Skip to content

Conversation

uicontent
Copy link
Collaborator

This PR contains the following updates:

Package Change Age Confidence
linkifyjs (source) 4.3.1 -> 4.3.2 age confidence

GitHub Vulnerability Alerts

CVE-2025-8101

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.


Release Notes

nfrasser/linkifyjs (linkifyjs)

v4.3.2

Compare Source

  • Replace assign helper with Object.assign to avoid prototype pollution

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


This PR has been generated by Renovate Bot.

@uicontent uicontent added the dependencies Pull requests that update a dependency file label Jul 30, 2025
@uicontent uicontent requested a review from a team as a code owner July 30, 2025 08:22
gjulivan
gjulivan previously approved these changes Jul 30, 2025
@uicontent uicontent force-pushed the deps/npm-linkifyjs-vulnerability branch from 5bef928 to a58782c Compare July 31, 2025 08:22
gjulivan
gjulivan previously approved these changes Jul 31, 2025
@uicontent uicontent force-pushed the deps/npm-linkifyjs-vulnerability branch 6 times, most recently from 571e159 to 0e785c6 Compare August 7, 2025 08:22
@uicontent uicontent force-pushed the deps/npm-linkifyjs-vulnerability branch 5 times, most recently from 538b83d to a3b6cd4 Compare August 15, 2025 08:21
@uicontent uicontent force-pushed the deps/npm-linkifyjs-vulnerability branch 6 times, most recently from e86faaa to f1856a4 Compare August 25, 2025 08:22
@uicontent uicontent force-pushed the deps/npm-linkifyjs-vulnerability branch 3 times, most recently from f9984eb to 3ec6906 Compare August 28, 2025 08:20
@uicontent uicontent force-pushed the deps/npm-linkifyjs-vulnerability branch from 3ec6906 to 8e79e9a Compare August 29, 2025 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants