chore(deps): update dependency serve to v10 [security] #116
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.5.5→10.1.2GitHub Vulnerability Alerts
CVE-2018-3809
Versions of
servebefore 7.0.0 are vulnerable to information exposure, bypassing the ignore security control, but only on case insensitive file systems.Recommendation
Update to version 7.0.0 or later.
CVE-2019-5417
Versions of
servebefore 7.1.3 are vulnerable to Directory Traversal. File paths are not sanitized leading to unauthorized access of system files.Recommendation
Upgrade to version 7.1.3 or later
GHSA-xw79-hhv6-578c
Versions of
serveprior to 10.0.2 are vulnerable to Cross-Site Scripting (XSS). The package does not encode output, allowing attackers to execute arbitrary JavaScript in the victim's browser if user-supplied input is rendered.Recommendation
Upgrade to version 10.0.2 or later.
GHSA-48gc-5j93-5cfq
Versions of
serveprior to 10.1.2 are vulnerable to Path Traversal. Explicitly ignored folders can be accessed through relative paths, which allows attackers to access hidden folders and files.Recommendation
Upgrade to version 10.1.2 or later.
GHSA-cpgr-wmr9-qxv4
Versions of
serveprior to 10.0.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code.Recommendation
Upgrade to version 10.0.2 or later.
Release Notes
vercel/serve (serve)
v10.1.2Compare Source
Patches
serve-handlerto latest version: #505Credits
Huge thanks to @saintwinkle for helping!
v10.1.1Compare Source
Patches
v10.1.0Compare Source
Minor Changes
NO_UPDATE_CHECKenvironment flag: #457Patches
serve-handlerto the latest version: #488now.jsonandpackage.json: #489Credits
Huge thanks to @leeyeh for helping!
v10.0.2Compare Source
Patches
serve-handlerto the latest version: #480v10.0.1Compare Source
Patches
@zeit/schemasto the latest version: #475v10.0.0Compare Source
Major Changes
v9.6.0Compare Source
Minor Changes
v9.4.2Compare Source
Patches
v9.4.1Compare Source
Patches
v9.4.0Compare Source
Minor Changes
ETagandIf-None-Match: #456v9.3.0Compare Source
Minor Changes
Patches
Credits
Huge thanks to @az0uz and @styfle for helping!
v9.2.0Compare Source
Minor Changes
v9.1.2Compare Source
Patches
v9.1.1Compare Source
Patches
Credits
Huge thanks to @just-boris for helping!
v9.1.0Compare Source
Minor Changes
PORT: #434Credits
Huge thanks to @compulim for helping!
v9.0.0Compare Source
Major Changes
Minor Changes
Patches
publicoption: #428v8.2.0Compare Source
Minor Changes
--configfor custom paths toserve.json: #418Credits
Huge thanks to @tohjustin for helping!
v8.1.4Compare Source
Patches
/indexbeing redirected wrong: #416v8.1.3Compare Source
Patches
-pas an alias to-l: #412Credits
Huge thanks to @wawhal for helping!
v8.1.2Compare Source
Patches
v8.1.1Compare Source
Patches
Credits
Huge thanks to @iczero for helping!
v8.1.0Compare Source
Minor Changes
renderSingleand reduced stat calls: #406v8.0.0Compare Source
Major Changes
cleanUrlsstop stripping.htmextension: #403v7.2.0Compare Source
Minor Changes
Content-Dispositionheader: #397v7.1.6Compare Source
Patches
ad821bev7.1.5Compare Source
Patches
Content-Typeheader: #394v7.1.4Compare Source
Patches
README.mdis correct: #392v7.1.3Compare Source
Patches
v7.1.2Compare Source
Patches
v7.1.1Compare Source
Patches
v7.1.0Compare Source
Minor Changes
--singleand made--listensupport ports: #384Patches
serve-handlerto the latest version: #383Credits
Huge thanks to @jaeseok-park for helping!
v7.0.1Compare Source
Patches
v7.0.0Compare Source
This release marks a completely fresh start for this project.
Over the years, the core of the package has gotten bigger and bigger, eventually containing features that should not be part of it at all. This led to
servebecoming rather slow in certain situations. But not just in terms of serving requests, but also when installing (because of the dependency count).As of today, the package is going into a completely new direction and we're re-evaluating any feature suggestions we're encoutering on the repository.
If you want to continue using the old
serve, please lock it like this in your dependencies:{ "serve": "6.5.8" }Notice that the version number is not prefixed with
^.However, for those of you who would like to upgrade, there are plenty amazing things awaiting you:
serve– right out of the box: Useservefor development and Now in production.If you have any suggestions, let us know in the issue list or create a pull request to fix something! 🙏
Thank you all for using
serveand have a great day!Leo – @notquiteleo
v6.5.8Compare Source
Patches
v6.5.7Compare Source
Patches
update-checkpackage to the latest version: #362enginesfield to match readme: #366Credits
Huge thanks to @MiniGod, @sreeramjayan and @n0v1 for helping!
v6.5.6Compare Source
Patches
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.