Skip to content
This repository has been archived by the owner on Mar 26, 2022. It is now read-only.

Update dependency webpack-subresource-integrity to 1.5.1 [SECURITY] #315

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 3, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change
webpack-subresource-integrity 1.1.0-rc.6 -> 1.5.1

GitHub Vulnerability Alerts

CVE-2020-15262

Impact

All dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are unaffected.

Patches

This issue is patched in version 1.5.1.

Workarounds

N/A

References

https://github.com/waysact/webpack-subresource-integrity/issues/131

For more information

If you have any questions or comments about this advisory:


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled due to failing status checks.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch 22 times, most recently from 5318654 to 521ba9b Compare March 8, 2021 23:32
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch 3 times, most recently from f356525 to cf1d9b9 Compare March 19, 2021 04:40
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch 4 times, most recently from 5c19553 to 0e14dc1 Compare March 30, 2021 09:07
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch from 0e14dc1 to 81068fc Compare April 19, 2021 20:06
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch 10 times, most recently from 94419ff to b8a9b2c Compare May 7, 2021 22:20
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch 4 times, most recently from 43d9f1f to 9373495 Compare May 29, 2021 02:37
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch 4 times, most recently from 3b42a6e to 2c7b391 Compare June 15, 2021 16:46
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch 3 times, most recently from c0eaa5d to 4fc63f4 Compare August 11, 2021 01:39
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch from 4fc63f4 to a7759a9 Compare October 8, 2021 01:21
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch 2 times, most recently from 1241673 to 90b5827 Compare October 26, 2021 04:49
@renovate renovate bot force-pushed the renovate/npm-webpack-subresource-integrity-vulnerability branch from 90b5827 to 04ef3f3 Compare October 26, 2021 05:12
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant