cli-error-notifier
cli-error-notifier copied to clipboard
chore(deps-dev): bump eslint-plugin-security from 1.5.0 to 1.7.1
Bumps eslint-plugin-security from 1.5.0 to 1.7.1.
Release notes
Sourced from eslint-plugin-security's releases.
eslint-plugin-security v1.7.1
Bug Fixes
- false positives for static expressions in detect-non-literal-fs-filename, detect-child-process, detect-non-literal-regexp, and detect-non-literal-require (#109) (56102b5)
eslint-plugin-security v1.7.0
Features
eslint-plugin-security v1.6.0
Features
- Add meta object documentation for all rules (#79) (fb1d9ef)
- detect-bidi-characters rule (#95) (4294d29)
- detect-non-literal-fs-filename: change to track non-top-level
require()as well (#105) (d3b1543)- extend detect non literal fs filename (#92) (08ba476)
- non-literal-require: support template literals (#81) (208019b)
Bug Fixes
- Avoid crash when exec() is passed no arguments (7f97815), closes #82 #23
- Avoid TypeError when exec stub is used with no arguments (#97) (9c18f16)
- detect-child-process: false positive for destructuring with
exec(#102) (657921a)- detect-child-process: false positives for destructuring
spawn(#103) (fdfe37d)- Incorrect method name in detect-buffer-noassert. (313c0c6), closes #63 #80
Changelog
Sourced from eslint-plugin-security's changelog.
1.7.1 (2023-02-02)
Bug Fixes
- false positives for static expressions in detect-non-literal-fs-filename, detect-child-process, detect-non-literal-regexp, and detect-non-literal-require (#109) (56102b5)
1.7.0 (2023-01-26)
Features
1.6.0 (2023-01-11)
Features
- Add meta object documentation for all rules (#79) (fb1d9ef)
- detect-bidi-characters rule (#95) (4294d29)
- detect-non-literal-fs-filename: change to track non-top-level
require()as well (#105) (d3b1543)- extend detect non literal fs filename (#92) (08ba476)
- non-literal-require: support template literals (#81) (208019b)
Bug Fixes
- Avoid crash when exec() is passed no arguments (7f97815), closes #82 #23
- Avoid TypeError when exec stub is used with no arguments (#97) (9c18f16)
- detect-child-process: false positive for destructuring with
exec(#102) (657921a)- detect-child-process: false positives for destructuring
spawn(#103) (fdfe37d)- Incorrect method name in detect-buffer-noassert. (313c0c6), closes #63 #80
Commits
0c9c1dechore: release 1.7.1 (#114)56102b5fix: false positives for static expressions in detect-non-literal-fs-filename...75e1e9dchore: release 1.7.0 (#113)951fcc8docs: Correct typos64ae529feat: improve detect-child-process rule (#108)d699c30chore: fix repo url (#111)c54e618chore: release 1.6.0 (#107)74e5203chore: Clean up changelogd3b1543feat(detect-non-literal-fs-filename): change to track non-top-level `require(...7d482c5chore: Add release-please to automate releases- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by eslint-community-bot, a new releaser for eslint-plugin-security since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)