Bumps terser from 4.8.0 to 4.8.1. This update includes a security fix.
Vulnerabilities fixed
Terser insecure use of regular expressions before v4.8.1 and v5.14.2 leads to ReDoS
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebase will rebase this MR
$dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts
Bumps [terser](https://github.com/terser/terser) from 4.8.0 to 4.8.1. **This update includes a security fix.**
<details>
<summary>Vulnerabilities fixed</summary>
<blockquote>
<p><strong>Terser insecure use of regular expressions before v4.8.1 and v5.14.2 leads to ReDoS</strong>
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.</p>
<p>Patched versions: 4.8.1
Affected versions: < 4.8.1</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/terser/terser/blob/master/CHANGELOG.md">terser's changelog</a>.</em></p>
<blockquote>
<h2>v4.8.1 (backport)</h2>
<ul>
<li>Security fix for RegExps that should not be evaluated (regexp DDOS)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/terser/terser/commit/40674a433e2b2fd9dfe7aaa93a0da224fb5e76b9"><code>40674a4</code></a> update changelog, version</li>
<li><a href="https://github.com/terser/terser/commit/d8cc5691be980d663c29cc4d5ce67e852d597012"><code>d8cc569</code></a> backport fix to potential regexp DDOS</li>
<li>See full diff in <a href="https://github.com/terser/terser/compare/v4.8.0...v4.8.1">compare view</a></li>
</ul>
</details>
<br />
---
<details>
<summary>Dependabot commands</summary>
<br />
You can trigger Dependabot actions by commenting on this MR
- `$dependabot rebase` will rebase this MR
- `$dependabot recreate` will recreate this MR rewriting all the manual changes and resolving conflicts
</details>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps terser from 4.8.0 to 4.8.1. This update includes a security fix.
Vulnerabilities fixed
Changelog
Sourced from terser's changelog.
Commits
40674a4update changelog, versiond8cc569backport fix to potential regexp DDOSDependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebasewill rebase this MR$dependabot recreatewill recreate this MR rewriting all the manual changes and resolving conflictsadded 2 commits
95510d42- 1 commit from branchmasterCompare with previous version
added 2 commits
d4d70f41- 1 commit from branchmasterCompare with previous version
added 2 commits
c08fced3- 1 commit from branchmasterCompare with previous version
added 2 commits
0ca65d7a- 1 commit from branchmastere2d68589- Build(deps): [security] bump terser from 4.8.0 to 4.8.1Compare with previous version