chore(deps): bump i18next-resources-to-backend from 1.2.1 to 1.2.2 (#3309)
Bumps [i18next-resources-to-backend](https://github.com/i18next/i18next-resources-to-backend) from 1.2.1 to 1.2.2. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next-resources-to-backend/blob/main/CHANGELOG.md">i18next-resources-to-backend's changelog</a>.</em></p> <blockquote> <h3>1.2.2</h3> <ul> <li>security: validate <code>language</code> and <code>namespace</code> in <code>read()</code> before they are passed to the loader. i18next resolves any string as a language unless <code>supportedLngs</code> is set, so these values can carry whatever a language detector picked up from the querystring, path or a cookie. The documented usage pattern is <code>import(</code>./locales/${language}/${namespace}.json<code>)</code>, and while a bundler compiles that template to a fixed context map, an unbundled ESM runtime (Node SSR) resolves the specifier against the filesystem, where a crafted value escapes the locales directory. Values containing <code>..</code>, <code>\</code>, control characters, <code>__proto__</code> / <code>constructor</code> / <code>prototype</code>, or longer than 128 characters are now rejected with an error and the loader is never called; <code>/</code> is rejected for <code>language</code> but allowed for <code>namespace</code>, where nested layouts such as <code>a/b</code> are legitimate. The same check keeps the static-resources lookup off <code>Object.prototype</code>.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="7992601563"><code>7992601</code></a> 1.2.2</li> <li><a href="8b7240c588"><code>8b7240c</code></a> cosmetics</li> <li><a href="1d45d0b9d5"><code>1d45d0b</code></a> security: validate language/namespace before calling the loader</li> <li><a href="75a31f87a6"><code>75a31f8</code></a> README: mention npx i18next-cli localize as the zero-to-localized path</li> <li><a href="12858c7218"><code>12858c7</code></a> Add Locize advice section near the top of README</li> <li><a href="e3f24cd694"><code>e3f24cd</code></a> Modernize locize.com URLs and refresh UTM tags</li> <li><a href="33a1f29eba"><code>33a1f29</code></a> chore: ignore .env*, *.pem, *.key in .gitignore</li> <li>See full diff in <a href="https://github.com/i18next/i18next-resources-to-backend/compare/v1.2.1...v1.2.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: gsxdsm <gsxdsm@users.noreply.github.com>
This commit is contained in:
@@ -137,7 +137,7 @@
|
||||
"html2canvas": "^1.4.1",
|
||||
"i18next": "^26.3.1",
|
||||
"i18next-browser-languagedetector": "^8.2.1",
|
||||
"i18next-resources-to-backend": "^1.2.1",
|
||||
"i18next-resources-to-backend": "^1.2.2",
|
||||
"ioredis": "^5.6.0",
|
||||
"lucide-react": "^1.7.0",
|
||||
"mermaid": "^11.4.0",
|
||||
|
||||
10
pnpm-lock.yaml
generated
10
pnpm-lock.yaml
generated
@@ -350,8 +350,8 @@ importers:
|
||||
specifier: ^8.2.1
|
||||
version: 8.2.1
|
||||
i18next-resources-to-backend:
|
||||
specifier: ^1.2.1
|
||||
version: 1.2.1
|
||||
specifier: ^1.2.2
|
||||
version: 1.2.2
|
||||
ioredis:
|
||||
specifier: ^5.6.0
|
||||
version: 5.10.1
|
||||
@@ -5542,8 +5542,8 @@ packages:
|
||||
resolution: {integrity: sha512-n5UexwEVt0OoIAhG2MWpSnAVJW1U8mQrQTmXyxc5DMAx+NLhcLZhSMJo/FnUsA5JQ3obTYqTgB7YIuZKWpDgow==}
|
||||
hasBin: true
|
||||
|
||||
i18next-resources-to-backend@1.2.1:
|
||||
resolution: {integrity: sha512-okHbVA+HZ7n1/76MsfhPqDou0fptl2dAlhRDu2ideXloRRduzHsqDOznJBef+R3DFZnbvWoBW+KxJ7fnFjd6Yw==}
|
||||
i18next-resources-to-backend@1.2.2:
|
||||
resolution: {integrity: sha512-1qDy4c67qurkyLKXoFncMBB0XmXJE0GHoPCx7ONbDoq9R3puhjOpfUERbtWcwfulbXvxwdqWRmB4DIud+nLpuw==}
|
||||
|
||||
i18next@26.3.1:
|
||||
resolution: {integrity: sha512-txQqd5EULsqEh9OJqRH15aCaOuy/nLJyhw5EHCSKLKJE1aBbb3Zve2+uQIxgWhPm1QqUQoWyQBm2kfmmIrzkcQ==}
|
||||
@@ -12998,7 +12998,7 @@ snapshots:
|
||||
transitivePeerDependencies:
|
||||
- '@swc/helpers'
|
||||
|
||||
i18next-resources-to-backend@1.2.1:
|
||||
i18next-resources-to-backend@1.2.2:
|
||||
dependencies:
|
||||
'@babel/runtime': 7.29.7
|
||||
|
||||
|
||||
Reference in New Issue
Block a user