croodle
croodle copied to clipboard
Update dependency codeception/codeception to v3.1.3 [SECURITY]
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| codeception/codeception (source) | require-dev | patch | 3.1.2 -> 3.1.3 |
GitHub Vulnerability Alerts
CVE-2021-23420
This affects the package codeception/codeception from 4.0.0 before 4.1.22 and before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.
Release Notes
Codeception/Codeception
v3.1.3
- Security fix: Disable deserialization of RunProcess class (#6241) reported by @snoopysecurity
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- [ ] If you want to rebase/retry this PR, click this checkbox.
This PR has been generated by Mend Renovate. View repository job log here.
⚠ Artifact update problem
Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.
♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
- any of the package files in this branch needs updating, or
- the branch becomes conflicted, or
- you click the rebase/retry checkbox if found above, or
- you rename this PR's title to start with "rebase!" to trigger it manually
The artifact failure details are included below:
File name: api/composer.lock
Command failed: docker run --rm --name=renovate_php --label=renovate_child -v "/mnt/renovate/gh/jelhan/croodle":"/mnt/renovate/gh/jelhan/croodle" -v "/tmp/renovate-cache":"/tmp/renovate-cache" -v "/tmp/containerbase":"/tmp/containerbase" -e COMPOSER_CACHE_DIR -e BUILDPACK_CACHE_DIR -w "/mnt/renovate/gh/jelhan/croodle/api" docker.io/renovate/php:7.2.0 bash -l -c "install-tool composer 2.4.2 && composer update codeception/codeception --with-dependencies --ignore-platform-reqs --no-ansi --no-interaction --no-scripts --no-autoloader --no-plugins"
⚠ Artifact update problem
Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.
♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
- any of the package files in this branch needs updating, or
- the branch becomes conflicted, or
- you click the rebase/retry checkbox if found above, or
- you rename this PR's title to start with "rebase!" to trigger it manually
The artifact failure details are included below:
File name: api/composer.lock
Command failed: docker run --rm --name=renovate_a_sidecar --label=renovate_a_child -v "/tmp/worker/69104a/47fed2/repos/github/jelhan/croodle":"/tmp/worker/69104a/47fed2/repos/github/jelhan/croodle" -v "/tmp/worker/69104a/47fed2/cache":"/tmp/worker/69104a/47fed2/cache" -e COMPOSER_CACHE_DIR -e COMPOSER_AUTH -e CONTAINERBASE_CACHE_DIR -w "/tmp/worker/69104a/47fed2/repos/github/jelhan/croodle/api" ghcr.io/containerbase/sidecar:9.2.1 bash -l -c "install-tool php 7.2.0 && install-tool composer 2.5.8 && composer update codeception/codeception --with-dependencies --ignore-platform-req='ext-*' --ignore-platform-req='lib-*' --no-ansi --no-interaction --no-scripts --no-autoloader --no-plugins"
/usr/local/bin/docker: line 4: .: filename argument required
.: usage: . filename [arguments]