Skip to content

Conversation

@dependabot-preview
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Aug 27, 2019

Bumps mixin-deep from 1.3.1 to 1.3.2. This update includes a security fix.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

High severity vulnerability that affects mixin-deep
mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Affected versions: < 1.3.2

Commits
Maintainer changes

This version was pushed to npm by doowb, a new releaser for mixin-deep since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Finally, you can contact us by mentioning @dependabot.

@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Aug 27, 2019
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch 4 times, most recently from 6698605 to a8dd4e1 Compare April 9, 2020 13:32
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch 3 times, most recently from 173ef89 to 4984f0a Compare May 15, 2020 14:27
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch from 4984f0a to 1387dfc Compare June 10, 2020 12:17
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch from 1387dfc to 04a04be Compare July 4, 2020 15:35
@LevelbossMike
Copy link
Owner

@dependabot-bot recreate

@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch 2 times, most recently from 9ec9d16 to 2dffdb1 Compare July 4, 2020 18:23
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch from 2dffdb1 to f4c0b2e Compare August 3, 2020 07:27
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch 3 times, most recently from 21ddf28 to a035f46 Compare August 25, 2020 14:43
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch 5 times, most recently from d2e59a6 to 32ba5c9 Compare September 9, 2020 20:58
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch from 32ba5c9 to d389d56 Compare September 25, 2020 14:22
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch 2 times, most recently from 47ac2ef to 4735360 Compare September 25, 2020 15:01
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch from 4735360 to 31a79ad Compare October 27, 2020 12:49
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch from 31a79ad to 20e454a Compare January 12, 2021 06:56
Bumps [mixin-deep](https://github.com/jonschlinkert/mixin-deep) from 1.3.1 to 1.3.2. **This update includes a security fix.**
- [Release notes](https://github.com/jonschlinkert/mixin-deep/releases)
- [Commits](jonschlinkert/mixin-deep@1.3.1...1.3.2)

Signed-off-by: dependabot-preview[bot] <[email protected]>
@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/mixin-deep-1.3.2 branch from 20e454a to 9cf2749 Compare May 21, 2021 13:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants