Repository navigation
chore(deps): update dependency csp_evaluator to v1.1.8 - #431
renovate[bot] wants to merge 1 commit into
Conversation
✅ Deploy Preview for cn-devtools-app canceled.
|
53f132a to
5fe09ef
Compare
james-crabnebula
left a comment
There was a problem hiding this comment.
Lockfile moves csp_evaluator 1.1.5 -> 1.1.8 and nothing else (it has no dependencies). Apache-2.0. Our only use is clients/web/src/lib/security.ts (CspParser + CspEvaluator.evaluate()); that surface, the deep-import paths and the .d.ts files are byte-identical between the versions. 1.1.6 and 1.1.7 were published without a types field; 1.1.8 restores it, so this is the right target.
One behaviour change, from the shipped dist/csp.js: policyHasScriptNonces / policyHasScriptHashes now validate strictly (isNonce(val, true) / isHash(val, true)) and the hash pattern accepts base64url (_, -). Policies with malformed nonce or hash values are now treated as having none, which can change the strict-dynamic / allowlist findings, and valid base64url hashes are no longer flagged. No test imports security.ts, so the test job does not cover it; a quick manual look at the Security tab with a nonce- or hash-based CSP would close that gap. The audit failure is pre-existing on main and unrelated to this package.
This PR contains the following updates:
1.1.5→1.1.8Release Notes
google/csp-evaluator (csp_evaluator)
v1.1.8Compare Source
v1.1.7Compare Source
v1.1.6Compare Source
Configuration
📅 Schedule: (UTC)
* * 1 * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.