Update dependency semver to v4 [SECURITY] - #11
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
January 11, 2025 11:49
aab8131 to
611b8fd
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
January 15, 2025 19:40
611b8fd to
f3445e8
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
January 17, 2025 11:45
f3445e8 to
7500c34
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
January 25, 2025 11:49
7500c34 to
896a6ac
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
January 26, 2025 06:13
896a6ac to
cea25ad
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
January 31, 2025 19:07
cea25ad to
b52410f
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
February 1, 2025 19:46
b52410f to
e91d224
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
2 times, most recently
from
February 12, 2025 07:54
4511133 to
6099c01
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
March 5, 2025 03:44
6099c01 to
7436c8b
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
March 8, 2025 03:32
7436c8b to
1af0226
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
2 times, most recently
from
March 15, 2025 11:18
6251bb1 to
89cfc92
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
March 19, 2025 23:58
89cfc92 to
fec0c9a
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
March 21, 2025 23:49
fec0c9a to
a1f1235
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
May 17, 2025 04:02
3973124 to
673eb20
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
May 18, 2025 19:27
673eb20 to
6bab41d
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
May 24, 2025 11:33
6bab41d to
dd97921
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
May 25, 2025 11:37
dd97921 to
85fc674
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
May 31, 2025 12:12
85fc674 to
edb4158
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
June 1, 2025 19:14
edb4158 to
11e8749
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
June 6, 2025 18:23
11e8749 to
cb57603
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
June 8, 2025 10:34
cb57603 to
019babc
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
June 21, 2025 12:03
019babc to
ec84844
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
July 13, 2025 23:55
ec84844 to
fe4d7a4
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
August 11, 2025 03:26
fe4d7a4 to
e6c728b
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
August 16, 2025 11:48
e6c728b to
7d9f5d3
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
August 21, 2025 04:15
7d9f5d3 to
91305f9
Compare
renovate
Bot
force-pushed
the
renovate/npm-semver-vulnerability
branch
from
August 24, 2025 04:12
91305f9 to
cdefc89
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
~1.1.0→~4.3.2Regular Expression Denial of Service in semver
CVE-2015-8855 / GHSA-x6fg-f45m-jf5q
More information
Details
Versions 4.3.1 and earlier of
semverare affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.Recommendation
Update to version 4.3.2 or later
Severity
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
npm/node-semver (semver)
v4.3.2Compare Source
v4.3.1Compare Source
v4.3.0Compare Source
v4.2.2Compare Source
v4.2.1Compare Source
v4.2.0Compare Source
v4.1.1Compare Source
v4.1.0Compare Source
v4.0.3Compare Source
v4.0.2Compare Source
v4.0.0Compare Source
v3.0.1Compare Source
v3.0.0Compare Source
v2.3.2Compare Source
v2.3.1Compare Source
v2.3.0Compare Source
v2.2.1Compare Source
v2.2.0Compare Source
v2.1.0Compare Source
v2.0.11Compare Source
v2.0.10Compare Source
v2.0.9Compare Source
v2.0.8Compare Source
v2.0.7Compare Source
v2.0.6Compare Source
v2.0.5Compare Source
v2.0.4Compare Source
v2.0.3Compare Source
v2.0.2Compare Source
v2.0.1Compare Source
v1.1.4Compare Source
v1.1.3Compare Source
v1.1.2Compare Source
v1.1.1Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.