-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update dependency zod to v3.22.3 [security] #87
base: beta
Are you sure you want to change the base?
Conversation
Quality Gate passedIssues Measures |
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
|
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
Next stepsWhat is an install script?Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts. Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead. Take a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with
|
This PR contains the following updates:
3.21.4
->3.22.3
GitHub Vulnerability Alerts
CVE-2023-4316
Zod version 3.22.2 allows an attacker to perform a denial of service while validating emails.
Release Notes
colinhacks/zod (zod)
v3.22.3
Compare Source
Commits:
1e23990
Commit9bd3879
docs: remove obsolete text about readonly types (#2676)f59be09
clarify datetime ISO 8601 (#2673)64dcc8e
Update sponsors18115a8
Formatting28c1927
Update sponsorsad2ee9c
2718 Updated Custom Schemas documentation example to use type narrowing (#2778)ae0f7a2
docs: update ref to discriminated-unions docs (#2485)2ba00fe
[2609] fix ReDoS vulnerability in email regex (#2824)1e61d76
3.22.3v3.22.2
Compare Source
Commits:
13d9e6b
Fix lint0d49f10
docs: add typeschema to ecosystem (#2626)8e4af7b
X to Zod: add app.quicktype.io (#2668)792b3ef
Fix superrefine typesv3.22.1
Compare Source
Commits:
Fix handing of
this
in ZodFunction schemas. The parse logic for function schemas now requires theReflect
API.932cc47
Initial prototype fix for issue #2651 (#2652)0a055e7
3.22.1v3.22.0
Compare Source
ZodReadonly
This release introduces
ZodReadonly
and the.readonly()
method onZodType
.Calling
.readonly()
on any schema returns aZodReadonly
instance that wraps the original schema. The new schema parses all inputs using the original schema, then callsObject.freeze()
on the result. The inferred type is also marked asreadonly
.The inferred type uses TypeScript's built-in readonly types when relevant.
Commits:
6dad907
Comments56ace68
Fix deno test3809d54
Add superformsd1ad522
Add transloadita3bb701
Testing on Typescript 5.0 (#2221)51e14be
docs: update deprecated link (#2219)a263814
fixed Datetime & IP TOC links502384e
docs: add mobx-zod-form to form integrations (#2299)a8be450
docs: Addzocker
to Ecosystem section (#2416)15de22a
Allow subdomains and hyphens inZodString.email
(#2274)00f5783
Addzod-openapi
to ecosystem (#2434)0a17340
docs: fix minor typo (#2439)60a2134
Add masterborn0a90ed1
chore: moveexports.types
field to first spot @ package.json. (#2443)67f35b1
docs: allow Zod to be used in dev tools at site (#2432)6795c57
Fix not working Deno doc link. (#2428)37e9c55
Generalize uuidRegex0969950
adds ctx to preprocess (#2426)af08390
fix: super refinement function types (#2420)36fef58
Make email regex reasonable (#2157)f627d14
Document canarye06321c
docs: add tapiduck to API libraries (#2410)11e507c
docs: add ts as const example in zod enums (#2412)5427565
docs: add zod-fixture to mocking ecosystem (#2409)d3bf7e6
docs: addzodock
to mocking ecosystem (#2394)2270ae5
remove "as any" casts in createZodEnum (#2332)00bdd0a
fix proto pollution vulnerability (#2239)a3c5256
Fix error_handling unrecognized_keys example4f75cbc
Adds getters to Map for key + value (#2356)ca7b032
FMC (#2346)6fec8bd
docs: fix typo in link fragment (#2329)16f90bd
Update README.md2c80250
Update readmeeaf64e0
Update sponsorsc576311
Update readme5e23b4f
Add*.md
pattern to prettier (#2476)898dced
Revamp tests6309322
Update test runnersc0aece1
Add vitest config73a5610
Update script8d8e1a2
Fix deno test bug9eb2508
Clean up configscfbc7b3
Fix root jest config8677f68
docs(comparison-yup): Yup added partial() and deepPartial() in v1 (#2603)fb00edd
docs: add VeeValidate form library for Vue.js (#2578)ab8e717
docs: fix typo in z.object (#2570)d870407
docs: fix incomplete Records example (#2579)5adae24
docs: add conform form integration (#2577)8b8ab3e
Update README.md (#2562)6aab901
fix typo test name (#2542)81a89f5
Update nullish documentation to correct chaining order (#2457)78a4090
docs: update comparison withruntypes
(#2536)1ecd624
Fix prettier981d4b5
Add ZodReadonly (#2634)fba438c
3.22.0Configuration
📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.