Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Mar 16, 2023

Mend Renovate

This PR contains the following updates:

Package Change
decode-uri-component 0.2.0 -> 0.2.1

GitHub Vulnerability Alerts

CVE-2022-38900

decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.


Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Tokyo, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the deps Pull requests that update a dependency file label Mar 16, 2023
@renovate renovate bot changed the title chore(deps): update dependency decode-uri-component to 0.2.1 [security] chore(deps): update dependency decode-uri-component to 0.2.1 [security] - autoclosed Mar 23, 2023
@renovate renovate bot closed this Mar 23, 2023
@renovate renovate bot deleted the renovate/npm-decode-uri-component-vulnerability branch March 23, 2023 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deps Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants