Skip to content
This repository has been archived by the owner on Nov 23, 2021. It is now read-only.

fix(deps): update dependency grunt to v1.3.0 [security] #33

Merged
merged 1 commit into from Sep 23, 2021

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented May 6, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
grunt (source) 1.0.4 -> 1.3.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2020-7729

The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.


Release Notes

gruntjs/grunt

v1.3.0

Compare Source

  • Merge pull request #​1720 from gruntjs/update-changelog-deps faab6be
  • Update Changelog and legacy-util dependency 520fedb
  • Merge pull request #​1719 from gruntjs/yaml-refactor 7e669ac
  • Switch to use safeLoad for loading YML files via file.readYAML. e350cea
  • Merge pull request #​1718 from gruntjs/legacy-log-bumo 7125f49
  • Bump legacy-log 00d5907

v1.2.1

Compare Source

v1.2.0

Compare Source

v1.1.0

Compare Source

  • Update to mkdirp ~1.0.3
  • Only support versions of Node >= 8

Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch 30 times, most recently from f56a5d0 to 96c9ab1 Compare September 23, 2021 11:56
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch 3 times, most recently from 8009af4 to ef05dbe Compare September 23, 2021 13:35
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch from ef05dbe to 3679b7e Compare September 23, 2021 13:38
@renovate renovate bot merged commit 597d74f into master Sep 23, 2021
@renovate renovate bot deleted the renovate/npm-grunt-vulnerability branch September 23, 2021 13:39
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant