Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Mar 11, 2019

This PR contains the following updates:

Package Type Update Change References
react-dom dependencies patch 16.2.0 -> 16.2.1 homepage, source

GitHub Vulnerability Alerts

CVE-2018-6341

React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This vulnerability can only affect some server-rendered React apps. Purely client-rendered apps are not affected.

This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.


Release Notes

facebook/react

v16.2.1

React DOM Server

Renovate configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or if you modify the PR title to begin with "rebase!".

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch 2 times, most recently from c70523d to 36280bf Compare March 22, 2019 17:05
@renovate renovate bot changed the title Update dependency react-dom to v16.8.4 [SECURITY] Update dependency react-dom to v16.8.5 [SECURITY] Mar 22, 2019
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch 4 times, most recently from fd6eb02 to ce813e5 Compare March 28, 2019 07:23
@renovate renovate bot changed the title Update dependency react-dom to v16.8.5 [SECURITY] Update dependency react-dom to v16.8.6 [SECURITY] Mar 28, 2019
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from ce813e5 to adb4737 Compare May 22, 2019 19:58
@renovate renovate bot changed the title Update dependency react-dom to v16.8.6 [SECURITY] Update dependency react-dom to v16.2.1 [SECURITY] May 22, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants