Skip to content

chore(deps): update dependency webpack-dev-server to v3 [security] - #266

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-webpack-dev-server-vulnerability
Open

chore(deps): update dependency webpack-dev-server to v3 [security]#266
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-webpack-dev-server-vulnerability

chore(deps): update dependency webpack-dev-server to v3 [security]

6f09782
Select commit
Loading
Failed to load commit list.
Codacy Production / Codacy Static Code Analysis required action May 9, 2026 in 0s

14 new security issues (0 max.).

Codacy Here is an overview of what got changed by this pull request:

Issues
======
+ Solved 18
- Added 26
           

See the complete overview on Codacy

Annotations

Check warning on line 2748 in demos/vue/ecommerce/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/ecommerce/yarn.lock#L2748

Insecure dependency npm/minimist@1.2.0 (CVE-2020-7598: nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload) (update to 1.2.3)

Check failure on line 2748 in demos/vue/ecommerce/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/ecommerce/yarn.lock#L2748

Insecure dependency npm/minimist@1.2.0 (CVE-2021-44906: minimist: prototype pollution) (update to 1.2.6)

Check warning on line 2752 in demos/vue/geo/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/geo/yarn.lock#L2752

Insecure dependency npm/minimist@1.2.0 (CVE-2020-7598: nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload) (update to 1.2.3)

Check failure on line 2752 in demos/vue/geo/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/geo/yarn.lock#L2752

Insecure dependency npm/minimist@1.2.0 (CVE-2021-44906: minimist: prototype pollution) (update to 1.2.6)

Check warning on line 2478 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2018-16487: lodash: Prototype pollution in utilities function) (update to >=4.17.11)

Check warning on line 2478 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2019-1010266: lodash: uncontrolled resource consumption in Data handler causing denial of service) (update to 4.17.11)

Check failure on line 2478 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2019-10744: nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties) (update to 4.17.12)

Check warning on line 2478 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2020-28500: nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions) (update to 4.17.21)

Check warning on line 2478 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2020-8203: nodejs-lodash: prototype pollution in zipObjectDeep function) (update to 4.17.19)

Check warning on line 2478 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2021-23337: nodejs-lodash: command injection via template) (update to 4.17.21)

Check warning on line 2478 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2025-13465: lodash: prototype pollution in _.unset and _.omit functions) (update to 4.17.23)

Check warning on line 2478 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2026-2950: lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass) (update to 4.18.0)

Check warning on line 2478 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2026-4800: lodash: lodash: Arbitrary code execution via untrusted input in template imports) (update to 4.18.0)

Check warning on line 2658 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2658

Insecure dependency npm/minimist@1.2.0 (CVE-2020-7598: nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload) (update to 1.2.3)

Check failure on line 2658 in demos/vue/media/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/media/yarn.lock#L2658

Insecure dependency npm/minimist@1.2.0 (CVE-2021-44906: minimist: prototype pollution) (update to 1.2.6)

Check warning on line 2478 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2018-16487: lodash: Prototype pollution in utilities function) (update to >=4.17.11)

Check warning on line 2478 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2019-1010266: lodash: uncontrolled resource consumption in Data handler causing denial of service) (update to 4.17.11)

Check failure on line 2478 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2019-10744: nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties) (update to 4.17.12)

Check warning on line 2478 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2020-28500: nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions) (update to 4.17.21)

Check warning on line 2478 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2020-8203: nodejs-lodash: prototype pollution in zipObjectDeep function) (update to 4.17.19)

Check warning on line 2478 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2021-23337: nodejs-lodash: command injection via template) (update to 4.17.21)

Check warning on line 2478 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2025-13465: lodash: prototype pollution in _.unset and _.omit functions) (update to 4.17.23)

Check warning on line 2478 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2026-2950: lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass) (update to 4.18.0)

Check warning on line 2478 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2478

Insecure dependency npm/lodash@4.17.10 (CVE-2026-4800: lodash: lodash: Arbitrary code execution via untrusted input in template imports) (update to 4.18.0)

Check warning on line 2658 in demos/vue/saas/yarn.lock

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

demos/vue/saas/yarn.lock#L2658

Insecure dependency npm/minimist@1.2.0 (CVE-2020-7598: nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload) (update to 1.2.3)