d573358 [Security] Bump extend from 3.0.1 to 3.0.2
📊 Changes
1 file changed (+3 additions, -3 deletions)
View changed files
📝yarn.lock (+3 -3)
📄 Description
Bumps extend from 3.0.1 to 3.0.2. This update includes security fixes.
Vulnerabilities fixed
Sourced from The GitHub Security Advisory Database.
Low severity vulnerability that affects extend
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
@dependabot use these labels will set the current labels as the default for future PRs for this repo and language
@dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
@dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
@dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
@dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot dashboard:
Update frequency (including time of day and day of week)
Automerge options (never/patch/minor, and dev/runtime dependencies)
Pull request limits (per update run and/or open at any time)
Out-of-range updates (receive only lockfile updates, if desired)
Security updates (receive only security updates, if desired)
Finally, you can contact us by mentioning @dependabot.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.
## 📋 Pull Request Information
**Original PR:** https://github.com/sobolevn/awesome-cryptography/pull/84
**Author:** [@dependabot-preview[bot]](https://github.com/apps/dependabot-preview)
**Created:** 6/27/2019
**Status:** ✅ Merged
**Merged:** 7/16/2019
**Merged by:** [@sobolevn](https://github.com/sobolevn)
**Base:** `master` ← **Head:** `dependabot/npm_and_yarn/extend-3.0.2`
---
### 📝 Commits (1)
- [`d573358`](https://github.com/sobolevn/awesome-cryptography/commit/d5733588d4e054178d437ae73a120e6b411cf002) [Security] Bump extend from 3.0.1 to 3.0.2
### 📊 Changes
**1 file changed** (+3 additions, -3 deletions)
<details>
<summary>View changed files</summary>
📝 `yarn.lock` (+3 -3)
</details>
### 📄 Description
Bumps [extend](https://github.com/justmoon/node-extend) from 3.0.1 to 3.0.2. **This update includes security fixes.**
<details>
<summary>Vulnerabilities fixed</summary>
*Sourced from The GitHub Security Advisory Database.*
> **Low severity vulnerability that affects extend**
> A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
>
> Affected versions: >= 3.0.0 < 3.0.2
</details>
<details>
<summary>Changelog</summary>
*Sourced from [extend's changelog](https://github.com/justmoon/node-extend/blob/master/CHANGELOG.md).*
> 3.0.2 / 2018-07-19
> ==================
> * [Fix] Prevent merging `__proto__` property ([#48](https://github-redirect.dependabot.com/justmoon/node-extend/issues/48))
> * [Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`
> * [Tests] up to `node` `v10.7`, `v9.11`, `v8.11`, `v7.10`, `v6.14`, `v4.9`; use `nvm install-latest-npm`
</details>
<details>
<summary>Commits</summary>
- [`8d106d2`](https://github.com/justmoon/node-extend/commit/8d106d23931c0802e8b88188b0aac433e13358d9) v3.0.2
- [`e97091f`](https://github.com/justmoon/node-extend/commit/e97091fa7557e106042e475ef59e654fa9d2c7ab) [Dev Deps] update `tape`
- [`e841aac`](https://github.com/justmoon/node-extend/commit/e841aac7ce7119606345b440b0a9e7668e848985) [Tests] up to `node` `v10.7`
- [`0e68e71`](https://github.com/justmoon/node-extend/commit/0e68e71d93507fcc391e398bc84abd0666b28190) [Fix] Prevent merging __proto__ property
- [`a689700`](https://github.com/justmoon/node-extend/commit/a689700740b44846e76f8f1dc4bdf230a2cb5c0d) Only apps should have lockfiles
- [`f13c1c4`](https://github.com/justmoon/node-extend/commit/f13c1c4e51c47b90604eb2dc56cc60561e497d36) [Dev Deps] update `eslint`, `@ljharb/eslint-config`, `tape`
- [`f3570fe`](https://github.com/justmoon/node-extend/commit/f3570fe5582dbfba47e60c0cd75b4fb6f01cd3fe) [Tests] up to `node` `v10.0`, `v9.11`, `v8.11`, `v7.10`, `v6.14`, `v4.9`; use...
- See full diff in [compare view](https://github.com/justmoon/node-extend/compare/v3.0.1...v3.0.2)
</details>
<br />
[](https://dependabot.com/compatibility-score.html?dependency-name=extend&package-manager=npm_and_yarn&previous-version=3.0.1&new-version=3.0.2)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Pull request limits (per update run and/or open at any time)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)
Finally, you can contact us by mentioning @dependabot.
</details>
---
<sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
📋 Pull Request Information
Original PR: https://github.com/sobolevn/awesome-cryptography/pull/84
Author: @dependabot-preview[bot]
Created: 6/27/2019
Status: ✅ Merged
Merged: 7/16/2019
Merged by: @sobolevn
Base:
master← Head:dependabot/npm_and_yarn/extend-3.0.2📝 Commits (1)
d573358[Security] Bump extend from 3.0.1 to 3.0.2📊 Changes
1 file changed (+3 additions, -3 deletions)
View changed files
📝
yarn.lock(+3 -3)📄 Description
Bumps extend from 3.0.1 to 3.0.2. This update includes security fixes.
Vulnerabilities fixed
Sourced from The GitHub Security Advisory Database.
Changelog
Sourced from extend's changelog.
Commits
8d106d2v3.0.2e97091f[Dev Deps] updatetapee841aac[Tests] up tonodev10.70e68e71[Fix] Prevent merging proto propertya689700Only apps should have lockfilesf13c1c4[Dev Deps] updateeslint,@ljharb/eslint-config,tapef3570fe[Tests] up tonodev10.0,v9.11,v8.11,v7.10,v6.14,v4.9; use...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot ignore this [patch|minor|major] versionwill close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readmeAdditionally, you can set the following in your Dependabot dashboard:
Finally, you can contact us by mentioning @dependabot.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.