charlescd
charlescd copied to clipboard
Update dependency ejs to 3.1.7 [SECURITY]
This PR contains the following updates:
| Package | Change |
|---|---|
| ejs | 2.7.4 -> 3.1.7 |
GitHub Vulnerability Alerts
CVE-2022-29078
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- [ ] If you want to rebase/retry this PR, click this checkbox.
This PR has been generated by Mend Renovate. View repository job log here.
⚠ Artifact update problem
Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.
♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
- any of the package files in this branch needs updating, or
- the branch becomes conflicted, or
- you click the rebase/retry checkbox if found above, or
- you rename this PR's title to start with "rebase!" to trigger it manually
The artifact failure details are included below:
File name: ui/package-lock.json
npm ERR! code ERESOLVE
npm ERR! ERESOLVE could not resolve
npm ERR!
npm ERR! While resolving: @casl/[email protected]
npm ERR! Found: [email protected]
npm ERR! node_modules/react
npm ERR! react@"^17.0.1" from the root project
npm ERR! peer react@">=16.3.0" from @emotion/[email protected]
npm ERR! node_modules/@emotion/core
npm ERR! peer @emotion/core@"^10.0.27" from @emotion/[email protected]
npm ERR! node_modules/@emotion/styled
npm ERR! @emotion/styled@"^10.0.27" from @storybook/[email protected]
npm ERR! node_modules/@storybook/theming
npm ERR! @storybook/theming@"6.3.4" from @storybook/[email protected]
npm ERR! node_modules/@storybook/addon-actions
npm ERR! 12 more (@storybook/addon-backgrounds, ...)
npm ERR! peer @emotion/core@"^10.0.28" from @emotion/[email protected]
npm ERR! node_modules/@emotion/styled-base
npm ERR! @emotion/styled-base@"^10.0.27" from @emotion/[email protected]
npm ERR! node_modules/@emotion/styled
npm ERR! @emotion/styled@"^10.0.27" from @storybook/[email protected]
npm ERR! node_modules/@storybook/theming
npm ERR! 4 more (@storybook/theming, @storybook/ui, emotion-theming, react-select)
npm ERR! 66 more (@emotion/styled, @emotion/styled-base, @mdx-js/react, ...)
npm ERR!
npm ERR! Could not resolve dependency:
npm ERR! peer react@"^15.0.0 || ^16.0.0" from @casl/[email protected]
npm ERR! node_modules/@casl/react
npm ERR! @casl/react@"2.1.0" from the root project
npm ERR!
npm ERR! Conflicting peer dependency: [email protected]
npm ERR! node_modules/react
npm ERR! peer react@"^15.0.0 || ^16.0.0" from @casl/[email protected]
npm ERR! node_modules/@casl/react
npm ERR! @casl/react@"2.1.0" from the root project
npm ERR!
npm ERR! Fix the upstream dependency conflict, or retry
npm ERR! this command with --force, or --legacy-peer-deps
npm ERR! to accept an incorrect (and potentially broken) dependency resolution.
npm ERR!
npm ERR! See /tmp/renovate-cache/others/npm/eresolve-report.txt for a full report.
npm ERR! A complete log of this run can be found in:
npm ERR! /tmp/renovate-cache/others/npm/_logs/2022-05-16T22_40_14_321Z-debug-0.log