Skip to content

fix(deps): update dependency url-parse to v1.5.2 [security]#17719

Merged
jennifer-shehane merged 1 commit into
developfrom
renovate/npm-url-parse-vulnerability
Aug 13, 2021
Merged

fix(deps): update dependency url-parse to v1.5.2 [security]#17719
jennifer-shehane merged 1 commit into
developfrom
renovate/npm-url-parse-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Aug 12, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
url-parse 1.5.1 -> 1.5.2 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-3664

Overview

Affected versions of npm url-parse are vulnerable to URL Redirection to Untrusted Site.

Impact

Depending on library usage and attacker intent, impacts may include allow/block list bypasses, SSRF attacks, open redirects, or other undesired behavior.


Release Notes

unshiftio/url-parse

v1.5.2

Compare Source


Configuration

📅 Schedule: "" in timezone America/New_York.

🚦 Automerge: Disabled due to failing status checks.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate Bot requested a review from a team as a code owner August 12, 2021 18:45
@renovate renovate Bot added renovate Triggered by renovatebot type: dependencies labels Aug 12, 2021
@renovate renovate Bot requested review from flotwig and kuceb and removed request for a team August 12, 2021 18:45
@cypress-bot
Copy link
Copy Markdown
Contributor

cypress-bot Bot commented Aug 12, 2021

See the guidelines for reviewing dependency updates for info on how to review dependency update PRs.

@cypress
Copy link
Copy Markdown

cypress Bot commented Aug 12, 2021



Test summary

8366 0 100 4Flakiness 3


Run details

Project cypress
Status Passed
Commit 11f798f
Started Aug 13, 2021 3:46 PM
Ended Aug 13, 2021 3:56 PM
Duration 10:10 💡
OS Linux Debian - 10.9
Browser Multiple

View run in Cypress Dashboard ➡️


Flakiness

cypress/proxy-logging-spec.ts Flakiness
1 Proxy Logging > request logging > fetch log shows resource type, url, method, and status code and has expected snapshots and consoleProps
2 Proxy Logging > request logging > fetch log shows resource type, url, method, and status code and has expected snapshots and consoleProps
commands/net_stubbing_spec.ts Flakiness
1 network stubbing > waiting and aliasing > can timeout waiting on a single request using "alias.request"

This comment has been generated by cypress-bot as a result of this project's GitHub integration settings. You can manage this integration in this project's settings in the Cypress Dashboard

@renovate renovate Bot force-pushed the renovate/npm-url-parse-vulnerability branch from 4f39410 to 2219715 Compare August 12, 2021 19:43
@renovate renovate Bot force-pushed the renovate/npm-url-parse-vulnerability branch from 2219715 to 11f798f Compare August 12, 2021 23:43
@jennifer-shehane jennifer-shehane merged commit 3c02755 into develop Aug 13, 2021
@renovate renovate Bot deleted the renovate/npm-url-parse-vulnerability branch August 13, 2021 16:41
@cypress-bot
Copy link
Copy Markdown
Contributor

cypress-bot Bot commented Aug 16, 2021

Released in 8.3.0.

This comment thread has been locked. If you are still experiencing this issue after upgrading to
Cypress v8.3.0, please open a new issue.

@cypress-bot cypress-bot Bot locked as resolved and limited conversation to collaborators Aug 16, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

renovate Triggered by renovatebot type: dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants