Build(deps): [security] bump terser from 4.8.0 to 4.8.1 #493

Merged
argoyle merged 1 commits from dependabot-npm_and_yarn-terser-4.8.1 into master 2022-07-23 10:30:48 +00:00
argoyle commented 2022-07-21 04:44:19 +00:00 (Migrated from gitlab.com)

Bumps terser from 4.8.0 to 4.8.1. This update includes a security fix.

Vulnerabilities fixed

Terser insecure use of regular expressions before v4.8.1 and v5.14.2 leads to ReDoS The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

Patched versions: 4.8.1 Affected versions: < 4.8.1

Changelog

Sourced from terser's changelog.

v4.8.1 (backport)

  • Security fix for RegExps that should not be evaluated (regexp DDOS)
Commits


Dependabot commands
You can trigger Dependabot actions by commenting on this MR
  • $dependabot rebase will rebase this MR
  • $dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts
Bumps [terser](https://github.com/terser/terser) from 4.8.0 to 4.8.1. **This update includes a security fix.** <details> <summary>Vulnerabilities fixed</summary> <blockquote> <p><strong>Terser insecure use of regular expressions before v4.8.1 and v5.14.2 leads to ReDoS</strong> The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.</p> <p>Patched versions: 4.8.1 Affected versions: &lt; 4.8.1</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/terser/terser/blob/master/CHANGELOG.md">terser's changelog</a>.</em></p> <blockquote> <h2>v4.8.1 (backport)</h2> <ul> <li>Security fix for RegExps that should not be evaluated (regexp DDOS)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/terser/terser/commits">compare view</a></li> </ul> </details> <br /> --- <details> <summary>Dependabot commands</summary> <br /> You can trigger Dependabot actions by commenting on this MR - `$dependabot rebase` will rebase this MR - `$dependabot recreate` will recreate this MR rewriting all the manual changes and resolving conflicts </details>
argoyle commented 2022-07-23 10:21:50 +00:00 (Migrated from gitlab.com)

added 2 commits

  • bb1be9be - 1 commit from branch master
  • 9bf719ea - Build(deps): [security] bump terser from 4.8.0 to 4.8.1

Compare with previous version

added 2 commits <ul><li>bb1be9be - 1 commit from branch <code>master</code></li><li>9bf719ea - Build(deps): [security] bump terser from 4.8.0 to 4.8.1</li></ul> [Compare with previous version](/unboundsoftware/dancefinder/dancefinder-app/-/merge_requests/444/diffs?diff_id=444955725&start_sha=209b373b2045b6c7a905a8d2d1765021385fb348)
argoyle (Migrated from gitlab.com) scheduled this pull request to auto merge when all checks succeed 2022-07-23 10:24:46 +00:00
argoyle (Migrated from gitlab.com) merged commit into master 2022-07-23 10:30:48 +00:00
Sign in to join this conversation.