-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update dependency websocket-extensions to 0.1.4 [security] #464
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-websocket-extensions-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
3 times, most recently
from
March 23, 2021 17:28
173e928
to
b472a9b
Compare
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
2 times, most recently
from
April 15, 2021 19:01
523cdff
to
aebac00
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
April 16, 2021 18:15
aebac00
to
9ff666e
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
April 16, 2021 19:16
9ff666e
to
87c4a40
Compare
|
renovate
bot
changed the title
chore(deps): update dependency websocket-extensions to 0.1.4 [security]
chore(deps): update dependency websocket-extensions to 0.1.4 [security] - autoclosed
May 26, 2021
renovate
bot
changed the title
chore(deps): update dependency websocket-extensions to 0.1.4 [security] - autoclosed
chore(deps): update dependency websocket-extensions to 0.1.4 [security]
May 26, 2021
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
May 27, 2021 00:02
87c4a40
to
342ecc2
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
June 4, 2021 23:33
342ecc2
to
419c36f
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
June 9, 2021 01:58
419c36f
to
b707380
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
June 10, 2021 20:11
b707380
to
f6cbc6b
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
June 22, 2021 18:13
f6cbc6b
to
4ac0a4e
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
June 28, 2021 18:50
4ac0a4e
to
6ee386a
Compare
|
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
July 14, 2021 22:00
5637ce3
to
2acbc48
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
July 15, 2021 00:05
2acbc48
to
a6717f7
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
July 20, 2021 17:33
a6717f7
to
6b45338
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
July 21, 2021 17:47
6b45338
to
4d3a457
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
September 9, 2021 22:15
4d3a457
to
382e774
Compare
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
September 21, 2021 23:34
382e774
to
d1acfb0
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
October 13, 2021 23:56
d1acfb0
to
27b6296
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
October 19, 2021 08:57
27b6296
to
3210b15
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
October 22, 2021 01:41
3210b15
to
536dc0a
Compare
|
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
March 8, 2022 01:29
536dc0a
to
143c073
Compare
⚠ Artifact update problemRenovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below: File name: package-lock.json
|
|
renovate
bot
changed the title
chore(deps): update dependency websocket-extensions to 0.1.4 [security]
chore(deps): update dependency websocket-extensions to 0.1.4 [security] - autoclosed
Mar 12, 2022
renovate
bot
deleted the
renovate/npm-websocket-extensions-vulnerability
branch
March 12, 2022 00:43
renovate
bot
changed the title
chore(deps): update dependency websocket-extensions to 0.1.4 [security] - autoclosed
chore(deps): update dependency websocket-extensions to 0.1.4 [security]
Mar 16, 2022
renovate
bot
restored the
renovate/npm-websocket-extensions-vulnerability
branch
March 16, 2022 02:23
renovate
bot
force-pushed
the
renovate/npm-websocket-extensions-vulnerability
branch
from
April 12, 2022 01:21
143c073
to
e90af4a
Compare
|
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.1.3
->0.1.4
GitHub Vulnerability Alerts
CVE-2020-7662
Impact
The ReDoS flaw allows an attacker to exhaust the server's capacity to process
incoming requests by sending a WebSocket handshake request containing a header
of the following form:
That is, a header containing an unclosed string parameter value whose content is
a repeating two-byte sequence of a backslash and some other character. The
parser takes exponential time to reject this header as invalid, and this will
block the processing of any other work on the same thread. Thus if you are
running a single-threaded server, such a request can render your service
completely unavailable.
Patches
Users should upgrade to version 0.1.4.
Workarounds
There are no known work-arounds other than disabling any public-facing
WebSocket functionality you are operating.
References
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.