Bumps @cypress/request from 2.88.11 to 2.88.12. This update includes a security fix.
Vulnerabilities fixed
Server-Side Request Forgery in Request
The request package through 2.88.2 for Node.js and the @cypress/request package through 2.88.11 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).
NOTE: The request package is no longer supported by the maintainer.
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts
Bumps [@cypress/request](https://github.com/cypress-io/request) from 2.88.11 to 2.88.12. **This update includes a security fix.**
<details>
<summary>Vulnerabilities fixed</summary>
<blockquote>
<p><strong>Server-Side Request Forgery in Request</strong>
The <code>request</code> package through 2.88.2 for Node.js and the <code>@cypress/request</code> package through 2.88.11 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).</p>
<p>NOTE: The <code>request</code> package is no longer supported by the maintainer.</p>
<p>Patched versions: none
Affected versions: <= 2.88.11</p>
</blockquote>
</details>
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/cypress-io/request/releases"><code>@cypress/request</code>'s releases</a>.</em></p>
<blockquote>
<h2>v2.88.12</h2>
<h2><a href="https://github.com/cypress-io/request/compare/v2.88.11...v2.88.12">2.88.12</a> (2023-08-01)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>request:</strong> update tough-cookie dep (<a href="https://github.com/cypress-io/request/commit/0664780557c95610eafeedff6067bacac6783705">0664780</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/cypress-io/request/commit/0664780557c95610eafeedff6067bacac6783705"><code>0664780</code></a> fix(request): update tough-cookie dep</li>
<li><a href="https://github.com/cypress-io/request/commit/30def80c9d957ed2a782af634602f26eb41843ee"><code>30def80</code></a> Merge pull request <a href="https://github.com/cypress-io/request/issues/39">#39</a> from cypress-io/jordanpowell88/update-pkg-version</li>
<li><a href="https://github.com/cypress-io/request/commit/6b79405e704e882df06b68961ab2835c56d7cbcf"><code>6b79405</code></a> update package version</li>
<li><a href="https://github.com/cypress-io/request/commit/bfbb95fa1b376977fff49317fe56fb340ee15657"><code>bfbb95f</code></a> Merge pull request <a href="https://github.com/cypress-io/request/issues/32">#32</a> from BreakBB/fix-cve-2023-26136</li>
<li><a href="https://github.com/cypress-io/request/commit/a67e1320ea1fbe74ebe936ad9ebeba3b60258774"><code>a67e132</code></a> pin 18.16</li>
<li><a href="https://github.com/cypress-io/request/commit/825485a0913e3823f147ae0411a48248cbdfc73f"><code>825485a</code></a> revert back to yarn but v 18</li>
<li><a href="https://github.com/cypress-io/request/commit/3bce3544559d7dbf572ae09ae51092a88c6d2dc1"><code>3bce354</code></a> update workflow to use npm</li>
<li><a href="https://github.com/cypress-io/request/commit/4ceb20bc0ec023790a821c494fe77ae094bf7f03"><code>4ceb20b</code></a> Merge branch 'master' into fix-cve-2023-26136</li>
<li><a href="https://github.com/cypress-io/request/commit/228831e4fef2298bc69127e2c73772125465be84"><code>228831e</code></a> Merge pull request <a href="https://github.com/cypress-io/request/issues/38">#38</a> from cypress-io/benm/github-workflows-update</li>
<li><a href="https://github.com/cypress-io/request/commit/f6ee03f77f8af517d23925026835a9cd46686337"><code>f6ee03f</code></a> chore: add in workflows for github. update workflow actions</li>
<li>Additional commits viewable in <a href="https://github.com/cypress-io/request/compare/v2.88.11...v2.88.12">compare view</a></li>
</ul>
</details>
<br />
---
<details>
<summary>Dependabot commands</summary>
<br />
You can trigger Dependabot actions by commenting on this MR
- `$dependabot recreate` will recreate this MR rewriting all the manual changes and resolving conflicts
</details>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps @cypress/request from 2.88.11 to 2.88.12. This update includes a security fix.
Vulnerabilities fixed
Release notes
Sourced from
@cypress/request's releases.Commits
0664780fix(request): update tough-cookie dep30def80Merge pull request #39 from cypress-io/jordanpowell88/update-pkg-version6b79405update package versionbfbb95fMerge pull request #32 from BreakBB/fix-cve-2023-26136a67e132pin 18.16825485arevert back to yarn but v 183bce354update workflow to use npm4ceb20bMerge branch 'master' into fix-cve-2023-26136228831eMerge pull request #38 from cypress-io/benm/github-workflows-updatef6ee03fchore: add in workflows for github. update workflow actionsDependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot recreatewill recreate this MR rewriting all the manual changes and resolving conflictsadded 3 commits
master859bd2d0- Build(deps): [security] bump @cypress/request from 2.88.11 to 2.88.12Compare with previous version