Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Aug 6, 2024

This PR contains the following updates:

Package Change Age Confidence
loader-utils 2.0.0 -> 2.0.4 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2022-37601

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.

CVE-2022-37599

A regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils via the resourcePath variable in interpolateName.js. A badly or maliciously formed string could be used to send crafted requests that cause a system to crash or take a disproportional amount of time to process. This issue has been patched in versions 1.4.2, 2.0.4 and 3.2.1.

CVE-2022-37603

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js. A badly or maliciously formed string could be used to send crafted requests that cause a system to crash or take a disproportional amount of time to process. This issue has been patched in versions 1.4.2, 2.0.4 and 3.2.1.


Release Notes

webpack/loader-utils (loader-utils)

v2.0.4

Compare Source

2.0.4 (2022-11-11)
Bug Fixes

v2.0.3

Compare Source

2.0.3 (2022-10-20)
Bug Fixes

v2.0.2

Compare Source

2.0.2 (2021-11-04)
Bug Fixes

v2.0.1

Compare Source

2.0.1 (2021-10-29)
Bug Fixes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the 📦 v14 Apply this label to a pull request, if it has to be cherry-picked to the v14.x-branch after merging. label Aug 6, 2024
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch from 17c8dff to 6fcc979 Compare January 23, 2025 18:34
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch from 6fcc979 to 258cc1a Compare January 30, 2025 18:45
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch from 258cc1a to b3c63a8 Compare February 9, 2025 13:41
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch from b3c63a8 to 6b78fcb Compare March 3, 2025 17:30
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch 3 times, most recently from 6bf883c to 27cacbb Compare March 17, 2025 16:39
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch 2 times, most recently from 14c1560 to 289490d Compare April 8, 2025 11:10
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch from 289490d to 16208ce Compare April 24, 2025 10:31
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch from 16208ce to 1d62724 Compare May 19, 2025 21:16
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch 2 times, most recently from a3376b4 to aaa7876 Compare June 4, 2025 11:35
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch from aaa7876 to 31888d3 Compare June 22, 2025 14:57
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch from 31888d3 to dba6eec Compare July 2, 2025 15:09
@renovate renovate bot force-pushed the renovate/release-bot/next-v14.x-npm-loader-utils-vulnerability branch from dba6eec to 5e639e8 Compare August 10, 2025 14:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

📦 v14 Apply this label to a pull request, if it has to be cherry-picked to the v14.x-branch after merging.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant