Skip to content
This repository was archived by the owner on Jul 7, 2025. It is now read-only.

Security - Bump json5 from 1.0.1 to 1.0.2#59

Closed
kj4ezj wants to merge 1 commit intotibdex:mainfrom
AntelopeIO:dependabot/npm_and_yarn/json5-1.0.2
Closed

Security - Bump json5 from 1.0.1 to 1.0.2#59
kj4ezj wants to merge 1 commit intotibdex:mainfrom
AntelopeIO:dependabot/npm_and_yarn/json5-1.0.2

Conversation

@kj4ezj
Copy link
Copy Markdown

@kj4ezj kj4ezj commented Jan 25, 2023

This pull request addresses a high severity (7.1/10) security vulnerability, CVE-2022-46175 - Prototype Pollution in JSON5 via Parse Method, that Dependabot identified by updating the json5 dependency.

Bumps json5 from 1.0.1 to 1.0.2.


updated-dependencies:

  • dependency-name: json5 dependency-type: indirect ...

Signed-off-by: dependabot[bot] support@github.com

See Also

Bumps [json5](https://github.com/json5/json5) from 1.0.1 to 1.0.2.
- [Release notes](https://github.com/json5/json5/releases)
- [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md)
- [Commits](json5/json5@v1.0.1...v1.0.2)

---
updated-dependencies:
- dependency-name: json5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant