Skip to content

chore(deps): pin dependency karma to 0.13.22 [security]#113

Open
sc-renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-karma-vulnerability
Open

chore(deps): pin dependency karma to 0.13.22 [security]#113
sc-renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-karma-vulnerability

Conversation

@sc-renovate
Copy link
Copy Markdown

@sc-renovate sc-renovate bot commented Mar 30, 2026

This PR contains the following updates:

Package Type Update Change
karma (source) devDependencies pin ^0.13.30.13.22

GitHub Vulnerability Alerts

CVE-2022-0437

karma prior to version 6.3.14 contains a cross-site scripting vulnerability.

CVE-2021-23495

Karma before 6.3.16 is vulnerable to Open Redirect due to missing validation of the return_url query parameter.

Add the preset :preserveSemverRanges to your config if you don't want to pin your dependencies.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@sc-renovate sc-renovate bot added dependencies Pull requests that update a dependency file renovate labels Mar 30, 2026
@sc-renovate sc-renovate bot force-pushed the renovate/npm-karma-vulnerability branch 4 times, most recently from 394ec38 to 335d394 Compare April 3, 2026 05:11
@sc-renovate sc-renovate bot changed the title chore(deps): update dependency karma to v6 [security] chore(deps): pin dependency karma to 0.13.22 [security] Apr 3, 2026
@sc-renovate sc-renovate bot force-pushed the renovate/npm-karma-vulnerability branch from 335d394 to 83c120d Compare April 4, 2026 00:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file renovate

Development

Successfully merging this pull request may close these issues.

0 participants