-
Notifications
You must be signed in to change notification settings - Fork 1
fix(deps): update dependency jszip to v3.8.0 [security] #110
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
Kudos, SonarCloud Quality Gate passed! |
94a501b to
c8e5877
Compare
|
Kudos, SonarCloud Quality Gate passed! |
c8e5877 to
a62925c
Compare
|
Kudos, SonarCloud Quality Gate passed! |
a62925c to
b8dbc16
Compare
|
Kudos, SonarCloud Quality Gate passed! |
b08fdaa to
5ba91f5
Compare
|
5ba91f5 to
98f9706
Compare
|
98f9706 to
08110a8
Compare











This PR contains the following updates:
3.7.1->3.8.0GitHub Vulnerability Alerts
CVE-2022-48285
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
Release Notes
Stuk/jszip (jszip)
v3.8.0Compare Source
loadAsync, to avoid "zip slip" attacks. The original filename is available on each zip entry asunsafeOriginalName. See the documentation. Many thanks to McCaulay Hudson for reporting.Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.