Skip to content

chore(deps): update dependency ansi-regex to v6#376

Closed
renovate[bot] wants to merge 1 commit intomainfrom
renovate/ansi-regex-6.x
Closed

chore(deps): update dependency ansi-regex to v6#376
renovate[bot] wants to merge 1 commit intomainfrom
renovate/ansi-regex-6.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented May 11, 2024

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
ansi-regex 3.0.1 -> 6.0.1 age adoption passing confidence

Release Notes

chalk/ansi-regex (ansi-regex)

v6.0.1

Compare Source

Fixes
  • Fix ReDoS in certain cases (#​37)
    You are only really affected if you run the regex on untrusted user input in a server context, which it's very unlikely anyone is doing, since this regex is mainly used in command-line tools.

CVE-2021-3807

Thank you @​yetingli for the patch and reproduction case!

v6.0.0

Compare Source

Breaking

v5.0.1

Compare Source

Fixes (backport of 6.0.1 to v5)

This is a backport of the minor ReDos vulnerability in ansi-regex@<6.0.1, as requested in #​38.

  • Fix ReDoS in certain cases (#​37)
    You are only really affected if you run the regex on untrusted user input in a server context, which it's very unlikely anyone is doing, since this regex is mainly used in command-line tools.

CVE-2021-3807

Thank you @​yetingli for the patch and reproduction case!

v5.0.0

Compare Source

Breaking
Enhancements

v4.1.1

Compare Source

v4.1.0

Compare Source

v4.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@vercel
Copy link
Copy Markdown

vercel bot commented May 11, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

2 Ignored Deployments
Name Status Preview Comments Updated (UTC)
junat-live ⬜️ Ignored (Inspect) Visit Preview 💬 Add feedback May 11, 2024 9:02pm
storybook ⬜️ Ignored (Inspect) Visit Preview May 11, 2024 9:02pm

@renovate renovate bot changed the title chore(deps): update dependency ansi-regex to v6 chore(deps): update dependency ansi-regex to v6 - autoclosed May 11, 2024
@renovate renovate bot closed this May 11, 2024
@renovate renovate bot deleted the renovate/ansi-regex-6.x branch May 11, 2024 21:18
@renovate renovate bot changed the title chore(deps): update dependency ansi-regex to v6 - autoclosed chore(deps): update dependency ansi-regex to v6 May 11, 2024
@renovate renovate bot reopened this May 11, 2024
@renovate renovate bot restored the renovate/ansi-regex-6.x branch May 11, 2024 22:04
@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch from 88bf015 to 2ce5cfe Compare May 11, 2024 22:14
@vercel
Copy link
Copy Markdown

vercel bot commented May 11, 2024

Deployment failed with the following error:

Resource is limited - try again in 1 hour (more than 100, code: "api-deployments-free-per-day").

@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch 3 times, most recently from 30720da to 6ebe51e Compare May 11, 2024 23:54
@vercel
Copy link
Copy Markdown

vercel bot commented May 11, 2024

Deployment failed with the following error:

Resource is limited - try again in 52 minutes (more than 100, code: "api-deployments-free-per-day").

@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch from 6ebe51e to 93b46ed Compare May 12, 2024 00:11
@vercel
Copy link
Copy Markdown

vercel bot commented May 12, 2024

Deployment failed with the following error:

Resource is limited - try again in 35 minutes (more than 100, code: "api-deployments-free-per-day").

@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch from 93b46ed to f3ca6a1 Compare May 12, 2024 00:41
@vercel
Copy link
Copy Markdown

vercel bot commented May 12, 2024

Deployment failed with the following error:

Resource is limited - try again in 5 minutes (more than 100, code: "api-deployments-free-per-day").

@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch from f3ca6a1 to 9551f83 Compare May 12, 2024 02:05
@vercel
Copy link
Copy Markdown

vercel bot commented May 12, 2024

Deployment failed with the following error:

Resource is limited - try again in 12 hours (more than 100, code: "api-deployments-free-per-day").

@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch 3 times, most recently from fa4045e to 0773a1f Compare May 12, 2024 03:03
@vercel
Copy link
Copy Markdown

vercel bot commented May 12, 2024

Deployment failed with the following error:

Resource is limited - try again in 11 hours (more than 100, code: "api-deployments-free-per-day").

@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch 7 times, most recently from 321b7dc to 33f47a0 Compare May 13, 2024 06:39
@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch 4 times, most recently from 3a37ac6 to fbf5753 Compare May 14, 2024 08:22
@renovate
Copy link
Copy Markdown
Contributor Author

renovate bot commented May 14, 2024

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch 2 times, most recently from 265113b to 7789d50 Compare May 14, 2024 14:51
@renovate renovate bot force-pushed the renovate/ansi-regex-6.x branch from 7789d50 to cc3d1fd Compare May 14, 2024 19:30
@jqpe jqpe closed this May 14, 2024
@renovate
Copy link
Copy Markdown
Contributor Author

renovate bot commented May 14, 2024

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future 6.x releases. But if you manually upgrade to 6.x then Renovate will re-enable minor and patch updates automatically.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate bot deleted the renovate/ansi-regex-6.x branch May 14, 2024 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant