chore: update module github.com/vektah/gqlparser/v2 to v2.5.14 [security] - autoclosed - #62
Conversation
ℹ Artifact update noticeFile name: server/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
✅ Deploy Preview for reearth-classic canceled.
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Join our Discord community for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #62 +/- ##
==========================================
- Coverage 23.80% 23.79% -0.01%
==========================================
Files 1587 1587
Lines 170092 170127 +35
Branches 2801 2801
==========================================
Hits 40486 40486
- Misses 128439 128474 +35
Partials 1167 1167
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
ad87aab to
259ed8b
Compare
259ed8b to
d77c727
Compare
375e964 to
ae6c1ca
Compare
470c7fd to
56f25db
Compare
ℹ️ Artifact update noticeFile name: server/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
7ebb9ff to
187dec0
Compare
7c61db1 to
f7b696a
Compare
d89b56a to
80c16fb
Compare
80c16fb to
44fa50d
Compare
9e43874 to
fce3c44
Compare
fce3c44 to
148393c
Compare
This PR contains the following updates:
v2.5.11→v2.5.14gqlparser denial of service vulnerability via the parserDirectives function
CVE-2023-49559 / GHSA-2hmf-46v7-v6fx
More information
Details
An issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the parserDirectives function.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
vektah/gqlparser (github.com/vektah/gqlparser/v2)
v2.5.14Compare Source
What's Changed
Full Changelog: vektah/gqlparser@v2.5.13...v2.5.14
v2.5.13Compare Source
What's Changed
New Contributors
Full Changelog: vektah/gqlparser@v2.5.12...v2.5.13
v2.5.12Compare Source
What's Changed
New Contributors
Full Changelog: vektah/gqlparser@v2.5.11...v2.5.12
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.