chore(deps): update dependency ansi-regex to v6#376
chore(deps): update dependency ansi-regex to v6#376renovate[bot] wants to merge 1 commit intomainfrom
Conversation
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎ 2 Ignored Deployments
|
88bf015 to
2ce5cfe
Compare
|
Deployment failed with the following error: |
30720da to
6ebe51e
Compare
|
Deployment failed with the following error: |
6ebe51e to
93b46ed
Compare
|
Deployment failed with the following error: |
93b46ed to
f3ca6a1
Compare
|
Deployment failed with the following error: |
f3ca6a1 to
9551f83
Compare
|
Deployment failed with the following error: |
fa4045e to
0773a1f
Compare
|
Deployment failed with the following error: |
321b7dc to
33f47a0
Compare
3a37ac6 to
fbf5753
Compare
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
265113b to
7789d50
Compare
7789d50 to
cc3d1fd
Compare
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
This PR contains the following updates:
3.0.1->6.0.1Release Notes
chalk/ansi-regex (ansi-regex)
v6.0.1Compare Source
Fixes
You are only really affected if you run the regex on untrusted user input in a server context, which it's very unlikely anyone is doing, since this regex is mainly used in command-line tools.
CVE-2021-3807
Thank you @yetingli for the patch and reproduction case!
v6.0.0Compare Source
Breaking
1b337adv5.0.1Compare Source
Fixes (backport of
6.0.1to v5)This is a backport of the minor ReDos vulnerability in
ansi-regex@<6.0.1, as requested in #38.You are only really affected if you run the regex on untrusted user input in a server context, which it's very unlikely anyone is doing, since this regex is mainly used in command-line tools.
CVE-2021-3807
Thank you @yetingli for the patch and reproduction case!
v5.0.0Compare Source
Breaking
166a0d5Enhancements
e77ea17v4.1.1Compare Source
v4.1.0Compare Source
96200bbv4.0.0Compare Source
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.