Build(deps): [security] bump parse-url from 6.0.0 to 6.0.5 #515

Merged
argoyle merged 1 commits from dependabot-npm_and_yarn-parse-url-6.0.5 into master 2022-08-05 12:17:17 +00:00
argoyle commented 2022-08-04 04:45:00 +00:00 (Migrated from gitlab.com)

Bumps parse-url from 6.0.0 to 6.0.5. This update includes security fixes.

Vulnerabilities fixed

Cross site scripting in parse-url Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 6.0.1

Patched versions: 6.0.1 Affected versions: < 6.0.1

Server-Side Request Forgery in parse-url Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.

Patched versions: 6.0.1 Affected versions: < 6.0.1

Cross site scripting in parse-url Cross-site Scripting (XSS) - Stored in GitHub repository ionicabizau/parse-url prior to 7.0.0.

Patched versions: 6.0.1 Affected versions: < 6.0.1

Hostname confusion in parse-url Exposure of Sensitive Information to an Unauthorized Actor via hostname confusion in GitHub repository ionicabizau/parse-url prior to 6.0.1

Patched versions: 6.0.1 Affected versions: < 6.0.1

Commits


Dependabot commands
You can trigger Dependabot actions by commenting on this MR
  • $dependabot rebase will rebase this MR
  • $dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts
Bumps [parse-url](https://github.com/IonicaBizau/parse-url) from 6.0.0 to 6.0.5. **This update includes security fixes.** <details> <summary>Vulnerabilities fixed</summary> <blockquote> <p><strong>Cross site scripting in parse-url</strong> Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 6.0.1</p> <p>Patched versions: 6.0.1 Affected versions: &lt; 6.0.1</p> </blockquote> <blockquote> <p><strong>Server-Side Request Forgery in parse-url</strong> Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.</p> <p>Patched versions: 6.0.1 Affected versions: &lt; 6.0.1</p> </blockquote> <blockquote> <p><strong>Cross site scripting in parse-url</strong> Cross-site Scripting (XSS) - Stored in GitHub repository ionicabizau/parse-url prior to 7.0.0.</p> <p>Patched versions: 6.0.1 Affected versions: &lt; 6.0.1</p> </blockquote> <blockquote> <p><strong>Hostname confusion in parse-url</strong> Exposure of Sensitive Information to an Unauthorized Actor via hostname confusion in GitHub repository ionicabizau/parse-url prior to 6.0.1</p> <p>Patched versions: 6.0.1 Affected versions: &lt; 6.0.1</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/IonicaBizau/parse-url/compare/6.0.0...6.0.5">compare view</a></li> </ul> </details> <br /> --- <details> <summary>Dependabot commands</summary> <br /> You can trigger Dependabot actions by commenting on this MR - `$dependabot rebase` will rebase this MR - `$dependabot recreate` will recreate this MR rewriting all the manual changes and resolving conflicts </details>
argoyle commented 2022-08-05 11:37:59 +00:00 (Migrated from gitlab.com)

added 2 commits

  • 95510d42 - 1 commit from branch master
  • 629deb9d - Build(deps): [security] bump parse-url from 6.0.0 to 6.0.5

Compare with previous version

added 2 commits <ul><li>95510d42 - 1 commit from branch <code>master</code></li><li>629deb9d - Build(deps): [security] bump parse-url from 6.0.0 to 6.0.5</li></ul> [Compare with previous version](/unboundsoftware/dancefinder/dancefinder-app/-/merge_requests/466/diffs?diff_id=454840436&start_sha=a9cc011a2d6d139d5b4fcce08f395a411c3bef41)
argoyle commented 2022-08-05 11:51:22 +00:00 (Migrated from gitlab.com)

added 2 commits

  • d4d70f41 - 1 commit from branch master
  • f3c5cfcd - Build(deps): [security] bump parse-url from 6.0.0 to 6.0.5

Compare with previous version

added 2 commits <ul><li>d4d70f41 - 1 commit from branch <code>master</code></li><li>f3c5cfcd - Build(deps): [security] bump parse-url from 6.0.0 to 6.0.5</li></ul> [Compare with previous version](/unboundsoftware/dancefinder/dancefinder-app/-/merge_requests/466/diffs?diff_id=454851501&start_sha=629deb9d81a2a0ea85538b02be08e7bd57e4fbe8)
argoyle commented 2022-08-05 12:03:55 +00:00 (Migrated from gitlab.com)

added 2 commits

  • c08fced3 - 1 commit from branch master
  • 0ca65d7a - Build(deps): [security] bump parse-url from 6.0.0 to 6.0.5

Compare with previous version

added 2 commits <ul><li>c08fced3 - 1 commit from branch <code>master</code></li><li>0ca65d7a - Build(deps): [security] bump parse-url from 6.0.0 to 6.0.5</li></ul> [Compare with previous version](/unboundsoftware/dancefinder/dancefinder-app/-/merge_requests/466/diffs?diff_id=454862486&start_sha=f3c5cfcde2041dc4437314a4c2507a4b582a2b5b)
argoyle (Migrated from gitlab.com) scheduled this pull request to auto merge when all checks succeed 2022-08-05 12:05:33 +00:00
argoyle (Migrated from gitlab.com) merged commit into master 2022-08-05 12:17:17 +00:00
Sign in to join this conversation.