Repository navigation
Bump joi from 17.6.0 to 17.13.7 - #1606
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [joi](https://github.com/hapijs/joi) from 17.6.0 to 17.13.7. - [Commits](hapijs/joi@v17.6.0...v17.13.7) --- updated-dependencies: - dependency-name: joi dependency-version: 17.13.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]>
PR SummaryLow Risk Overview In this repo, joi is pulled in transitively (e.g. via wait-on), so runtime impact is limited to whatever that tooling validates. The 17.6.0→17.13.7 line includes bugfixes such as ISO date timeshift parsing and hardening around prototype pollution in messages/rename paths. Reviewed by Cursor Bugbot for commit 021b0dd. Bugbot is set up for automated code reviews on this repo. Configure here. |
Bumps joi from 17.6.0 to 17.13.7.
Commits
ed9d7cd17.13.7f2729f7Merge pull request #3145 from hapijs/backport/isodate-timeshift-v17c43fc96chore: add regression test for #3143115e7b5fix(isoDate): pad a bare-hour timeshift with a colon, not just zeros850be1e17.13.69faeeccMerge pull request #3139 from hapijs/chore/backport-messages-proto8d0b808fix: prevent messages proto injection566e73f17.13.53f3907cMerge pull request #3135 from hapijs/chore/backport-rename-proto172ececfix: prevent proto on renamesMaintainer changes
This version was pushed to npm by marsup, a new releaser for joi since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.