Skip to content

Conversation

@dependabot-preview
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Mar 29, 2021

Bumps hosted-git-info from 2.7.1 to 4.0.2.

Changelog

Sourced from hosted-git-info's changelog.

Change Log

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

3.0.8 (2021-01-28)

Bug Fixes

  • simplify the regular expression for shortcut matching (bede0dc), closes #76

3.0.7 (2020-10-15)

Bug Fixes

  • correctly filter out urls for tarballs in gitlab (eb5bd5a), closes #69

3.0.6 (2020-10-12)

Bug Fixes

  • support to github gist legacy hash length (c067102), closes #68

3.0.5 (2020-07-11)

3.0.4 (2020-02-26)

Bug Fixes

  • Do not pass scp-style URLs to the WhatWG url.URL (0835306), closes #60 #63

... (truncated)

Commits
  • f7fba2e 4.0.2
  • 3756d2f fix: do not parse tarball urls for gitlab
  • 974bbca 4.0.1
  • ea2fdbe fix: account for extreme github shorthand in input that ends with a / as part...
  • 6335cac chore: package-lock
  • 49d2074 4.0.0
  • 34909e3 chore(publish): update publish lifcycle
  • c218b9e rewrite the entire module (#80)
  • deab507 Merge pull request #79 from npm/nlf/refactor-tests
  • c9b2f7d chore: switch from travis to github actions for ci
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by nlf, a new releaser for hosted-git-info since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot will not automatically merge this PR because it includes a major update to a production dependency.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yaml file in this repo:

  • Update frequency
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot requested a review from a team as a code owner March 29, 2021 14:20
@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Mar 29, 2021
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/hosted-git-info-4.0.2 branch from 2ddc9f6 to 4d411d5 Compare March 29, 2021 17:11
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/hosted-git-info-4.0.2 branch from 4d411d5 to 3f03e2d Compare April 16, 2021 22:10
@dependabot-preview
Copy link
Contributor Author

We've just been alerted that this update fixes a security vulnerability:

Sourced from The GitHub Security Advisory Database.

Regular Expression Deinal of Service in hosted-git-info

The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity

Affected versions: ["< 3.0.8"]

@dependabot-preview dependabot-preview bot changed the title Bump hosted-git-info from 2.7.1 to 4.0.2 [Security] Bump hosted-git-info from 2.7.1 to 4.0.2 May 6, 2021
@dependabot-preview dependabot-preview bot added the security Pull requests that address a security vulnerability label May 6, 2021
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/hosted-git-info-4.0.2 branch from 3f03e2d to 78d9e72 Compare May 6, 2021 17:07
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/hosted-git-info-4.0.2 branch from 78d9e72 to 307e93f Compare June 21, 2021 12:19
Bumps [hosted-git-info](https://github.com/npm/hosted-git-info) from 2.7.1 to 4.0.2.
- [Release notes](https://github.com/npm/hosted-git-info/releases)
- [Changelog](https://github.com/npm/hosted-git-info/blob/latest/CHANGELOG.md)
- [Commits](npm/hosted-git-info@v2.7.1...v4.0.2)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/hosted-git-info-4.0.2 branch from 307e93f to 7c063bc Compare August 3, 2021 19:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant