Skip to content

chore(deps): update dependency validator to v13.15.20 [security] - autoclosed - #3638

Closed
renovate[bot] wants to merge 1 commit into
nextfrom
renovate/npm-validator-vulnerability
Closed

chore(deps): update dependency validator to v13.15.20 [security] - autoclosed#3638
renovate[bot] wants to merge 1 commit into
nextfrom
renovate/npm-validator-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 27, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
validator 13.15.15 -> 13.15.20 age confidence

GitHub Vulnerability Alerts

CVE-2025-56200

A URL validation bypass vulnerability exists in validator.js prior to version 13.15.20. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open Redirect attacks.


Release Notes

validatorjs/validator.js (validator)

v13.15.20

Compare Source

Fixes, New Locales and Enhancements

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner October 27, 2025 17:37
@renovate renovate Bot added c: security Indicates a vulnerability or a potentially (security) risky change. p: 2-high Fix main branch labels Oct 27, 2025
@renovate renovate Bot added this to the vAnytime milestone Oct 27, 2025
@netlify

netlify Bot commented Oct 27, 2025

Copy link
Copy Markdown

Deploy Preview for fakerjs ready!

Name Link
🔨 Latest commit a300f30
🔍 Latest deploy log https://app.netlify.com/projects/fakerjs/deploys/690ff343144e0c00081c1649
😎 Deploy Preview https://deploy-preview-3638.fakerjs.dev
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@codecov

codecov Bot commented Oct 27, 2025

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.97%. Comparing base (57b2d78) to head (a300f30).
⚠️ Report is 1 commits behind head on next.

Additional details and impacted files
@@           Coverage Diff           @@
##             next    #3638   +/-   ##
=======================================
  Coverage   99.97%   99.97%           
=======================================
  Files        2994     2994           
  Lines      236305   236305           
  Branches      939      938    -1     
=======================================
  Hits       236248   236248           
  Misses         57       57           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate
renovate Bot force-pushed the renovate/npm-validator-vulnerability branch 8 times, most recently from d14891d to f620872 Compare November 9, 2025 01:26
@renovate
renovate Bot force-pushed the renovate/npm-validator-vulnerability branch from f620872 to a300f30 Compare November 9, 2025 01:49
@renovate renovate Bot changed the title chore(deps): update dependency validator to v13.15.20 [security] chore(deps): update dependency validator to v13.15.20 [security] - autoclosed Nov 9, 2025
@renovate renovate Bot closed this Nov 9, 2025
@renovate
renovate Bot deleted the renovate/npm-validator-vulnerability branch November 9, 2025 21:45
@ST-DDT ST-DDT removed this from the vAnytime milestone Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c: security Indicates a vulnerability or a potentially (security) risky change. p: 2-high Fix main branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant