability branch April 27, 2022 17:12
@renovate renovate bot changed the title chore(deps): update dependency semver-regex to 3.1.3 [security] - autoclosed chore(deps): update dependency semver-regex to 3.1.3 [security] Apr 27, 2022
@renovate renovate bot reopened this Apr 27, 2022
@renovate renovate bot restored the renovate/npm-semver-regex-vulnerability branch April 27, 2022 19:52
@renovate renovate bot force-pushed the renovate/npm-semver-regex-vulnerability branch from 6fd0fca to 465c1bb Compare June 18, 2022 19:39
@renovate renovate bot changed the title chore(deps): update dependency semver-regex to 3.1.3 [security] chore(deps): update dependency semver-regex to 3.1.4 [security] Jun 18, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.