Skip to content

WARNING: MAJOR (BREAKING) CHANGE: Update dependency karma to v6 [SECURITY] (master)#21

Open
renovatebot-confluentinc[bot] wants to merge 1 commit intomasterfrom
renovate/master-npm-karma-vulnerability
Open

WARNING: MAJOR (BREAKING) CHANGE: Update dependency karma to v6 [SECURITY] (master)#21
renovatebot-confluentinc[bot] wants to merge 1 commit intomasterfrom
renovate/master-npm-karma-vulnerability

Conversation

@renovatebot-confluentinc
Copy link
Contributor

@renovatebot-confluentinc renovatebot-confluentinc bot commented May 14, 2025

For any questions/concerns about this PR, please review the Renovate Bot wiki/FAQs, or the #renovatebot Slack channel.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
karma (source) ~4.1.0 -> ~6.3.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-0437

karma prior to version 6.3.14 contains a cross-site scripting vulnerability.

CVE-2021-23495

Karma before 6.3.16 is vulnerable to Open Redirect due to missing validation of the return_url query parameter.


Cross-site Scripting in karma

CVE-2022-0437 / GHSA-7x7c-qm48-pq9c

More information

Details

karma prior to version 6.3.14 contains a cross-site scripting vulnerability.

Severity

  • CVSS Score: 6.1 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Open redirect in karma

CVE-2021-23495 / GHSA-rc3x-jf5g-xvc5

More information

Details

Karma before 6.3.16 is vulnerable to Open Redirect due to missing validation of the return_url query parameter.

Severity

  • CVSS Score: 5.4 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@service-bot-app service-bot-app bot marked this pull request as ready for review May 15, 2025 07:34
@service-bot-app service-bot-app bot requested a review from a team as a code owner May 15, 2025 07:34
@service-bot-app
Copy link

Could not automerge PR: Found a file in the diff that is not marked as an approved dependency file: confluent-microservices/ui/src/main/webapp/package-lock.json

@renovatebot-confluentinc renovatebot-confluentinc bot changed the title Update dependency karma to v6 [SECURITY] (master) WARNING: MAJOR (BREAKING) CHANGE: Update dependency karma to v6 [SECURITY] (master) Jun 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants