Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade jquery-validation from 1.19.2 to 1.19.5 #5

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade jquery-validation from 1.19.2 to 1.19.5.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 5 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2022-07-01.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-JQUERYVALIDATION-1056868
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-JQUERYVALIDATION-2940620
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-JQUERYVALIDATION-2840635
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: jquery-validation
  • 1.19.5 - 2022-07-01

    1.19.5 / 2022-07-01

    Chore

    Core

    • Fixed jQuery .submit() event shorthand deprecation notice #2430
    • Fixed ReDos vulnerability in url, and url2 validation 5bbd80d

    Localisation

    • Added periods to messages #2266
  • 1.19.5-pre - 2022-05-19
  • 1.19.4 - 2022-05-19

    1.19.4 / 2022-05-19

    Build

    • Add License.md to zip tarball (#2386)

    Chore

    • Updated build status badges (#2424)
    • Enabled stable bot (#2425)

    Core

    • Fixed validation for input type="date" (#2360)
    • Wait for pendingRequests to finish before submitting form (#2369)
    • Fixed bug for Html Editors (#2154) (#2422)
    • Fixed ReDoS vulnerability in URL2 validation (#2428)

    Test

    • Switch from Travis to GitHub workflows (#2423)
  • 1.19.4-pre - 2022-04-12
  • 1.19.3 - 2021-01-09

    1.19.3 / 2021-01-09

    Core

    • CVE-2021-21252: fixed Regular Expression Denial of Service vulnerability (#2371)
    • Replaced deprecated jQuery functions (#2335)

    Chore

    • Add Accessibility section to Readme (#2149)

    Localization

    • Add "pattern" translation for French (#2363)
    • add phone validate translate for Turkish translation (#2343)
  • 1.19.2 - 2020-05-23

    1.19.2 / 2020-05-23

    Core

    • Core: Fixes deprecated calls to jQuery trim for compat with newer jQuery core versions (#2328)

    Contributors

    • Brighton Balfrey
    • Markus Staab
    • Brahim Arkni
from jquery-validation GitHub release notes
Commit messages
Package name: jquery-validation
  • 5907740 1.19.5
  • 5bbd80d Merge pull request from GHSA-ffmh-x56j-9rc3
  • 3d3c1fb Chore: Add CodeQL analysis
  • 0da4906 Core: fix deprecated jquery .submit() event shorthand (#2430)
  • 1b79877 Localization: Add periods to messages (#2266)
  • b68e282 Chore: update changelog
  • 3a4cd94 Build: Updating the master version to 1.19.5-pre.
  • 91d2098 Build: update release steps
  • 69cb17e Core: fix ReDoS vulnerability in url2 (#2428)
  • aa5bcdc Chore: update issue templates
  • 350f6ae Core: fix validation for input type="date" (#2360)
  • 7828568 Gruntfile.js: add LICENSE.md to zip tarball (#2386)
  • 3688078 Chore: switch to stale bot github action (#2425)
  • f8b0b53 README: update build status badge (#2424)
  • 25293cc Test: Switch from Travis to GitHub workflows (#2423)
  • 900a90b Core: fix code style (#2422)
  • eb88df0 Core: wait for pendingRequests to finish before submitting form (#2369)
  • 31ea8ff Fixed bug for Html Editor(summernote) (#2154)
  • df89cf0 Create SECURITY.md
  • bda9a58 Build: added CVE-2021-21252 reference
  • 322a575 Build: Updating the master version to 1.19.4-pre.
  • 5d8f29e Core: fixed Regular Expression Denial of Service vulnerability (#2371)
  • b8d6646 Localization: Add "pattern" translation for French (#2363)
  • b9c793c docs: Fix simple typo, atteched -> attached (#2345)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant