react-ssr-advanced-seed icon indicating copy to clipboard operation
react-ssr-advanced-seed copied to clipboard

chore(deps): update dependency got to 11.8.5 [security]

Open renovate[bot] opened this issue 2 years ago • 2 comments

Mend Renovate

This PR contains the following updates:

Package Change
got 11.6.0 -> 11.8.5

GitHub Vulnerability Alerts

CVE-2022-33987

The got package before 11.8.5 and 12.1.0 for Node.js allows a redirect to a UNIX socket.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • [ ] If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by Mend Renovate. View repository job log here.

renovate[bot] avatar Sep 25 '22 18:09 renovate[bot]

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json
ERR! lerna Unknown command "info"
ERR! lerna Did you mean init?
npm WARN [email protected] No repository field.

lerna notice cli v3.18.4
lerna info versioning independent
lerna notice filter excluding "__tests__"
lerna info filter [ '!__tests__' ]
lerna info Bootstrapping 27 packages
lerna info Installing external dependencies
lerna ERR! npm install --ignore-scripts --no-package-lock --ignore-scripts --no-audit --package-lock-only exited 1 in 'omega-web'
lerna ERR! npm install --ignore-scripts --no-package-lock --ignore-scripts --no-audit --package-lock-only stderr:
npm ERR! code ERESOLVE
npm ERR! ERESOLVE could not resolve
npm ERR! 
npm ERR! While resolving: [email protected]
npm ERR! Found: [email protected]
npm ERR! node_modules/react
npm ERR!   peer react@"^16.8.0" from @material-ui/[email protected]
npm ERR!   node_modules/@material-ui/core
npm ERR!     @material-ui/core@"4.4.2" from the root project
npm ERR!     peer @material-ui/core@"^4.0.0" from @material-ui/[email protected]
npm ERR!     node_modules/@material-ui/icons
npm ERR!       @material-ui/icons@"4.4.1" from the root project
npm ERR!   peer react@"^16.0.0" from [email protected]
npm ERR!   node_modules/react-dom
npm ERR!     react-dom@"16.8.6" from the root project
npm ERR!     peer react-dom@"^16.8.0" from @material-ui/[email protected]
npm ERR!     node_modules/@material-ui/core
npm ERR!       @material-ui/core@"4.4.2" from the root project
npm ERR!       1 more (@material-ui/icons)
npm ERR!     2 more (@material-ui/icons, @material-ui/styles)
npm ERR!   2 more (@material-ui/icons, @material-ui/styles)
npm ERR! 
npm ERR! Could not resolve dependency:
npm ERR! react-fade-in@"0.1.6" from the root project
npm ERR! 
npm ERR! Conflicting peer dependency: [email protected]
npm ERR! node_modules/react
npm ERR!   peer react@"^15.4.1" from [email protected]
npm ERR!   node_modules/react-fade-in
npm ERR!     react-fade-in@"0.1.6" from the root project
npm ERR! 
npm ERR! Fix the upstream dependency conflict, or retry
npm ERR! this command with --force, or --legacy-peer-deps
npm ERR! to accept an incorrect (and potentially broken) dependency resolution.
npm ERR! 
npm ERR! See /tmp/renovate-cache/others/npm/eresolve-report.txt for a full report.

npm ERR! A complete log of this run can be found in:
npm ERR!     /tmp/renovate-cache/others/npm/_logs/2022-09-25T18_41_36_421Z-debug-0.log

lerna ERR! npm install --ignore-scripts --no-package-lock --ignore-scripts --no-audit --package-lock-only exited 1 in 'omega-web'

renovate[bot] avatar Sep 25 '22 18:09 renovate[bot]

:warning: We detected 35 security issues in this pull request:

Vulnerable Libraries (35)
Severity Details
High @lerna/[email protected] (t) upgrade to: >3.21.0
High @lerna/[email protected] (t) upgrade to: >3.21.0
High @lerna/[email protected] (t) upgrade to: >3.21.0
High @lerna/[email protected] (t) upgrade to: >3.21.0
High @lerna/[email protected] (t) upgrade to: >3.21.0
High @lerna/[email protected] (t) upgrade to: >3.21.0
High @lerna/[email protected] (t) upgrade to: >3.22.0
High @lerna/[email protected] (t) upgrade to: >3.21.0
High @lerna/[email protected] (t) upgrade to: >3.21.0
High @lerna/[email protected] (t) upgrade to: >3.21.0
Critical @lerna/[email protected] (t) upgrade to: >5.5.1
High @lerna/[email protected] (t) upgrade to: >3.21.0
High @pm2/[email protected] (t) upgrade to: >2.0.0
High @pm2/[email protected] (t) upgrade to: >0.6.1
High [email protected] (t) upgrade to: >1.0.0-rc.3
High [email protected] (t) upgrade to: >4.2.1
High [email protected] (t) upgrade to: >=1.3.2
Medium [email protected] (t) upgrade to: >=6.5.4
Critical [email protected] (t) upgrade to: >=1.1.1
Critical [email protected] (t) upgrade to: >=4.7.7
Medium [email protected] (t) upgrade to: >=2.8.9
Critical [email protected] (t) upgrade to: >1.4.1 || >2.0.1
Medium [email protected] (t) upgrade to: >3.6.0
Medium [email protected] (t) upgrade to: >=4.17.21
Critical [email protected] (t) upgrade to: >=3.0.3
Medium [email protected] (t) upgrade to: >0.5.34
Medium [email protected] (t) upgrade to: >=8.0.1
Medium [email protected] (t) upgrade to: >=1.0.7
Critical [email protected] upgrade to: >=15.4.2
High [email protected] (t) upgrade to: >2.0.5
High [email protected] (t) upgrade to: >5.6.3
Critical [email protected] (t) upgrade to: >=3.3.1
High [email protected] (t) upgrade to: >=1.0.5
Medium [email protected] (t) upgrade to: >=1.0.3
Critical [email protected] (t) upgrade to: >1.5.8

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

guardrails[bot] avatar Sep 25 '22 18:09 guardrails[bot]