Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency serialize-javascript to v6.0.2 [security] #1922

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 18, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
serialize-javascript 6.0.0 -> 6.0.2 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-11831

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.


Release Notes

yahoo/serialize-javascript (serialize-javascript)

v6.0.2

Compare Source

v6.0.1

Compare Source

What's Changed

New Contributors

Full Changelog: yahoo/serialize-javascript@v6.0.0...v6.0.1


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link

changeset-bot bot commented Feb 18, 2025

⚠️ No Changeset found

Latest commit: e84a7ea

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Copy link

codecov bot commented Feb 18, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 94.65%. Comparing base (4417a9b) to head (75350d8).

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #1922   +/-   ##
=======================================
  Coverage   94.65%   94.65%           
=======================================
  Files         148      148           
  Lines        5105     5105           
  Branches     1380     1380           
=======================================
  Hits         4832     4832           
  Misses        270      270           
  Partials        3        3           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@renovate renovate bot force-pushed the renovate/npm-serialize-javascript-vulnerability branch 2 times, most recently from 4048cac to 4a9bfc0 Compare February 27, 2025 09:24
@renovate renovate bot force-pushed the renovate/npm-serialize-javascript-vulnerability branch 4 times, most recently from 75350d8 to a09ed34 Compare March 7, 2025 13:23
@renovate renovate bot force-pushed the renovate/npm-serialize-javascript-vulnerability branch from a09ed34 to e84a7ea Compare March 7, 2025 13:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants