Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency nanoid to v5 [SECURITY] #800

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Dec 10, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
nanoid 4.0.2 -> 5.0.9 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-55565

When nanoid is called with a fractional value, there were a number of undesirable effects:

  1. in browser and non-secure, the code infinite loops on while (size--)
  2. in node, the value of poolOffset becomes fractional, causing calls to nanoid to return zeroes until the pool is next filled
  3. if the first call in node is a fractional argument, the initial buffer allocation fails with an error

Version 3.3.8 and 5.0.9 are fixed.


Release Notes

ai/nanoid (nanoid)

v5.0.9

Compare Source

  • Fixed a way to break Nano ID by passing non-integer size (by @​myndzi).

v5.0.8

Compare Source

v5.0.7

Compare Source

v5.0.6

Compare Source

  • Fixed React Native support.

v5.0.5

Compare Source

  • Make browser’s version faster by increasing size a little (by Samuel Elgozi).

v5.0.4

Compare Source

v5.0.3

Compare Source

  • Fixed CLI docs (by Chris Schmich).

v5.0.2

Compare Source

  • Fixed webcrypto import (by Divyansh Singh).

v5.0.1

Compare Source

  • Fixed Node.js 18 support.

v5.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Automerge: Enabled

@renovate renovate bot enabled auto-merge (squash) December 10, 2024 02:36
Copy link

cloudflare-workers-and-pages bot commented Dec 10, 2024

Deploying newsdesk with  Cloudflare Pages  Cloudflare Pages

Latest commit: 5725ebf
Status: ✅  Deploy successful!
Preview URL: https://8b312aaa.newsdesk.pages.dev
Branch Preview URL: https://renovate-npm-nanoid-vulnerab.newsdesk.pages.dev

View logs

renovate-approve[bot]
renovate-approve bot previously approved these changes Dec 10, 2024
renovate-approve-2[bot]
renovate-approve-2 bot previously approved these changes Dec 10, 2024
Copy link

cypress bot commented Dec 10, 2024

newsdesk    Run #2235

Run Properties:  status check passed Passed #2235  •  git commit 2ba236ae33 ℹ️: Merge 8559bcd6d0099b55660f5ad22ae8015f83be4339 into 8ea6ccf19d9dc9279dd7f37fb6e6...
Project newsdesk
Branch Review refs/pull/800/merge
Run status status check passed Passed #2235
Run duration 02m 43s
Commit git commit 2ba236ae33 ℹ️: Merge 8559bcd6d0099b55660f5ad22ae8015f83be4339 into 8ea6ccf19d9dc9279dd7f37fb6e6...
Committer renovate[bot]
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 1
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 24
View all changes introduced in this branch ↗︎

@renovate renovate bot force-pushed the renovate/npm-nanoid-vulnerability branch from 28edc93 to 0d79eb3 Compare January 13, 2025 13:01
@renovate renovate bot force-pushed the renovate/npm-nanoid-vulnerability branch from 0d79eb3 to d3b2d87 Compare January 13, 2025 13:04
renovate-approve[bot]
renovate-approve bot previously approved these changes Jan 13, 2025
renovate-approve-2[bot]
renovate-approve-2 bot previously approved these changes Jan 13, 2025
@renovate renovate bot force-pushed the renovate/npm-nanoid-vulnerability branch 3 times, most recently from 60770b9 to 2f3f758 Compare January 13, 2025 14:31
@renovate renovate bot force-pushed the renovate/npm-nanoid-vulnerability branch from 2f3f758 to 5725ebf Compare January 13, 2025 14:53
renovate-approve-2[bot]
renovate-approve-2 bot previously approved these changes Jan 13, 2025
renovate-approve[bot]
renovate-approve bot previously approved these changes Jan 13, 2025
@renovate renovate bot force-pushed the renovate/npm-nanoid-vulnerability branch from 5725ebf to 227fc80 Compare January 13, 2025 14:55
@renovate renovate bot force-pushed the renovate/npm-nanoid-vulnerability branch from 227fc80 to 122d53b Compare January 13, 2025 15:15
@renovate renovate bot force-pushed the renovate/npm-nanoid-vulnerability branch from 122d53b to 8559bcd Compare January 13, 2025 15:17
@chrisns chrisns closed this Jan 13, 2025
auto-merge was automatically disabled January 13, 2025 15:56

Pull request was closed

Copy link
Contributor Author

renovate bot commented Jan 13, 2025

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future 5.x releases. But if you manually upgrade to 5.x then Renovate will re-enable minor and patch updates automatically.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate bot deleted the renovate/npm-nanoid-vulnerability branch January 13, 2025 15:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant