Skip to content

Bump jsoneditor to 9.5.6 to fix ReDoS vulnerability - #51

Open
ala747 wants to merge 7 commits into
yansenlei:masterfrom
ala747:master
Open

ala747 wants to merge 7 commits into
yansenlei:masterfrom
ala747:master

Conversation

@ala747

@ala747 ala747 commented Nov 30, 2021

Copy link
Copy Markdown

Hi there! I'm sending this PR to get a reported ReDoS vulnerability into jsoneditor fixed in your package.

Additionally I've added a npm run dev script and fixed some configurations and code to get /test/ demo properly running with the dev server with hot reload in local.

The reported vulnerability as shown by Github Dependabot:
image

I would appreciate a quick merge 😄

Plus added `npm run dev` script and fixed some configurations and code to get `/test/` demo properly running with the dev server.
@ala747

ala747 commented Nov 30, 2021

Copy link
Copy Markdown
Author

Just saw another Dependabot warning about webpack-dev-server vulnerability so I bumped the version and tested that everything still works

ala747 and others added 5 commits February 24, 2022 13:20
Bumps [url-parse](https://github.com/unshiftio/url-parse) from 1.5.3 to 1.5.10.
- [Release notes](https://github.com/unshiftio/url-parse/releases)
- [Commits](unshiftio/url-parse@1.5.3...1.5.10)

---
updated-dependencies:
- dependency-name: url-parse
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [follow-redirects](https://github.com/follow-redirects/follow-redirects) from 1.14.5 to 1.14.9.
- [Release notes](https://github.com/follow-redirects/follow-redirects/releases)
- [Commits](follow-redirects/follow-redirects@v1.14.5...v1.14.9)

---
updated-dependencies:
- dependency-name: follow-redirects
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
….5.10

Bump url-parse from 1.5.3 to 1.5.10
…rects-1.14.9

Bump follow-redirects from 1.14.5 to 1.14.9

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant