fix(deps): update dependency cross-fetch to v3.1.5 [security] #54
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.0.6
->3.1.5
GitHub Vulnerability Alerts
CVE-2022-1365
When fetching a remote url with Cookie if it get Location response header then it will follow that url and try to fetch that url with provided cookie . So cookie is leaked here to thirdparty.
Ex: you try to fetch example.com with cookie and if it get redirect url to attacker.com then it fetch that redirect url with provided cookie .
Release Notes
lquixada/cross-fetch (cross-fetch)
v3.1.5
Compare Source
What's Changed
New Contributors
Full Changelog: lquixada/cross-fetch@v3.1.4...v3.1.5
v3.1.4
Compare Source
🐞 fixed typescript errors.
v3.1.3
Compare Source
🐞 fixed typescript compilation error causing #95, #101, #102.
v3.1.2
Compare Source
🐞 added missing Headers interface augmentation from lib.dom.iterable.d.ts (#97)
v3.1.1
Compare Source
🐞 fixed missing fetch api types from constructor signatures #96 (thanks @jstewmon)
v3.1.0
Compare Source
⚡️ improved TypeScript support with own fetch API type definitions (thanks @jstewmon)
⚡️ set
fetch.ponyfill
totrue
when custom ponyfill implementation is used.💡 set the same fetch API test suite to run against
node-fetch
,whatwg-fetch
and native fetch.Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.