Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci(deps): Update dependency grunt to v1 [SECURITY] #25

Merged
merged 1 commit into from Aug 16, 2021

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 6, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
grunt (source) ~0.4.5 -> ~1.3.0 age adoption passing confidence

⚠️ MAJOR MAJOR MAJOR ⚠️

GitHub Vulnerability Alerts

CVE-2020-7729

The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.


Release Notes

gruntjs/grunt

v1.3.0

Compare Source

  • Merge pull request #​1720 from gruntjs/update-changelog-deps faab6be
  • Update Changelog and legacy-util dependency 520fedb
  • Merge pull request #​1719 from gruntjs/yaml-refactor 7e669ac
  • Switch to use safeLoad for loading YML files via file.readYAML. e350cea
  • Merge pull request #​1718 from gruntjs/legacy-log-bumo 7125f49
  • Bump legacy-log 00d5907

v1.2.1

Compare Source

v1.2.0

Compare Source

v1.1.0

Compare Source

  • Update to mkdirp ~1.0.3
  • Only support versions of Node >= 8

v1.0.4

Compare Source

v1.0.3

Compare Source

v1.0.2

Compare Source

v1.0.1

Compare Source

v1.0.0

Compare Source


Configuration

📅 Schedule: "" in timezone America/Lima.

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot added the dependencies label May 6, 2021
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch 5 times, most recently from 36d7448 to ecb4c1f Compare May 8, 2021 15:59
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch 6 times, most recently from 0245514 to 42a5268 Compare May 22, 2021 13:42
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch 10 times, most recently from c68121b to 3a996ee Compare June 1, 2021 20:19
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch 4 times, most recently from b7b5042 to 0a9eeab Compare June 7, 2021 12:37
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch 4 times, most recently from f895635 to f45d1d3 Compare June 14, 2021 10:03
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch 8 times, most recently from ba621ff to 50a5148 Compare June 21, 2021 11:43
@renovate renovate bot changed the title ci(deps): Update dependency grunt to v1 [SECURITY] ci(deps): Update dependency grunt to v1 [SECURITY] - autoclosed Aug 15, 2021
@renovate renovate bot closed this Aug 15, 2021
@renovate renovate bot deleted the renovate/npm-grunt-vulnerability branch August 15, 2021 18:59
@renovate renovate bot changed the title ci(deps): Update dependency grunt to v1 [SECURITY] - autoclosed ci(deps): Update dependency grunt to v1 [SECURITY] Aug 15, 2021
@renovate renovate bot restored the renovate/npm-grunt-vulnerability branch August 15, 2021 19:50
@renovate renovate bot reopened this Aug 15, 2021
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch 2 times, most recently from 2ef5319 to 69ded61 Compare August 15, 2021 21:58
@renovate renovate bot force-pushed the renovate/npm-grunt-vulnerability branch from 69ded61 to bb421b1 Compare August 15, 2021 23:07
@renovate renovate bot merged commit 814241a into develop Aug 16, 2021
@renovate renovate bot deleted the renovate/npm-grunt-vulnerability branch August 16, 2021 00:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant