Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency webpack-dev-server to v3.1.11 [security] #119

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Apr 15, 2020

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
webpack-dev-server 3.1.3 -> 3.1.11 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2018-14732

Versions of webpack-dev-server before 3.1.10 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated.

Recommendation

For webpack-dev-server update to version 3.1.11 or later.


Release Notes

webpack/webpack-dev-server (webpack-dev-server)

v3.1.11

Compare Source

Bug Fixes

v3.1.10

Compare Source

Bug Fixes

v3.1.9

Compare Source

3.1.9 (2018-09-24)

v3.1.8

Compare Source

Bug Fixes
  • package: yargs security vulnerability (dependencies) (#​1492) (8fb67c9)
  • utils/createLogger: ensure quiet always takes precedence (options.quiet) (#​1486) (7a6ca47)

v3.1.7

Compare Source

Bug Fixes

v3.1.6

Compare Source

Bug Fixes
  • bin: handle process signals correctly when the server isn't ready yet (#​1432) (334c3a5)
  • examples/cli: correct template path in open-page example (#​1401) (df30727)
  • schema: allow the output filename to be a {Function} (#​1409) (e2220c4)

v3.1.5

Compare Source

  • Send the Progress event in the client so plugins can use it (#​1427)
  • Update sockjs-client to fix infinite reconnection loop (#​1434)

v3.1.4

Compare Source

  • Update to webpack-dev-middleware 3.1.3, which should fix paths with a space not working on Windows (#​1392)
  • Fix logLevel option silent not being accepted by schema validation (#​1372)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch 2 times, most recently from 900e045 to b0aa329 Compare May 7, 2020 21:58
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from b0aa329 to f7bc1c7 Compare May 15, 2020 07:57
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch 4 times, most recently from 1871393 to 75fd984 Compare June 19, 2020 07:35
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 75fd984 to 8717a59 Compare June 24, 2020 10:55
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch 9 times, most recently from 7a182b9 to d4bff60 Compare July 13, 2020 18:15
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch 4 times, most recently from 3d9094d to 53e82b7 Compare July 24, 2020 19:46
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch 3 times, most recently from ef29903 to c2f15a4 Compare August 4, 2020 06:29
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch 2 times, most recently from bec81d7 to c7dc228 Compare August 13, 2020 18:07
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from c7dc228 to c5bcf78 Compare August 27, 2020 06:56
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from c5bcf78 to 2a09b98 Compare October 26, 2020 08:56
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 2a09b98 to 20e51cb Compare November 27, 2020 06:52
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 20e51cb to a44f09c Compare December 10, 2020 12:57
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch 2 times, most recently from ff0fed6 to f8d2eab Compare January 10, 2021 13:53
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from f8d2eab to b4122dd Compare January 22, 2021 18:00
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from b4122dd to b1cc8c2 Compare January 30, 2021 21:00
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch 2 times, most recently from 1fb5596 to bafd3fb Compare February 10, 2021 18:54
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from bafd3fb to 4f3cfbc Compare April 26, 2021 12:44
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 4f3cfbc to d1c9f5d Compare May 9, 2021 20:40
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from d1c9f5d to c1ef44b Compare March 7, 2022 09:51
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from c1ef44b to 5ee021d Compare March 26, 2022 12:09
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 5ee021d to 80fd213 Compare April 24, 2022 21:15
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 80fd213 to 737f362 Compare May 15, 2022 20:32
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch 2 times, most recently from 8ff2593 to 4aa8b1d Compare June 23, 2022 19:37
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 4aa8b1d to 44cc3bb Compare September 25, 2022 12:23
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 44cc3bb to 545bf9b Compare November 20, 2022 18:43
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 545bf9b to 67b1744 Compare March 16, 2023 08:05
@renovate
Copy link
Author

renovate bot commented Mar 24, 2023

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: yarn.lock
Error response from daemon: toomanyrequests: You have reached your pull rate limit. You may increase the limit by authenticating and upgrading: https://www.docker.com/increase-rate-limit

@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 67b1744 to 6fc285b Compare March 24, 2023 23:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants