Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency yarn to v1.22.0 [SECURITY] #101

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Jul 31, 2019

This PR contains the following updates:

Package Type Update Change
yarn devDependencies minor 1.15.2 -> 1.22.0

GitHub Vulnerability Alerts

CVE-2019-5448

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

CVE-2019-10773

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.


Release Notes

yarnpkg/yarn

v1.22.0

Compare Source

v1.21.1

Compare Source

v1.21.0

Compare Source

v1.19.2

Compare Source

  • Folders like .cache won't be pruned from the node_modules after each install.

    #​7699 - Maël Nison

  • Correctly installs workspace child dependencies when workspace child not symlinked to root.

    #​7289 - Daniel Tschinder

  • Makes running scripts with Plug'n Play possible on node 13.

    #​7650 - Sander Verweij

  • Change run command to check cwd/node_modules/.bin for commands. Fixes run in workspaces.

    #​7151 - Jeff Valore

v1.19.1

Compare Source

Important: This release contains a cache bump. It will cause the very first install following the upgrade to take slightly more time, especially if you don't use the Offline Mirror feature. After that everything will be back to normal.

v1.19.0

Compare Source

Important: This release contains a cache bump. It will cause the very first install following the upgrade to take slightly more time, especially if you don't use the Offline Mirror feature. After that everything will be back to normal.

  • Fixes a potential vulnerability regarding how the build artifacts are stored

    Reported by ChALkeR, fixed by Maël Nison

v1.18.0

Compare Source

v1.17.3

Compare Source

v1.17.2

Compare Source

v1.17.1

Compare Source

v1.17.0

Compare Source

v1.16.0

Compare Source


Renovate configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Enabled.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by WhiteSource Renovate. View repository job log here.

@smblee smblee closed this Sep 16, 2019
@smblee smblee reopened this Sep 16, 2019
@renovate renovate bot force-pushed the renovate/npm-yarn-vulnerability branch from fec1991 to 792fb64 Compare September 28, 2019 16:45
@renovate renovate bot force-pushed the renovate/npm-yarn-vulnerability branch from 792fb64 to d3ab10f Compare October 8, 2019 12:24
@renovate renovate bot force-pushed the renovate/npm-yarn-vulnerability branch from d3ab10f to bf24161 Compare December 15, 2019 02:00
@renovate renovate bot force-pushed the renovate/npm-yarn-vulnerability branch from bf24161 to b21fdbb Compare February 5, 2020 19:18
@renovate renovate bot changed the title Update dependency yarn to v1.17.3 [SECURITY] Update dependency yarn to v1.22.0 [SECURITY] Feb 15, 2020
@renovate renovate bot force-pushed the renovate/npm-yarn-vulnerability branch from b21fdbb to c4a6b2a Compare March 6, 2020 17:08
@renovate renovate bot force-pushed the renovate/npm-yarn-vulnerability branch from c4a6b2a to d829a06 Compare March 9, 2020 16:27
@smblee smblee closed this Mar 27, 2020
@renovate
Copy link
Author

renovate bot commented Mar 27, 2020

Renovate Ignore Notification

As this PR has been closed unmerged, Renovate will now ignore this update (^1.15.2). You will still receive a PR once a newer version is released, so if you wish to permanently ignore this dependency, please add it to the ignoreDeps array of your renovate config.

If this PR was closed by mistake or you changed your mind, you can simply rename this PR and you will soon get a fresh replacement PR opened.

@renovate renovate bot deleted the renovate/npm-yarn-vulnerability branch March 27, 2020 00:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants