redis-browser
redis-browser copied to clipboard
[Security] Bump redis from 2.8.0 to 3.1.1
Bumps redis from 2.8.0 to 3.1.1. This update includes a security fix.
Vulnerabilities fixed
Sourced from The GitHub Security Advisory Database.
Potential exponential regex in monitor mode
Impact
When a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service.
Patches
The problem was fixed in commit
2d11b6dand was released in version3.1.1.References
#1569 (GHSL-2021-026)
Affected versions: >= 2.6.0 < 3.1.1
Release notes
Sourced from redis's releases.
V3.1.1
Enhancements
- Upgrade node and dependencies (#1578)
Fixes
- Fix a potential exponential regex in monitor mode (#1595)
v3.1.0
Enhancements
- Upgrade node and dependencies and redis-commands to support Redis 6 (#1578)
- Add support for Redis 6
auth pass [user](#1508)v3.0.2
No release notes provided.
v3.0.0
This version is mainly a release to distribute all the unreleased changes on master since 2017 and additionally removes a lot of old deprecated features and internals in preparation for an upcoming modernization refactor (v4).
Breaking Changes
- Dropped support for Node.js < 6
- Dropped support for
hiredis(no longer required)- Removed previously deprecated
drainevent- Removed previously deprecated
idleevent- Removed previously deprecated
parseroption- Removed previously deprecated
max_delayoption- Removed previously deprecated
max_attemptsoption- Removed previously deprecated
socket_no_delayoptionBug Fixes
- Removed development files from published package (#1370)
- Duplicate function now allows db param to be passed (#1311)
Features
- Upgraded to latest
redis-commandspackage- Upgraded to latest
redis-parserpackage, v3.0.0, which brings performance improvements- Replaced
double-ended-queuewithdenque, which brings performance improvements- Add timestamps to debug traces
- Add
socket_initial_delayoption forsocket.setKeepAlive(#1396)- Add support for
redissprotocol in url (#1282)
Changelog
Sourced from redis's changelog.
Changelog
v3.0.0 - 09 Feb, 2020
This version is mainly a release to distribute all the unreleased changes on master since 2017 and additionally removes a lot of old deprecated features and old internals in preparation for an upcoming modernization refactor (v4).
Breaking Changes
- Dropped support for Node.js < 6
- Dropped support for
hiredis(no longer required)- Removed previously deprecated
drainevent- Removed previously deprecated
idleevent- Removed previously deprecated
parseroption- Removed previously deprecated
max_delayoption- Removed previously deprecated
max_attemptsoption- Removed previously deprecated
socket_no_delayoptionBug Fixes
- Removed development files from published package (#1370)
- Duplicate function now allows db param to be passed (#1311)
Features
- Upgraded to latest
redis-commandspackage- Upgraded to latest
redis-parserpackage, v3.0.0, which brings performance improvements- Replaced
double-ended-queuewithdenque, which brings performance improvements- Add timestamps to debug traces
- Add
socket_initial_delayoption forsocket.setKeepAlive(#1396)- Add support for
redissprotocol in url (#1282)
Commits
fc28860Bump version to 3.1.1 (#1597)2d11b6dfix #1569 - improve monitor_regex (#1595)7e77de8Add Chat (#1594)5d3e995Merge branch 'master' of https://github.com/NodeRedis/node-redisb797cf2add user to README.md79f34c2Bump version to 3.1.0 (#1590)7fdc54efix for 428e1c8a7b2322c2650294638cb1663ac5692728 - fix auth retry when redis ...09f0fe8"fix" tests428e1c8Add support for Redis 6auth pass [user](#1508)bb208d0Add codeclimate badge (#1572)- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by leibale, a new releaser for redis since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot dashboard:
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)