-
Notifications
You must be signed in to change notification settings - Fork 63
chore(deps): update dependency node-fetch to v2.6.7 [security] #489
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
c7ea4fc to
aeddfa7
Compare
⚠ Artifact update problemRenovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below: File name: .build/package-lock.json |
aeddfa7 to
c6ff88e
Compare
|
This PR contains the following updates:
2.6.1->2.6.7GitHub Vulnerability Alerts
CVE-2022-0235
node-fetch forwards secure headers such as
authorization,www-authenticate,cookie, &cookie2when redirecting to a untrusted site.Release Notes
node-fetch/node-fetch (node-fetch)
v2.6.7Compare Source
Security patch release
Recommended to upgrade, to not leak sensitive cookie and authentication header information to 3th party host while a redirect occurred
What's Changed
Full Changelog: node-fetch/node-fetch@v2.6.6...v2.6.7
v2.6.6Compare Source
What's Changed
Full Changelog: node-fetch/node-fetch@v2.6.5...v2.6.6
v2.6.5Compare Source
v2.6.4Compare Source
v2.6.3Compare Source
v2.6.2Compare Source
fixed main path in package.json
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.