Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Bump https-proxy-agent from 2.2.1 to 2.2.4 #6803

Merged
merged 1 commit into from
Nov 18, 2019

Conversation

dependabot-preview[bot]
Copy link
Contributor

Bumps https-proxy-agent from 2.2.1 to 2.2.4. This update includes security fixes.

Vulnerabilities fixed

Sourced from The Node Security Working Group.

Man-in-the-Middle
[https-proxy-agent] Socket returned without TLS upgrade on non-200 CONNECT response, allowing request data to be sent over unencrypted connection

Affected versions: <2.2.3

Sourced from The npm Advisory Database.

Man-in-the-Middle (MitM)
Affected versions of this package are vulnerable to Man-in-the-Middle (MitM). When targeting a HTTP proxy, https-proxy-agent opens a socket to the proxy, and sends the proxy server a CONNECT request. If the proxy server responds with something other than a HTTP response 200, https-proxy-agent incorrectly returns the socket without any TLS upgrade. This request data may contain basic auth credentials or other secrets, is sent over an unencrypted connection. A suitably positioned attacker could steal these secrets and impersonate the client.

Affected versions: < 2.2.3

Release notes

Sourced from https-proxy-agent's releases.

2.2.4

Patches

  • Add .editorconfig file: a0d4a20458498fc31e5721471bd2b655e992d44b
  • Add .eslintrc.js file: eecea74a1db1c943eaa4f667a561fd47c33da897
  • Use a net.Socket instead of a plain EventEmitter for replaying proxy errors: #83
  • Remove unused stream module: 9fdcd47bd813e9979ee57920c69e2ee2e0683cd4

Credits

Huge thanks to @​lpinca for helping!

2.2.3

Patches

  • Update README with actual secureProxy behavior: #65
  • Update proxy to v1.0.0: d0e3c18079119057b05582cb72d4fda21dfc2546
  • Remove unreachable code: 46aad0988b471f042856436cf3192b0e09e36fe6
  • Test on Node.js 10 and 12: 3535951e482ea52af4888938f59649ed92e81b2b
  • Fix compatibility with Node.js >= 10.0.0: #73
  • Use an EventEmitter to replay failed proxy connect HTTP requests: #77

Credits

Huge thanks to @​stoically, @​lpinca, and @​zkochan for helping!

2.2.2

Patches

  • Remove package-lock.json: c881009b9873707f5c4a0e9c277dde588e1139c7
  • Ignore test directory, History.md and .travis.yml when creating npm package. Fixes #42: #45
  • Update agent-base to v4.2: #50
  • Add TypeScript type definitions: #66
  • Feat(typescript): Allow input to be options or string: #68
  • Update agent-base to v4.3: #69

Credits

Huge thanks to @​marco-c, @​tareqhs, @​ianhowe76, and @​BYK for helping!

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [https-proxy-agent](https://github.com/TooTallNate/node-https-proxy-agent) from 2.2.1 to 2.2.4. **This update includes security fixes.**
- [Release notes](https://github.com/TooTallNate/node-https-proxy-agent/releases)
- [Commits](TooTallNate/proxy-agents@2.2.1...2.2.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file JavaScript security labels Nov 18, 2019
@jywarren jywarren merged commit a5d3392 into master Nov 18, 2019
@dependabot-preview dependabot-preview bot deleted the dependabot/npm_and_yarn/https-proxy-agent-2.2.4 branch November 18, 2019 20:15
jywarren added a commit that referenced this pull request Nov 21, 2019
* new navbar but should mostly be in a feature

* Changed the hyperlink text in Login/Signup Model (#6364)

* Changed the hyperlink text in Login/Signup Model

Issue Number #6360

* Updated Hyperlink Text

* Updated Text in HyperLink

* Update _nodes.html.erb

* Functional Tests for Ordering aphabetically (#6371)

* test ordering of tags

* test that wikis are ordered alphabetically based on title

* Fix failing test on wiki test

* Change 'Read More' blog link to button (#6537)

* OpenGraph for Twitter

* Update _new_question.html.erb

* Add questions and comments to profile cards (#6472)

* add # notes, questions, comments to user profile

* fix codeclimate errors

* display correct node type at top of tag/author page

* fix /profile/comments/ to show by username

* add route for comments by tagname, link added in profile

* add styling to profile page cards

* refactored Node.find_by_tag_and_author to use Node.questions

* change display of note/question/comment links

* add unit test for Comment.find_by_tag_and_author

* add unit test for Node.find_by_tag_and_author

* add assert for questions type in test find by name and user id

* remove light grey footer background

* Removed style-breaking classes from table (#6374)

* Update 503.html - replace http with https (#6562)

* Update 502.html - replace http with https (#6561)

* Update 500.html - replace http with https (#6560)

* Update 422.html - replace http with https (#6559)

* Update 404.html - replace http with https (#6558)

* Update index.html - replace http with https (#6557)

* change the function named t(...) to translation(...) (#6580)

* Flow: Button to post marker + Popup working for multiple maps (#6591)

* init

* LEL pointed to different branch

* popups working

* removed forked leaflet

* button working great

* CSS changes of button

* CSS changed to orignal bootstrap button

* Updated the user.rb file to bootstrap italic (#6535)

* Update README.md file (#6510)

Added link to first-timers-only issue template.

* Fix comment spelling error (#6521)

* Fix icon color on btn-outline-secondary buttons #6518 (#6520)

* Bump chart.js from 2.8.0 to 2.9.1 (#6567)

Bumps [chart.js](https://github.com/chartjs/Chart.js) from 2.8.0 to 2.9.1.
- [Release notes](https://github.com/chartjs/Chart.js/releases)
- [Commits](chartjs/Chart.js@v2.8.0...v2.9.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Changed from function t to translation (#6609)

Issue resolved: Change function t to translation in dashboard/_node_comment #6600

* Update _edit.html.erb (#6583)

* Update _comments.html.erb (#6585)

I changed the function named t(....) to be named as translations(...).

* Update user.rb (#6587)

* Change function t to translation in dashboard/_node_wiki (#6607)

* Update_function t to translation in comments/_form (#6608)

* wiki/methods: Change t to translation in (#6564)

Changes the function name from t to translation in wiki/methods

Fixes #6540

* t(....) named as translations(...) on lines 25, 30, 35 and 38 (#6552)

* t(....) named as translations(...) on lines 25, 30, 35 and 38

* fix type translations to translation

* Change function t to translations in comments/_edit

* Revert "Change function t to translations in comments/_edit"

This reverts commit e858b75.

* changed t function name (#6546)

* changed t function name

* name fix

* change funcion t to translations in users/spamaway (#6545)

* change funcion t to translations in users/spamaway

* fix typo

* Change function t to translations in comments/comments #6538 (#6543)

* Change function t to translations

Change function t to translations in comments/comments

* Change translations to translation

* Update _node_meta.html.erb (#6606)

Changing method "t" to "translation"

* Fix follow button bug on tags (#6576)

* Fix bug on issue #6570

* Persist data

* Add co-authored posts to profile.html.erb (#6418)

* Add co-authored posts to profile.html.erb

* Update profile.html.erb

* Adjustments to tag graph labeling

* Update stats.html.erb

* Change function to to translation #6603 (#6659)

Change function t to translation in dashboard/_node_question #6603
#6603

* Refresh button (#6507)

* added tooltip for refresh button

* changes

* new changes1

* #6539 Updated t to translations. (#6544)

* Updated t to translations.

* Updated translations to translation.

Error in issue description.

* Changed t to translation in _node_moderate (#6695)

* some translations adjustments

* Add more tests for Node (for note and wiki page titles) (#6366)

* Add more tests for Node

* Prevent titles that are empty, blank or too short

* Update functional tests

* Add Redis installation to readme (#6398)

* Fix recent questions on shadow page (#6342)

* Add package.json, package-lock and test.sqlite-journal to gitingore #6384 (#6385)

* Make "choose one" link in comment forms appear underlined (#6401)

* Underline "choose one" link

Make "choose one" link in comment forms appear underlined #6399

* Add a CSS class to underline text

* Add !important to underline CSS class

* Fix rubocop errors in app/api & app/channels (#6425)

* Fix rubocop errors in app/api & app/channels

* Fix rubocop guardclause offenses

* Add tag link to show question (#6430)

* simple fix for link

* not sure what that file was

* removed redundant comment count being showed in blog section (#6746)

* Update t() function to translation() (#6729)

#6728

* Add redis installations for linux (#6751)

* Bump rake from 12.3.3 to 13.0.1 (#6764)

Bumps [rake](https://github.com/ruby/rake) from 12.3.3 to 13.0.1.
- [Release notes](https://github.com/ruby/rake/releases)
- [Changelog](https://github.com/ruby/rake/blob/master/History.rdoc)
- [Commits](ruby/rake@v12.3.3...v13.0.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Update _comments.html.erb (#6766)

* Update _comments.html.erb

Changed the t() to translation() in line 4, 18 and 21.

* Update _comments.html.erb

Changed the two translation() back to t() on line 18.

* Full screen button added in inline maps, Multiple maps in Wiki page works now. (#6699)

* full screen added

* working on wiki page

* code refactoring

* console logs removed

* inline map layers are ON by default now

* version bump of LEL to add new Layers

* api changed tagslocation init

* api taglocations changed

* popup content changed

* PL.editor shows map if lat,lon passed in URL. (#6788)

* pl-editor shows map

* indentation

* yarn.lock added for PL.editor

* safe traverse syntax used

* map API using common global variable. (#6802)

* done

* removed console logs

* [Security] Bump https-proxy-agent from 2.2.1 to 2.2.4 (#6803)

Bumps [https-proxy-agent](https://github.com/TooTallNate/node-https-proxy-agent) from 2.2.1 to 2.2.4. **This update includes security fixes.**
- [Release notes](https://github.com/TooTallNate/node-https-proxy-agent/releases)
- [Commits](TooTallNate/proxy-agents@2.2.1...2.2.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Update _thumbnail.html.erb to make it consistent with new card display (#6581)

* Update _thumbnail.html.erb

* Update style.css

* Update node_shared_test.rb

* Update _thumbnail.html.erb

* Update _notes.html.erb

* Update _notes.html.erb

* Update _notes.html.erb

* added ApplicationController.helpers.logged_in_as

* Update _notes.html.erb

* self.current_user in application_helper.rb

* Update application_helper.rb

* switch to "@current_user && ['admin','moderator'].includes?(@current_user.role)"

* PL.editor shows map if lat,lon passed in URL. (#6788)

* pl-editor shows map

* indentation

* yarn.lock added for PL.editor

* safe traverse syntax used

* handle nils

* Update _notes.html.erb

* new navbar but should mostly be in a feature

* some translations adjustments

* final navbar

* fixes for collapse menu

* fixes for collapse menu 2

* rest of menus
vinitshahdeo pushed a commit to vinitshahdeo/plots2 that referenced this pull request Feb 1, 2020
Bumps [https-proxy-agent](https://github.com/TooTallNate/node-https-proxy-agent) from 2.2.1 to 2.2.4. **This update includes security fixes.**
- [Release notes](https://github.com/TooTallNate/node-https-proxy-agent/releases)
- [Commits](TooTallNate/proxy-agents@2.2.1...2.2.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
vinitshahdeo pushed a commit to vinitshahdeo/plots2 that referenced this pull request Feb 1, 2020
* new navbar but should mostly be in a feature

* Changed the hyperlink text in Login/Signup Model (publiclab#6364)

* Changed the hyperlink text in Login/Signup Model

Issue Number publiclab#6360

* Updated Hyperlink Text

* Updated Text in HyperLink

* Update _nodes.html.erb

* Functional Tests for Ordering aphabetically (publiclab#6371)

* test ordering of tags

* test that wikis are ordered alphabetically based on title

* Fix failing test on wiki test

* Change 'Read More' blog link to button (publiclab#6537)

* OpenGraph for Twitter

* Update _new_question.html.erb

* Add questions and comments to profile cards (publiclab#6472)

* add # notes, questions, comments to user profile

* fix codeclimate errors

* display correct node type at top of tag/author page

* fix /profile/comments/ to show by username

* add route for comments by tagname, link added in profile

* add styling to profile page cards

* refactored Node.find_by_tag_and_author to use Node.questions

* change display of note/question/comment links

* add unit test for Comment.find_by_tag_and_author

* add unit test for Node.find_by_tag_and_author

* add assert for questions type in test find by name and user id

* remove light grey footer background

* Removed style-breaking classes from table (publiclab#6374)

* Update 503.html - replace http with https (publiclab#6562)

* Update 502.html - replace http with https (publiclab#6561)

* Update 500.html - replace http with https (publiclab#6560)

* Update 422.html - replace http with https (publiclab#6559)

* Update 404.html - replace http with https (publiclab#6558)

* Update index.html - replace http with https (publiclab#6557)

* change the function named t(...) to translation(...) (publiclab#6580)

* Flow: Button to post marker + Popup working for multiple maps (publiclab#6591)

* init

* LEL pointed to different branch

* popups working

* removed forked leaflet

* button working great

* CSS changes of button

* CSS changed to orignal bootstrap button

* Updated the user.rb file to bootstrap italic (publiclab#6535)

* Update README.md file (publiclab#6510)

Added link to first-timers-only issue template.

* Fix comment spelling error (publiclab#6521)

* Fix icon color on btn-outline-secondary buttons publiclab#6518 (publiclab#6520)

* Bump chart.js from 2.8.0 to 2.9.1 (publiclab#6567)

Bumps [chart.js](https://github.com/chartjs/Chart.js) from 2.8.0 to 2.9.1.
- [Release notes](https://github.com/chartjs/Chart.js/releases)
- [Commits](chartjs/Chart.js@v2.8.0...v2.9.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Changed from function t to translation (publiclab#6609)

Issue resolved: Change function t to translation in dashboard/_node_comment publiclab#6600

* Update _edit.html.erb (publiclab#6583)

* Update _comments.html.erb (publiclab#6585)

I changed the function named t(....) to be named as translations(...).

* Update user.rb (publiclab#6587)

* Change function t to translation in dashboard/_node_wiki (publiclab#6607)

* Update_function t to translation in comments/_form (publiclab#6608)

* wiki/methods: Change t to translation in (publiclab#6564)

Changes the function name from t to translation in wiki/methods

Fixes publiclab#6540

* t(....) named as translations(...) on lines 25, 30, 35 and 38 (publiclab#6552)

* t(....) named as translations(...) on lines 25, 30, 35 and 38

* fix type translations to translation

* Change function t to translations in comments/_edit

* Revert "Change function t to translations in comments/_edit"

This reverts commit e858b75.

* changed t function name (publiclab#6546)

* changed t function name

* name fix

* change funcion t to translations in users/spamaway (publiclab#6545)

* change funcion t to translations in users/spamaway

* fix typo

* Change function t to translations in comments/comments publiclab#6538 (publiclab#6543)

* Change function t to translations

Change function t to translations in comments/comments

* Change translations to translation

* Update _node_meta.html.erb (publiclab#6606)

Changing method "t" to "translation"

* Fix follow button bug on tags (publiclab#6576)

* Fix bug on issue publiclab#6570

* Persist data

* Add co-authored posts to profile.html.erb (publiclab#6418)

* Add co-authored posts to profile.html.erb

* Update profile.html.erb

* Adjustments to tag graph labeling

* Update stats.html.erb

* Change function to to translation publiclab#6603 (publiclab#6659)

Change function t to translation in dashboard/_node_question publiclab#6603
publiclab#6603

* Refresh button (publiclab#6507)

* added tooltip for refresh button

* changes

* new changes1

* publiclab#6539 Updated t to translations. (publiclab#6544)

* Updated t to translations.

* Updated translations to translation.

Error in issue description.

* Changed t to translation in _node_moderate (publiclab#6695)

* some translations adjustments

* Add more tests for Node (for note and wiki page titles) (publiclab#6366)

* Add more tests for Node

* Prevent titles that are empty, blank or too short

* Update functional tests

* Add Redis installation to readme (publiclab#6398)

* Fix recent questions on shadow page (publiclab#6342)

* Add package.json, package-lock and test.sqlite-journal to gitingore publiclab#6384 (publiclab#6385)

* Make "choose one" link in comment forms appear underlined (publiclab#6401)

* Underline "choose one" link

Make "choose one" link in comment forms appear underlined publiclab#6399

* Add a CSS class to underline text

* Add !important to underline CSS class

* Fix rubocop errors in app/api & app/channels (publiclab#6425)

* Fix rubocop errors in app/api & app/channels

* Fix rubocop guardclause offenses

* Add tag link to show question (publiclab#6430)

* simple fix for link

* not sure what that file was

* removed redundant comment count being showed in blog section (publiclab#6746)

* Update t() function to translation() (publiclab#6729)

publiclab#6728

* Add redis installations for linux (publiclab#6751)

* Bump rake from 12.3.3 to 13.0.1 (publiclab#6764)

Bumps [rake](https://github.com/ruby/rake) from 12.3.3 to 13.0.1.
- [Release notes](https://github.com/ruby/rake/releases)
- [Changelog](https://github.com/ruby/rake/blob/master/History.rdoc)
- [Commits](ruby/rake@v12.3.3...v13.0.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Update _comments.html.erb (publiclab#6766)

* Update _comments.html.erb

Changed the t() to translation() in line 4, 18 and 21.

* Update _comments.html.erb

Changed the two translation() back to t() on line 18.

* Full screen button added in inline maps, Multiple maps in Wiki page works now. (publiclab#6699)

* full screen added

* working on wiki page

* code refactoring

* console logs removed

* inline map layers are ON by default now

* version bump of LEL to add new Layers

* api changed tagslocation init

* api taglocations changed

* popup content changed

* PL.editor shows map if lat,lon passed in URL. (publiclab#6788)

* pl-editor shows map

* indentation

* yarn.lock added for PL.editor

* safe traverse syntax used

* map API using common global variable. (publiclab#6802)

* done

* removed console logs

* [Security] Bump https-proxy-agent from 2.2.1 to 2.2.4 (publiclab#6803)

Bumps [https-proxy-agent](https://github.com/TooTallNate/node-https-proxy-agent) from 2.2.1 to 2.2.4. **This update includes security fixes.**
- [Release notes](https://github.com/TooTallNate/node-https-proxy-agent/releases)
- [Commits](TooTallNate/proxy-agents@2.2.1...2.2.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Update _thumbnail.html.erb to make it consistent with new card display (publiclab#6581)

* Update _thumbnail.html.erb

* Update style.css

* Update node_shared_test.rb

* Update _thumbnail.html.erb

* Update _notes.html.erb

* Update _notes.html.erb

* Update _notes.html.erb

* added ApplicationController.helpers.logged_in_as

* Update _notes.html.erb

* self.current_user in application_helper.rb

* Update application_helper.rb

* switch to "@current_user && ['admin','moderator'].includes?(@current_user.role)"

* PL.editor shows map if lat,lon passed in URL. (publiclab#6788)

* pl-editor shows map

* indentation

* yarn.lock added for PL.editor

* safe traverse syntax used

* handle nils

* Update _notes.html.erb

* new navbar but should mostly be in a feature

* some translations adjustments

* final navbar

* fixes for collapse menu

* fixes for collapse menu 2

* rest of menus
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file JavaScript security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant