Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented May 28, 2023

This PR contains the following updates:

Package Change Age Confidence
webpack-bundle-analyzer 3.0.3 -> 3.3.2 age confidence

GitHub Vulnerability Alerts

GHSA-pgr8-jg6h-8gw6

Versions of webpack-bundle-analyzer prior to 3.3.2 are vulnerable to Cross-Site Scripting. The package uses JSON.stringify() without properly escaping input which may lead to Cross-Site Scripting.

Recommendation

Upgrade to version 3.3.2 or later.


Release Notes

webpack/webpack-bundle-analyzer (webpack-bundle-analyzer)

v3.3.2

Compare Source

  • Bug Fix
    • Fix regression with escaping internal assets (#​264, fixes #​263)

v3.3.1

Compare Source

  • Improvements

    • Use relative links for serving internal assets (#​261, fixes #​254)
    • Properly escape embedded JS/JSON (#​262)
  • Bug Fix

v3.3.0

Compare Source

  • New Feature

  • Internal

    • Updated dev dependencies

v3.2.0

Compare Source

v3.1.0

Compare Source

v3.0.4

Compare Source

  • Bug Fix
    • Make webpack's done hook wait until analyzer writes report or stat file (#​247, @​mareolan)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch 2 times, most recently from c74e9cb to 44b2611 Compare October 16, 2023 03:02
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from 44b2611 to 308acab Compare October 24, 2023 05:49
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch 2 times, most recently from b6beff2 to 57b4458 Compare February 4, 2024 14:45
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from 57b4458 to 3c05fc2 Compare February 26, 2024 02:13
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from 3c05fc2 to 6a7498a Compare March 13, 2024 08:44
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch 2 times, most recently from a82e582 to 1687ea0 Compare March 26, 2024 02:33
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from 1687ea0 to 8f1dd40 Compare July 21, 2024 23:49
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from 8f1dd40 to 024721c Compare October 9, 2024 08:50
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from 024721c to bab8d8f Compare December 3, 2024 02:55
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from bab8d8f to 9c43aed Compare January 25, 2025 07:44
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from 9c43aed to febf8a7 Compare February 11, 2025 07:56
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from febf8a7 to 679ead1 Compare March 4, 2025 20:18
@renovate renovate bot force-pushed the renovate/npm-webpack-bundle-analyzer-vulnerability branch from 679ead1 to 088cffa Compare December 4, 2025 00:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant