Hostname confusion in parse-url
Exposure of Sensitive Information to an Unauthorized Actor via hostname confusion in GitHub repository ionicabizau/parse-url prior to 6.0.1
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebase will rebase this MR
$dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts
Bumps [parse-url](https://github.com/IonicaBizau/parse-url) from 6.0.0 to 6.0.5. **This update includes security fixes.**
<details>
<summary>Vulnerabilities fixed</summary>
<blockquote>
<p><strong>Cross site scripting in parse-url</strong>
Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 6.0.1</p>
<p>Patched versions: 6.0.1
Affected versions: < 6.0.1</p>
</blockquote>
<blockquote>
<p><strong>Server-Side Request Forgery in parse-url</strong>
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.</p>
<p>Patched versions: 6.0.1
Affected versions: < 6.0.1</p>
</blockquote>
<blockquote>
<p><strong>Cross site scripting in parse-url</strong>
Cross-site Scripting (XSS) - Stored in GitHub repository ionicabizau/parse-url prior to 7.0.0.</p>
<p>Patched versions: 6.0.1
Affected versions: < 6.0.1</p>
</blockquote>
<blockquote>
<p><strong>Hostname confusion in parse-url</strong>
Exposure of Sensitive Information to an Unauthorized Actor via hostname confusion in GitHub repository ionicabizau/parse-url prior to 6.0.1</p>
<p>Patched versions: 6.0.1
Affected versions: < 6.0.1</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a href="https://github.com/IonicaBizau/parse-url/compare/6.0.0...6.0.5">compare view</a></li>
</ul>
</details>
<br />
---
<details>
<summary>Dependabot commands</summary>
<br />
You can trigger Dependabot actions by commenting on this MR
- `$dependabot rebase` will rebase this MR
- `$dependabot recreate` will recreate this MR rewriting all the manual changes and resolving conflicts
</details>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps parse-url from 6.0.0 to 6.0.5. This update includes security fixes.
Vulnerabilities fixed
Commits
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebasewill rebase this MR$dependabot recreatewill recreate this MR rewriting all the manual changes and resolving conflictsadded 2 commits
95510d42- 1 commit from branchmasterCompare with previous version
added 2 commits
d4d70f41- 1 commit from branchmasterCompare with previous version
added 2 commits
c08fced3- 1 commit from branchmaster0ca65d7a- Build(deps): [security] bump parse-url from 6.0.0 to 6.0.5Compare with previous version