Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented May 28, 2024

This PR contains the following updates:

Package Change Age Confidence
pug (source) 3.0.2 -> 3.0.3 age confidence

GitHub Vulnerability Alerts

CVE-2024-36361

Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileClient, or compileClientWithDependenciesTracked function. NOTE: these functions are for compiling Pug templates into JavaScript, and there would typically be no reason to allow untrusted callers.


Release Notes

pugjs/pug (pug)

v3.0.3

Compare Source

Bug Fixes

  • Update pug-code-gen with the following fix: (#​3438)

    Validate templateName and globals are valid JavaScript identifiers to prevent possible remote code execution if un-trusted user input is passed to the compilation options


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label May 28, 2024
@renovate renovate bot force-pushed the renovate/npm-pug-vulnerability branch 2 times, most recently from ccfab2d to c68fdb9 Compare October 17, 2024 20:32
@renovate renovate bot force-pushed the renovate/npm-pug-vulnerability branch from c68fdb9 to 8a60f03 Compare June 16, 2025 10:27
@renovate renovate bot force-pushed the renovate/npm-pug-vulnerability branch from 8a60f03 to 952789a Compare June 23, 2025 22:57
@renovate renovate bot force-pushed the renovate/npm-pug-vulnerability branch from 952789a to d9fed02 Compare June 24, 2025 23:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant