Skip to content

Conversation

@renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented May 28, 2024

This PR contains the following updates:

Package Change Age Confidence
pug (source) 3.0.23.0.3 age confidence

GitHub Vulnerability Alerts

CVE-2024-36361

Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileClient, or compileClientWithDependenciesTracked function. NOTE: these functions are for compiling Pug templates into JavaScript, and there would typically be no reason to allow untrusted callers.


Release Notes

pugjs/pug (pug)

v3.0.3

Compare Source

Bug Fixes

  • Update pug-code-gen with the following fix: (#​3438)

    Validate templateName and globals are valid JavaScript identifiers to prevent possible remote code execution if un-trusted user input is passed to the compilation options


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot force-pushed the renovate/npm-pug-vulnerability branch from 4847b2c to fcc32cb Compare August 10, 2025 16:04
@renovate-bot renovate-bot force-pushed the renovate/npm-pug-vulnerability branch from fcc32cb to 6891da0 Compare August 19, 2025 12:29
@renovate-bot renovate-bot force-pushed the renovate/npm-pug-vulnerability branch from 6891da0 to 32ffbc3 Compare September 25, 2025 17:56
@renovate-bot renovate-bot force-pushed the renovate/npm-pug-vulnerability branch from 32ffbc3 to 2f24a02 Compare October 21, 2025 20:45
@renovate-bot renovate-bot force-pushed the renovate/npm-pug-vulnerability branch from 2f24a02 to 7f6a89d Compare November 11, 2025 02:57
@renovate-bot renovate-bot force-pushed the renovate/npm-pug-vulnerability branch from 7f6a89d to 6d44652 Compare November 18, 2025 23:13
@renovate-bot renovate-bot force-pushed the renovate/npm-pug-vulnerability branch from 6d44652 to 59aee13 Compare December 31, 2025 12:33
@renovate-bot renovate-bot force-pushed the renovate/npm-pug-vulnerability branch from 59aee13 to 9ae07da Compare December 31, 2025 21:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant