Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade jquery-validation from 1.19.3 to 1.20.0 #18

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

MrRaja23
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to upgrade jquery-validation from 1.19.3 to 1.20.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 5 versions ahead of your current version.

  • The recommended version was released on 7 months ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-JQUERYVALIDATION-2840635
586 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-JQUERYVALIDATION-2940620
586 No Known Exploit
Release notes
Package name: jquery-validation
  • 1.20.0 - 2023-10-09

    1.20.0 / 2023-10-10

    Additional

    • Fixed vinUS validation failing on valid vin numbers #2460

    Core

    • Fixed race condition in remote validation rules #2435
    • Removed pending class from fields with an aborted request #2436
    • Fixed remote validation error tracking #2242
    • Added escapeHtml option to avoid XSS attacks via showLabel method #2462

    Demo

    • Fixed minlength validation in ajaxSubmit-integration-demo.html #2454

    Localisation

    • Improved required translation in pt_BR #2445
    • Added Hindi translation #2453
    • Added French currency translation #2471
  • 1.19.5 - 2022-07-01

    1.19.5 / 2022-07-01

    Chore

    Core

    • Fixed jQuery .submit() event shorthand deprecation notice #2430
    • Fixed ReDos vulnerability in url, and url2 validation 5bbd80d

    Localisation

    • Added periods to messages #2266
  • 1.19.5-pre - 2022-05-19
  • 1.19.4 - 2022-05-19

    1.19.4 / 2022-05-19

    Build

    • Add License.md to zip tarball (#2386)

    Chore

    • Updated build status badges (#2424)
    • Enabled stable bot (#2425)

    Core

    • Fixed validation for input type="date" (#2360)
    • Wait for pendingRequests to finish before submitting form (#2369)
    • Fixed bug for Html Editors (#2154) (#2422)
    • Fixed ReDoS vulnerability in URL2 validation (#2428)

    Test

    • Switch from Travis to GitHub workflows (#2423)
  • 1.19.4-pre - 2022-04-12
  • 1.19.3 - 2021-01-09

    1.19.3 / 2021-01-09

    Core

    • CVE-2021-21252: fixed Regular Expression Denial of Service vulnerability (#2371)
    • Replaced deprecated jQuery functions (#2335)

    Chore

    • Add Accessibility section to Readme (#2149)

    Localization

    • Add "pattern" translation for French (#2363)
    • add phone validate translate for Turkish translation (#2343)
from jquery-validation GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade jquery-validation from 1.19.3 to 1.20.0.

See this package in npm:
jquery-validation

See this project in Snyk:
https://app.snyk.io/org/nielymmah/project/d8c4aee4-ae55-4a8d-81ab-58807ade7f37?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants