René's URL Explorer Experiment


Title: [Security] Bump y18n from 4.0.0 to 4.0.3 by dependabot-preview[bot] · Pull Request #785 · dry-python/dry-python.github.io · GitHub

Open Graph Title: [Security] Bump y18n from 4.0.0 to 4.0.3 by dependabot-preview[bot] · Pull Request #785 · dry-python/dry-python.github.io

X Title: [Security] Bump y18n from 4.0.0 to 4.0.3 by dependabot-preview[bot] · Pull Request #785 · dry-python/dry-python.github.io

Description: Bumps y18n from 4.0.0 to 4.0.3. This update includes a security fix. Vulnerabilities fixed Sourced from The GitHub Security Advisory Database. Prototype Pollution Overview The npm package y18n before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution. POC const y18n = require('y18n')(); y18n.setLocale('proto'); y18n.updateLocale({polluted: true}); console.log(polluted); // true Recommendation Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later. Affected versions: = 4.0.0 Changelog Sourced from y18n's changelog. 4.0.3 (2021-04-07) Bug Fixes release: 4.x.x should not enforce Node 10 (#126) (1e21a53) 4.0.1 (2020-11-30) Bug Fixes address prototype pollution issue (#108) (a9ac604) Commits 0aa97c5 chore: release 4.x.x (#128) a8e7f04 build(release-please): configure branch properly (#127) 1e21a53 fix(release): 4.x.x should not enforce Node 10 (#126) 8dc7580 docs: update CHANGELOG 7de58ca fix: address prototype pollution issue See full diff in compare view Maintainer changes This version was pushed to npm by oss-bot, a new releaser for y18n since your current version. Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase. If all status checks pass Dependabot will automatically merge this pull request. Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: @dependabot rebase will rebase this PR @dependabot recreate will recreate this PR, overwriting any edits that have been made to it @dependabot merge will merge this PR after your CI passes on it @dependabot squash and merge will squash and merge this PR after your CI passes on it @dependabot cancel merge will cancel a previously requested merge and block automerging @dependabot reopen will reopen this PR if it is closed @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) @dependabot use these labels will set the current labels as the default for future PRs for this repo and language @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot dashboard: Update frequency (including time of day and day of week) Pull request limits (per update run and/or open at any time) Automerge options (never/patch/minor, and dev/runtime dependencies) Out-of-range updates (receive only lockfile updates, if desired) Security updates (receive only security updates, if desired)

Open Graph Description: Bumps y18n from 4.0.0 to 4.0.3. This update includes a security fix. Vulnerabilities fixed Sourced from The GitHub Security Advisory Database. Prototype Pollution Overview The npm package y18n be...

X Description: Bumps y18n from 4.0.0 to 4.0.3. This update includes a security fix. Vulnerabilities fixed Sourced from The GitHub Security Advisory Database. Prototype Pollution Overview The npm package y18n be...

Opengraph URL: https://github.com/dry-python/dry-python.github.io/pull/785

X: @github

direct link

Domain: github.com

route-pattern/:user_id/:repository/pull/:id/files(.:format)
route-controllerpull_requests
route-actionfiles
fetch-noncev2:41f6e6f1-421d-df39-4d00-30a289c8b807
current-catalog-service-hashae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b
request-idD1B4:DE287:2053B0E:2ABB5DB:696B0AEC
html-safe-noncea7a95d2784275d0cc956059333833e20d85690d1334c5eb94f08397afd08249a
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJEMUI0OkRFMjg3OjIwNTNCMEU6MkFCQjVEQjo2OTZCMEFFQyIsInZpc2l0b3JfaWQiOiIzMzE0NDc0NDU3OTE5ODUxMjQ0IiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0=
visitor-hmacdc01f5f52acaf46cedf3ae0a1d33dbd34e558411e595131941498b98e5e6cb47
hovercard-subject-tagpull_request:612166820
github-keyboard-shortcutsrepository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///pull_requests/show/files
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/dry-python/dry-python.github.io/pull/785/files
twitter:imagehttps://avatars.githubusercontent.com/in/2141?s=400&v=4
twitter:cardsummary_large_image
og:imagehttps://avatars.githubusercontent.com/in/2141?s=400&v=4
og:image:altBumps y18n from 4.0.0 to 4.0.3. This update includes a security fix. Vulnerabilities fixed Sourced from The GitHub Security Advisory Database. Prototype Pollution Overview The npm package y18n be...
og:site_nameGitHub
og:typeobject
hostnamegithub.com
expected-hostnamegithub.com
None5f99f7c1d70f01da5b93e5ca90303359738944d8ab470e396496262c66e60b8d
turbo-cache-controlno-preview
diff-viewunified
go-importgithub.com/dry-python/dry-python.github.io git https://github.com/dry-python/dry-python.github.io.git
octolytics-dimension-user_id37993755
octolytics-dimension-user_logindry-python
octolytics-dimension-repository_id137952335
octolytics-dimension-repository_nwodry-python/dry-python.github.io
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id137952335
octolytics-dimension-repository_network_root_nwodry-python/dry-python.github.io
turbo-body-classeslogged-out env-production page-responsive
disable-turbotrue
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release82560a55c6b2054555076f46e683151ee28a19bc
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/dry-python/dry-python.github.io/pull/785/files#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fdry-python%2Fdry-python.github.io%2Fpull%2F785%2Ffiles
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fdry-python%2Fdry-python.github.io%2Fpull%2F785%2Ffiles
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fpull_requests%2Fshow%2Ffiles&source=header-repo&source_repo=dry-python%2Fdry-python.github.io
Reloadhttps://github.com/dry-python/dry-python.github.io/pull/785/files
Reloadhttps://github.com/dry-python/dry-python.github.io/pull/785/files
Reloadhttps://github.com/dry-python/dry-python.github.io/pull/785/files
dry-python https://github.com/dry-python
dry-python.github.iohttps://github.com/dry-python/dry-python.github.io
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/785/files
Notifications https://github.com/login?return_to=%2Fdry-python%2Fdry-python.github.io
Fork 5 https://github.com/login?return_to=%2Fdry-python%2Fdry-python.github.io
Star 10 https://github.com/login?return_to=%2Fdry-python%2Fdry-python.github.io
Code https://github.com/dry-python/dry-python.github.io
Issues 14 https://github.com/dry-python/dry-python.github.io/issues
Pull requests 36 https://github.com/dry-python/dry-python.github.io/pulls
Security Uh oh! There was an error while loading. Please reload this page. https://github.com/dry-python/dry-python.github.io/security
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/785/files
Insights https://github.com/dry-python/dry-python.github.io/pulse
Code https://github.com/dry-python/dry-python.github.io
Issues https://github.com/dry-python/dry-python.github.io/issues
Pull requests https://github.com/dry-python/dry-python.github.io/pulls
Security https://github.com/dry-python/dry-python.github.io/security
Insights https://github.com/dry-python/dry-python.github.io/pulse
Sign up for GitHub https://github.com/signup?return_to=%2Fdry-python%2Fdry-python.github.io%2Fissues%2Fnew%2Fchoose
terms of servicehttps://docs.github.com/terms
privacy statementhttps://docs.github.com/privacy
Sign inhttps://github.com/login?return_to=%2Fdry-python%2Fdry-python.github.io%2Fissues%2Fnew%2Fchoose
dependabot-previewhttps://github.com/apps/dependabot-preview
develophttps://github.com/dry-python/dry-python.github.io/tree/develop
dependabot/npm_and_yarn/y18n-4.0.3https://github.com/dry-python/dry-python.github.io/tree/dependabot/npm_and_yarn/y18n-4.0.3
Conversation 0 https://github.com/dry-python/dry-python.github.io/pull/785
Commits 1 https://github.com/dry-python/dry-python.github.io/pull/785/commits
Checks 0 https://github.com/dry-python/dry-python.github.io/pull/785/checks
Files changed https://github.com/dry-python/dry-python.github.io/pull/785/files
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/785/files
[Security] Bump y18n from 4.0.0 to 4.0.3 https://github.com/dry-python/dry-python.github.io/pull/785/files#top
Show all changes 1 commit https://github.com/dry-python/dry-python.github.io/pull/785/files
d8c6bbe [Security] Bump y18n from 4.0.0 to 4.0.3 dependabot-preview[bot] Apr 9, 2021 https://github.com/dry-python/dry-python.github.io/pull/785/commits/d8c6bbe02c59e3a21791542dbb59cf2e8d172bc4
Clear filters https://github.com/dry-python/dry-python.github.io/pull/785/files
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/785/files
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/785/files
package-lock.jsonhttps://github.com/dry-python/dry-python.github.io/pull/785/files#diff-053150b640a7ce75eff69d1a22cae7f0f94ad64ce9a855db544dda0929316519
View file https://github.com/dry-python/dry-python.github.io/blob/d8c6bbe02c59e3a21791542dbb59cf2e8d172bc4/package-lock.json
Open in desktop https://desktop.github.com
how customized files appear on GitHubhttps://docs.github.com/github/administering-a-repository/customizing-how-changed-files-appear-on-github
Please reload this pagehttps://github.com/dry-python/dry-python.github.io/pull/785/files
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.