Skip to content

[Security] Bump @antfu/utils from 0.7.2 to 0.7.6

Dependabot requested to merge dependabot-npm_and_yarn-antfu-utils-0.7.6 into master

Bumps @antfu/utils from 0.7.2 to 0.7.6. This update includes a security fix.

Vulnerabilities fixed

antfu/utils vulnerable to prototype pollution Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.

Patched versions: 0.7.3 Affected versions: < 0.7.3

Release notes

Sourced from @​antfu/utils's releases.

v0.7.6

No release notes provided.

v0.7.5

Bug Fixes

  • deepMerge: override plain value (34cbabf)

Features

  • template: support object style templates (#34) (c7bbe2d)

v0.7.4

Features

v0.7.3

Bug Fixes

Features

  • deepMergeWithArray: new function (5b2b75c)
Commits


Dependabot commands
You can trigger Dependabot actions by commenting on this MR
  • $dependabot rebase will rebase this MR
  • $dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts

Merge request reports