Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency cross-fetch to v3.1.5 [security] #54

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jan 11, 2024

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
cross-fetch 3.0.6 -> 3.1.5 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-1365

When fetching a remote url with Cookie if it get Location response header then it will follow that url and try to fetch that url with provided cookie . So cookie is leaked here to thirdparty.
Ex: you try to fetch example.com with cookie and if it get redirect url to attacker.com then it fetch that redirect url with provided cookie .


Release Notes

lquixada/cross-fetch (cross-fetch)

v3.1.5

Compare Source

What's Changed

New Contributors

Full Changelog: lquixada/cross-fetch@v3.1.4...v3.1.5

v3.1.4

Compare Source

🐞 fixed typescript errors.

v3.1.3

Compare Source

🐞 fixed typescript compilation error causing #​95, #​101, #​102.

v3.1.2

Compare Source

🐞 added missing Headers interface augmentation from lib.dom.iterable.d.ts (#​97)

v3.1.1

Compare Source

🐞 fixed missing fetch api types from constructor signatures #​96 (thanks @​jstewmon)

v3.1.0

Compare Source

⚡️ improved TypeScript support with own fetch API type definitions (thanks @​jstewmon)
⚡️ set fetch.ponyfill to true when custom ponyfill implementation is used.
💡 set the same fetch API test suite to run against node-fetch, whatwg-fetch and native fetch.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot requested a review from a team as a code owner January 11, 2024 12:41
Copy link

changeset-bot bot commented Jan 11, 2024

⚠️ No Changeset found

Latest commit: d05bcd8

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Copy link

New dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
cross-fetch 3.1.5 None +3 531 kB lquixada

@renovate renovate bot force-pushed the renovate/npm-cross-fetch-vulnerability branch from 84fcafc to 16308d4 Compare January 11, 2024 14:49
@aaronmgdr aaronmgdr self-assigned this Jan 11, 2024
@renovate renovate bot force-pushed the renovate/npm-cross-fetch-vulnerability branch 2 times, most recently from 003ed68 to 45b251b Compare January 11, 2024 18:01
@renovate renovate bot changed the title fix(deps): update dependency cross-fetch to v3.1.5 [security] fix(deps): update dependency cross-fetch to v3.1.5 [security] - autoclosed Jan 11, 2024
@renovate renovate bot closed this Jan 11, 2024
@renovate renovate bot deleted the renovate/npm-cross-fetch-vulnerability branch January 11, 2024 18:31
@renovate renovate bot changed the title fix(deps): update dependency cross-fetch to v3.1.5 [security] - autoclosed fix(deps): update dependency cross-fetch to v3.1.5 [security] Jan 12, 2024
@renovate renovate bot reopened this Jan 12, 2024
@renovate renovate bot force-pushed the renovate/npm-cross-fetch-vulnerability branch from abe7f42 to 45b251b Compare January 12, 2024 10:48
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot force-pushed the renovate/npm-cross-fetch-vulnerability branch from 45b251b to d05bcd8 Compare January 12, 2024 10:48
@aaronmgdr
Copy link
Member

Ignore

@aaronmgdr aaronmgdr closed this Jan 12, 2024
Copy link
Contributor Author

renovate bot commented Jan 12, 2024

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (3.1.5). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant