Skip to content

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Aug 8, 2024

This PR contains the following updates:

Package Change Age Confidence
serialize-to-js ^1.2.2 -> ^3.0.1 age confidence

GitHub Vulnerability Alerts

CVE-2019-16772

Versions of serialize-to-js prior to 3.0.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize serialized regular expressions. This vulnerability does not affect Node.js applications.

Recommendation

Upgrade to version 3.0.1 or later.

GHSA-w5q7-3pr9-x44w

Versions of serialize-to-js prior to 2.0.0 are vulnerable to Denial of Service. User input is not properly validated, allowing attackers to provide inputs that lead the execution to loop indefinitely.

Recommendation

Upgrade to version 2.0.0 or later.


Release Notes

commenthol/serialize-to-js (serialize-to-js)

v3.0.1

Compare Source

v3.0.0

Compare Source

v2.0.1

Compare Source

v2.0.0

Compare Source

Breaking changes:

  • removal of deserialize function as being vulnerable to DOS

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from 8c55395 to 093ff4f Compare October 12, 2024 05:37
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from d661977 to ac7a29b Compare October 31, 2024 05:37
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 3 times, most recently from c9b452f to 8ac2a0f Compare December 11, 2024 05:34
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from dfa0ff7 to 998d41c Compare December 18, 2024 05:57
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 3 times, most recently from 65b4a17 to 265ace1 Compare December 24, 2024 20:50
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from eb65263 to e1b6062 Compare January 17, 2025 07:14
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 3 times, most recently from e728b93 to 6958b1c Compare January 31, 2025 16:10
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch from 6958b1c to 0c842fb Compare February 2, 2025 07:10
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from 05f6ed9 to 1e1e223 Compare February 15, 2025 11:24
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from af60f94 to b32638a Compare March 7, 2025 19:52
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 3 times, most recently from 13541e7 to f2fe04c Compare March 19, 2025 03:56
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch from f2fe04c to 3513573 Compare March 22, 2025 00:10
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from 41de302 to ea8769d Compare April 3, 2025 23:59
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from 6f8696c to f33c89c Compare April 13, 2025 11:39
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from 9bfb8a7 to d83f153 Compare April 29, 2025 04:03
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from 976f2e0 to 532fe79 Compare May 10, 2025 19:43
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from 1ca7df7 to 1ff91d2 Compare May 18, 2025 08:07
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 3 times, most recently from d9c2212 to 429f1b7 Compare May 31, 2025 07:39
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 3 times, most recently from ebd1f59 to 4ccb293 Compare June 8, 2025 11:09
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch from 4ccb293 to e2d8928 Compare June 22, 2025 23:55
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch from e2d8928 to 0189a10 Compare July 13, 2025 11:47
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from 950e6ce to a8cf15a Compare August 16, 2025 11:37
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch 2 times, most recently from 49b6a8d to 871d291 Compare August 24, 2025 19:40
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch from 871d291 to cdb167d Compare September 1, 2025 06:32
@renovate renovate bot force-pushed the renovate/npm-serialize-to-js-vulnerability branch from cdb167d to a81a17b Compare September 2, 2025 18:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants