quilt icon indicating copy to clipboard operation
quilt copied to clipboard

Update dependency semver-regex to 3.1.4 [SECURITY]

Open renovate[bot] opened this issue 2 years ago • 1 comments

Mend Renovate

This PR contains the following updates:

Package Change
semver-regex 3.1.2 -> 3.1.4

GitHub Vulnerability Alerts

CVE-2021-3795

npm semver-regex is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-43307

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • [ ] If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by Mend Renovate. View repository job log here.

renovate[bot] avatar Feb 09 '22 09:02 renovate[bot]

Codecov Report

Merging #2674 (f9c3823) into master (bda772c) will decrease coverage by 4.99%. The diff coverage is n/a.

@@            Coverage Diff             @@
##           master    #2674      +/-   ##
==========================================
- Coverage   41.36%   36.38%   -4.99%     
==========================================
  Files         536      708     +172     
  Lines       24751    37998   +13247     
  Branches     3380     6275    +2895     
==========================================
+ Hits        10239    13826    +3587     
- Misses      13739    22580    +8841     
- Partials      773     1592     +819     
Flag Coverage Δ
api-python 91.94% <ø> (+1.34%) :arrow_up:
catalog 11.15% <ø> (-2.06%) :arrow_down:
lambda 88.10% <ø> (+0.04%) :arrow_up:

Flags with carried forward coverage won't be shown. Click here to find out more.

Impacted Files Coverage Δ
catalog/app/components/Intercom/index.js 50.00% <0.00%> (-50.00%) :arrow_down:
catalog/app/components/Code/Code.tsx 36.36% <0.00%> (-30.31%) :arrow_down:
catalog/app/components/Footer/Footer.js 32.39% <0.00%> (-28.14%) :arrow_down:
catalog/app/components/Layout/Layout.tsx 30.00% <0.00%> (-23.34%) :arrow_down:
catalog/app/components/Logo/index.tsx 78.12% <0.00%> (-21.88%) :arrow_down:
catalog/app/containers/Auth/actions.js 68.18% <0.00%> (-20.06%) :arrow_down:
catalog/app/components/Preview/loaders/Text.js 37.14% <0.00%> (-19.38%) :arrow_down:
catalog/app/utils/string.js 78.78% <0.00%> (-13.81%) :arrow_down:
catalog/app/containers/Auth/SignUp.js 15.85% <0.00%> (-10.41%) :arrow_down:
catalog/app/containers/NavBar/NavBar.tsx 10.50% <0.00%> (-9.63%) :arrow_down:
... and 357 more

:mega: We’re building smart automated test selection to slash your CI/CD build times. Learn more

codecov[bot] avatar Feb 09 '22 09:02 codecov[bot]

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

renovate[bot] avatar Mar 21 '23 11:03 renovate[bot]