Skip to content

@remotion/bundler: Bump loader-utils to 2.0.4#6980

Merged
JonnyBurger merged 1 commit intomainfrom
bump/loader-utils-2.0.4
Apr 4, 2026
Merged

@remotion/bundler: Bump loader-utils to 2.0.4#6980
JonnyBurger merged 1 commit intomainfrom
bump/loader-utils-2.0.4

Conversation

@JonnyBurger
Copy link
Copy Markdown
Member

Bumps loader-utils from 2.0.2 to 2.0.4 to address the prototype pollution fix in 2.0.3 and the ReDoS fix in 2.0.4.

Supersedes the closed Dependabot PR #6885.

Made with Cursor

@vercel
Copy link
Copy Markdown
Contributor

vercel bot commented Apr 4, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
bugs Ready Ready Preview, Comment Apr 4, 2026 7:23am
remotion Ready Ready Preview, Comment Apr 4, 2026 7:23am

Request Review

@JonnyBurger JonnyBurger enabled auto-merge (squash) April 4, 2026 07:21
@pullfrog
Copy link
Copy Markdown
Contributor

pullfrog bot commented Apr 4, 2026

Reviewed PR #6980 — clean security-only dependency bump of loader-utils from 2.0.2 to 2.0.4. No issues found.

Task list (4/4 completed)
  • Read the PR diff and identify areas of change
  • Investigate changes in detail (dependency bump, lock file)
  • Check for impact and correctness
  • Submit review or report progress

Pullfrog  | View workflow run | Triggered by Pullfrog | Using Big Pickle (free) | 𝕏

Copy link
Copy Markdown
Contributor

@pullfrog pullfrog bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security-only bump (prototype pollution fix in 2.0.3, ReDoS fix in 2.0.4) with no API changes. The three loader-utils APIs used by @remotion/bundler (getOptions, stringifyRequest, urlToRequest) are unaffected. Lock file correctly scopes other packages to their own loader-utils@2.0.2 copies.

Pullfrog  | View workflow run | Using Big Pickle (free) | 𝕏

@JonnyBurger JonnyBurger merged commit c515b9f into main Apr 4, 2026
19 checks passed
@JonnyBurger JonnyBurger deleted the bump/loader-utils-2.0.4 branch April 4, 2026 07:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant