fix(deps): update dependency nanoid to v5.0.9 [security]#591
fix(deps): update dependency nanoid to v5.0.9 [security]#591renovate[bot] wants to merge 1 commit intomainfrom
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
#1454 Bundle Size — 2.56MiB (0%).2c8d1dd(current) vs 3b6dffc main#1453(baseline) Warning Bundle contains 4 duplicate packages – View duplicate packages Bundle metrics
Bundle size by type
|
| Current #1454 |
Baseline #1453 |
|
|---|---|---|
2.24MiB |
2.24MiB |
|
213.87KiB |
213.87KiB |
|
89.92KiB |
89.92KiB |
|
15.35KiB |
15.35KiB |
|
1.73KiB |
1.73KiB |
Bundle analysis report Branch refs/pull/591/merge Project dashboard
Generated by RelativeCI Documentation Report issue
c5775fe to
48ab56c
Compare
48ab56c to
fb293a4
Compare
fb293a4 to
968a568
Compare
968a568 to
552666d
Compare
552666d to
fb0e86f
Compare
fb0e86f to
f5d1a28
Compare
f5d1a28 to
4e35ebc
Compare
4e35ebc to
55f723b
Compare
55f723b to
237a351
Compare
237a351 to
b0cf8aa
Compare
b0cf8aa to
fcdbba5
Compare
fcdbba5 to
f0a1b50
Compare
f0a1b50 to
baea17c
Compare
This PR contains the following updates:
5.0.7→5.0.9Predictable results in nanoid generation when given non-integer values
CVE-2024-55565 / GHSA-mwcw-c2x4-8c55
More information
Details
When nanoid is called with a fractional value, there were a number of undesirable effects:
Version 3.3.8 and 5.0.9 are fixed.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
ai/nanoid (nanoid)
v5.0.9Compare Source
v5.0.8Compare Source
customAlphabetsize (by @kirillgroshkov).Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.