Skip to content

Conversation

dependabot-preview[bot]
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented May 7, 2021

Bumps hosted-git-info from 2.8.8 to 2.8.9. This update includes a security fix.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

Regular Expression Denial of Service in hosted-git-info The npm package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity

Affected versions: < 2.8.9

Changelog

Sourced from hosted-git-info's changelog.

2.8.9 (2021-04-07)

Bug Fixes

Commits
Maintainer changes

This version was pushed to npm by nlf, a new releaser for hosted-git-info since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added security Pull requests that address a security vulnerability 🔗 dependencies Pull requests that update a dependency file labels May 7, 2021
@codecov
Copy link

codecov bot commented May 7, 2021

Codecov Report

Merging #645 (f5216b0) into master (005d450) will not change coverage.
The diff coverage is 100.00%.

Impacted file tree graph

@@            Coverage Diff             @@
##            master      #645    +/-   ##
==========================================
  Coverage   100.00%   100.00%            
==========================================
  Files           24        29     +5     
  Lines          149       303   +154     
  Branches        30        65    +35     
==========================================
+ Hits           149       303   +154     
Impacted Files Coverage Δ
packages/ab-test-jsx/src/withABTest/withABTest.tsx 100.00% <ø> (ø)
...ckages/ab-test-jsx/src/withABTests/withABTests.tsx 100.00% <ø> (ø)
.../ab-test-jsx/src/ABTestsContext/ABTestsContext.tsx 100.00% <100.00%> (ø)
...b-test-jsx/src/ABTestsProvider/ABTestsProvider.tsx 100.00% <100.00%> (ø)
packages/ab-test-jsx/src/useABTests/useABTests.tsx 100.00% <100.00%> (ø)
...sx/src/withABTestsProvider/withABTestsProvider.tsx 100.00% <100.00%> (ø)
...r-boundary-jsx/src/ErrorBoundary/ErrorBoundary.tsx 100.00% <100.00%> (ø)
...ry-jsx/src/withErrorBoundary/withErrorBoundary.tsx 100.00% <100.00%> (ø)
...fast-number-formatter/src/numberFormatter/index.ts 100.00% <100.00%> (ø)
...es/feature-toggle-jsx/src/useFeature/useFeature.ts 100.00% <100.00%> (ø)
... and 18 more

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update d9313fe...f5216b0. Read the comment docs.

@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/hosted-git-info-2.8.9 branch from c52b170 to 6f84f93 Compare May 28, 2021 22:51
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/hosted-git-info-2.8.9 branch 2 times, most recently from b710305 to dbe042d Compare June 19, 2021 14:09
Bumps [hosted-git-info](https://github.com/npm/hosted-git-info) from 2.8.8 to 2.8.9. **This update includes a security fix.**
- [Release notes](https://github.com/npm/hosted-git-info/releases)
- [Changelog](https://github.com/npm/hosted-git-info/blob/v2.8.9/CHANGELOG.md)
- [Commits](npm/hosted-git-info@v2.8.8...v2.8.9)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/hosted-git-info-2.8.9 branch from dbe042d to f5216b0 Compare June 25, 2021 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🔗 dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants