René's URL Explorer Experiment


Title: [Security] Bump y18n from 4.0.0 to 4.0.2 by dependabot-preview[bot] · Pull Request #783 · dry-python/dry-python.github.io · GitHub

Open Graph Title: [Security] Bump y18n from 4.0.0 to 4.0.2 by dependabot-preview[bot] · Pull Request #783 · dry-python/dry-python.github.io

X Title: [Security] Bump y18n from 4.0.0 to 4.0.2 by dependabot-preview[bot] · Pull Request #783 · dry-python/dry-python.github.io

Description: Bumps y18n from 4.0.0 to 4.0.2. This update includes a security fix. Vulnerabilities fixed Sourced from The GitHub Security Advisory Database. Prototype Pollution Overview The npm package y18n before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution. POC const y18n = require('y18n')(); y18n.setLocale('proto'); y18n.updateLocale({polluted: true}); console.log(polluted); // true Recommendation Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later. Affected versions: = 4.0.0 Changelog Sourced from y18n's changelog. 4.0.2 (2021-04-07) Bug Fixes security: ensure entry exists for backport (#120) (b22c0df) 5.0.4 (2020-10-16) Bug Fixes exports: node 13.0 and 13.1 require the dotted object form with a string fallback (#105) (4f85d80) 5.0.3 (2020-10-16) Bug Fixes exports: node 13.0-13.6 require a string fallback (#103) (e39921e) 5.0.2 (2020-10-01) Bug Fixes deno: update types for deno ^1.4.0 (#100) (3834d9a) 5.0.1 (2020-09-05) Bug Fixes main had old index path (#98) (124f7b0) 5.0.0 (2020-09-05) ⚠ BREAKING CHANGES exports maps are now used, which modifies import behavior. drops Node 6 and 4. begin following Node.js LTS schedule (#89) Features add support for ESM and Deno #95) (4d7ae94) Build System ... (truncated) Commits bcfdd05 chore: release (#122) af90f17 build: fix json in manifest d65aef1 build: add default branch 910ff4c build: use appropriate releaser b22c0df fix(security): ensure entry exists for backport (#120) a9ac604 fix: address prototype pollution issue (#108) 61a8b9a chore: release 5.0.4 (#106) 4f85d80 fix(exports): node 13.0 and 13.1 require the dotted object form with a stri... 3c4e241 chore: release 5.0.3 (#104) e39921e fix(exports): node 13.0-13.6 require a string fallback (#103) Additional commits viewable in compare view Maintainer changes This version was pushed to npm by oss-bot, a new releaser for y18n since your current version. Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase. If all status checks pass Dependabot will automatically merge this pull request. Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: @dependabot rebase will rebase this PR @dependabot recreate will recreate this PR, overwriting any edits that have been made to it @dependabot merge will merge this PR after your CI passes on it @dependabot squash and merge will squash and merge this PR after your CI passes on it @dependabot cancel merge will cancel a previously requested merge and block automerging @dependabot reopen will reopen this PR if it is closed @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) @dependabot use these labels will set the current labels as the default for future PRs for this repo and language @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot dashboard: Update frequency (including time of day and day of week) Pull request limits (per update run and/or open at any time) Automerge options (never/patch/minor, and dev/runtime dependencies) Out-of-range updates (receive only lockfile updates, if desired) Security updates (receive only security updates, if desired)

Open Graph Description: Bumps y18n from 4.0.0 to 4.0.2. This update includes a security fix. Vulnerabilities fixed Sourced from The GitHub Security Advisory Database. Prototype Pollution Overview The npm package y18n be...

X Description: Bumps y18n from 4.0.0 to 4.0.2. This update includes a security fix. Vulnerabilities fixed Sourced from The GitHub Security Advisory Database. Prototype Pollution Overview The npm package y18n be...

Opengraph URL: https://github.com/dry-python/dry-python.github.io/pull/783

X: @github

direct link

Domain: github.com

route-pattern/:user_id/:repository/pull/:id/checks(.:format)
route-controllerpull_requests
route-actionchecks
fetch-noncev2:7ef0e701-07e4-c8b5-f108-c2b9c1d3b342
current-catalog-service-hash87dc3bc62d9b466312751bfd5f889726f4f1337bdff4e8be7da7c93d6c00a25a
request-id862C:B7306:40F191:5B0303:696A6A14
html-safe-noncea1a442568b4c9b39096aab5542f95a5ec7e3936ea8ed9ab5cbaf61e884ad7dd0
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI4NjJDOkI3MzA2OjQwRjE5MTo1QjAzMDM6Njk2QTZBMTQiLCJ2aXNpdG9yX2lkIjoiNDk5ODg1MzcxNjc5MDExMDc0MCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9
visitor-hmac8cc34dc49f5fd543c4f6ed8780dbee0cc5e3b692fe0bba01a69cb696d667bb0b
hovercard-subject-tagpull_request:610351667
github-keyboard-shortcutsrepository,pull-request-list,pull-request-conversation,pull-request-files-changed,checks,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///pull_requests/show/checks
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/dry-python/dry-python.github.io/pull/783/checks
twitter:imagehttps://avatars.githubusercontent.com/in/2141?s=400&v=4
twitter:cardsummary_large_image
og:imagehttps://avatars.githubusercontent.com/in/2141?s=400&v=4
og:image:altBumps y18n from 4.0.0 to 4.0.2. This update includes a security fix. Vulnerabilities fixed Sourced from The GitHub Security Advisory Database. Prototype Pollution Overview The npm package y18n be...
og:site_nameGitHub
og:typeobject
hostnamegithub.com
expected-hostnamegithub.com
None6fea32d5b7276b841b7a803796d9715bc6cfb31ed549fdf9de2948ac25d12ba6
turbo-cache-controlno-preview
go-importgithub.com/dry-python/dry-python.github.io git https://github.com/dry-python/dry-python.github.io.git
octolytics-dimension-user_id37993755
octolytics-dimension-user_logindry-python
octolytics-dimension-repository_id137952335
octolytics-dimension-repository_nwodry-python/dry-python.github.io
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id137952335
octolytics-dimension-repository_network_root_nwodry-python/dry-python.github.io
turbo-body-classeslogged-out env-production page-responsive full-width full-width-p-0
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
releasef2d9f6432a5a115ec709295ae70623f33bb80aee
ui-targetcanary-2
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/dry-python/dry-python.github.io/pull/783/checks#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fdry-python%2Fdry-python.github.io%2Fpull%2F783%2Fchecks
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fdry-python%2Fdry-python.github.io%2Fpull%2F783%2Fchecks
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fpull_requests%2Fshow%2Fchecks&source=header-repo&source_repo=dry-python%2Fdry-python.github.io
Reloadhttps://github.com/dry-python/dry-python.github.io/pull/783/checks
Reloadhttps://github.com/dry-python/dry-python.github.io/pull/783/checks
Reloadhttps://github.com/dry-python/dry-python.github.io/pull/783/checks
dry-python https://github.com/dry-python
dry-python.github.iohttps://github.com/dry-python/dry-python.github.io
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/783/checks
Notifications https://github.com/login?return_to=%2Fdry-python%2Fdry-python.github.io
Fork 5 https://github.com/login?return_to=%2Fdry-python%2Fdry-python.github.io
Star 10 https://github.com/login?return_to=%2Fdry-python%2Fdry-python.github.io
Code https://github.com/dry-python/dry-python.github.io
Issues 14 https://github.com/dry-python/dry-python.github.io/issues
Pull requests 36 https://github.com/dry-python/dry-python.github.io/pulls
Security Uh oh! There was an error while loading. Please reload this page. https://github.com/dry-python/dry-python.github.io/security
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/783/checks
Insights https://github.com/dry-python/dry-python.github.io/pulse
Code https://github.com/dry-python/dry-python.github.io
Issues https://github.com/dry-python/dry-python.github.io/issues
Pull requests https://github.com/dry-python/dry-python.github.io/pulls
Security https://github.com/dry-python/dry-python.github.io/security
Insights https://github.com/dry-python/dry-python.github.io/pulse
Sign up for GitHub https://github.com/signup?return_to=%2Fdry-python%2Fdry-python.github.io%2Fissues%2Fnew%2Fchoose
terms of servicehttps://docs.github.com/terms
privacy statementhttps://docs.github.com/privacy
Sign inhttps://github.com/login?return_to=%2Fdry-python%2Fdry-python.github.io%2Fissues%2Fnew%2Fchoose
dependabot-previewhttps://github.com/apps/dependabot-preview
develophttps://github.com/dry-python/dry-python.github.io/tree/develop
dependabot/npm_and_yarn/y18n-4.0.2https://github.com/dry-python/dry-python.github.io/tree/dependabot/npm_and_yarn/y18n-4.0.2
Conversation 1 https://github.com/dry-python/dry-python.github.io/pull/783
Commits 1 https://github.com/dry-python/dry-python.github.io/pull/783/commits
Checks 0 https://github.com/dry-python/dry-python.github.io/pull/783/checks
Files changed https://github.com/dry-python/dry-python.github.io/pull/783/files
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/783/checks
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/783/checks
[Security] Bump y18n from 4.0.0 to 4.0.2 https://github.com/dry-python/dry-python.github.io/pull/783/checks#top
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/783/checks
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.