Update dependency eslint to v4.18.2 [SECURITY]#10
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.15.0->4.18.2GitHub Vulnerability Alerts
GHSA-jcgq-xh2f-2hfm / WS-2018-0592
A vulnerability was descovered in eslint before 4.18.2. One of the regexes in eslint is vulnerable to catastrophic backtracking.
Release Notes
eslint/eslint
v4.18.2Compare Source
6b71fd0Fix: table@4.0.2, because 4.0.3 needs "ajv": "^6.0.1" (#10022) (Mathieu Seiler)3c697deChore: fix incorrect comment about linter.verify return value (#10030) (Teddy Katz)9df8653Chore: refactor parser-loading out of linter.verify (#10028) (Teddy Katz)f6901d0Fix: remove catastrophic backtracking vulnerability (fixes #10002) (#10019) (Jamie Davis)e4f52ceChore: Simplify dataflow in linter.verify (#10020) (Teddy Katz)33177cdChore: make library files non-executable (#10021) (Teddy Katz)558ccbaChore: refactor directive comment processing (#10007) (Teddy Katz)18e15d9Chore: avoid useless catch clauses that just rethrow errors (#10010) (Teddy Katz)a1c3759Chore: refactor populating configs with defaults in linter (#10006) (Teddy Katz)aea07dcFix: Make max-len ignoreStrings ignore JSXText (fixes #9954) (#9985) (Rachael Sim)v4.18.1Compare Source
f417506Fix: ensure no-await-in-loop reports the correct node (fixes #9992) (#9993) (Teddy Katz)3e99363Docs: Fixed typo in key-spacing rule doc (#9987) (Jaid)7c2cd70Docs: deprecate experimentalObjectRestSpread (#9986) (Toru Nagashima)v4.18.0Compare Source
70f22f3Chore: Apply memoization to config creation within glob utils (#9944) (Kenton Jacobsen)0e4ae22Update: fix indent bug with binary operators/ignoredNodes (fixes #9882) (#9951) (Teddy Katz)47ac478Update: add named imports and exports for object-curly-newline (#9876) (Nicholas Chua)e8efdd0Fix: support Rest/Spread Properties (fixes #9885) (#9943) (Toru Nagashima)f012b8cFix: support Async iteration (fixes #9891) (#9957) (Toru Nagashima)74fa253Docs: Clarify no-mixed-operators options (fixes #9962) (#9964) (Ivan Hayes)426868fDocs: clean up key-spacing docs (fixes #9900) (#9963) (Abid Uzair)4a6f22eUpdate: support eslint-disable-* block comments (fixes #8781) (#9745) (Erin)777283bDocs: Propose fix typo for function (#9965) (John Eismeier)bf3d494Docs: Fix typo in max-len ignorePattern example. (#9956) (Tim Martin)d64fbb4Docs: fix typo in prefer-destructuring.md example (#9930) (Vse Mozhet Byt)f8d343fChore: Fix default issue template (#9946) (Kai Cataldo)v4.17.0Compare Source
1da1adaUpdate: Add "multiline" type to padding-line-between-statements (#8668) (Matthew Bennett)bb213dcChore: Use messageIds in some of the core rules (#9648) (Jed Fox)1aa1970Docs: remove outdated rule naming convention (#9925) (Teddy Katz)3afaff6Docs: Add prefer-destructuring variable reassignment example (#9873) (LePirlouit)d20f6b4Fix: Typo in error message when running npm (#9866) (Maciej Kasprzyk)51ec6a7Docs: Use GitHub Multiple PR/Issue templates (#9911) (Kai Cataldo)dc80487Update: space-unary-ops uses astUtils.canTokensBeAdjacent (fixes #9907) (#9906) (Kevin Partington)084351bDocs: Fix the messageId example (fixes #9889) (#9892) (Jed Fox)9cbb487Docs: Mention theglobalskey in the no-undef docs (#9867) (Dan Dascalescu)v4.16.0Compare Source
e26a25fUpdate: allow continue instead of if wrap in guard-for-in (fixes #7567) (#9796) (Michael Ficarra)af043ebUpdate: Add NewExpression support to comma-style (#9591) (Frazer McLean)4f898c7Build: Fix JSDoc syntax errors (#9813) (Matija Marohnić)13bcf3cFix: Removing curly quotes in no-eq-null report message (#9852) (Kevin Partington)b96fb31Docs: configuration hierarchy for CLIEngine options (fixes #9526) (#9855) (PiIsFour)8ccbddaDocs: Clarify that -c configs merge with.eslintrc.*(fixes #9535) (#9847) (Kevin Partington)978574fDocs: Fix examples for no-useless-escape (#9853) (Toru Kobayashi)cd5681dChore: Deactivate consistent-docs-url in internal rules folder (#9815) (Kevin Partington)2e87dddDocs: Sync messageId examples' style with other examples (#9816) (Kevin Partington)1d61930Update: use doctrine range information in valid-jsdoc (#9831) (Teddy Katz)133336eUpdate: fix indent behavior on template literal arguments (fixes #9061) (#9820) (Teddy Katz)ea1b15dFix: avoid crashing on malformed configuration comments (fixes #9373) (#9819) (Teddy Katz)add1e70Update: fix indent bug on comments in ternary expressions (fixes #9729) (#9818) (Teddy Katz)6a5cd32Fix: prefer-destructuring error with computed properties (fixes #9784) (#9817) (Teddy Katz)601f851Docs: Minor modification to code comments for clarity (#9821) (rgovind92)b9da067Docs: fix misleading info about RuleTester column numbers (#9830) (Teddy Katz)2cf4522Update: Rename and deprecate object-property-newline option (#9570) (Jonathan Pool)acde640Docs: Add ES 2018 to Configuring ESLint (#9829) (Kai Cataldo)ccfce15Docs: Minor tweaks to working with rules page (#9824) (Kevin Partington)54b329aDocs: fix substitution of {{ name }} (#9822) (Andres Kalle)Renovate configuration
📅 Schedule: "" (UTC).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by WhiteSource Renovate. View repository job log here.