Skip to content

chore(deps): update dependency karma to v6.3.16 [security] #1042

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Aug 6, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
karma (source) 6.2.0 -> 6.3.16 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-0437

karma prior to version 6.3.14 contains a cross-site scripting vulnerability.

CVE-2021-23495

Karma before 6.3.16 is vulnerable to Open Redirect due to missing validation of the return_url query parameter.


Release Notes

karma-runner/karma (karma)

v6.3.16

Compare Source

Bug Fixes
  • security: mitigate the "Open Redirect Vulnerability" (ff7edbb)

v6.3.15

Compare Source

Bug Fixes

v6.3.14

Compare Source

Bug Fixes
  • remove string template from client code (91d5acd)
  • warn when singleRun and autoWatch are false (69cfc76)
  • security: remove XSS vulnerability in returnUrl query param (839578c)

v6.3.13

Compare Source

Bug Fixes

v6.3.12

Compare Source

Bug Fixes
  • remove depreciation warning from log4js (41bed33)

v6.3.11

Compare Source

Bug Fixes
  • deps: pin colors package to 1.4.0 due to security vulnerability (a5219c5)

v6.3.10

Compare Source

Bug Fixes
  • logger: create parent folders if they are missing (0d24bd9), closes #​3734

v6.3.9

Compare Source

Bug Fixes

v6.3.8

Compare Source

Bug Fixes
  • reporter: warning if stack trace contains generated code invocation (4f23b14)

v6.3.7

Compare Source

Bug Fixes
  • middleware: replace %X_UA_COMPATIBLE% marker anywhere in the file (f1aeaec), closes #​3711

v6.3.6

Compare Source

Bug Fixes

v6.3.5

Compare Source

Bug Fixes
  • client: prevent socket.io from hanging due to mocked clocks (#​3695) (105da90)

v6.3.4

Compare Source

Bug Fixes

v6.3.3

Compare Source

Bug Fixes

v6.3.2

Compare Source

Bug Fixes

v6.3.1

Compare Source

Bug Fixes
  • client: error out when opening a new tab fails (099b85e)

v6.3.0

Compare Source

Features
  • support asynchronous config.set() call in karma.conf.js (#​3660) (4c9097a)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the renovatebot label Aug 6, 2024
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch 2 times, most recently from 0b1b29e to a51e359 Compare September 3, 2024 00:44
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch from a51e359 to 9ae3898 Compare October 9, 2024 11:40
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch 3 times, most recently from 947bc23 to 9f2bba6 Compare December 6, 2024 23:45
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch 2 times, most recently from 9a4dca4 to 6789edc Compare January 30, 2025 14:59
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch from 6789edc to 8c3c34d Compare February 9, 2025 14:10
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch from 8c3c34d to d6e92cc Compare March 3, 2025 17:10
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch from d6e92cc to 9394b98 Compare March 11, 2025 10:57
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch from 9394b98 to dbcda44 Compare April 1, 2025 11:24
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch from dbcda44 to a18cc52 Compare April 8, 2025 14:11
@renovate renovate bot force-pushed the renovate/npm-karma-vulnerability branch from a18cc52 to b7ad470 Compare April 24, 2025 06:03
# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants