[Snyk] Upgrade posthog-js from 1.111.0 to 1.115.0 #1070

Closed
opened 2026-04-05 16:25:12 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 4/5/2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade posthog-js from 1.111.0 to 1.115.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 14 versions ahead of your current version.
  • The recommended version was released 22 days ago, on 2024-03-14.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
504/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 6.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: posthog-js
  • 1.115.0 - 2024-03-14

    1.115.0 - 2024-03-14

    • feat: track recording URL without pageview capture (#1076)
    • fix: return typing of global functions (#1081)
  • 1.114.2 - 2024-03-12

    1.114.2 - 2024-03-12

    • fix: patch rrweb zero width canvas bug (#1075)
  • 1.114.1 - 2024-03-12

    1.114.1 - 2024-03-12

    • fix: Disabled compression and application json (#1074)
  • 1.114.0 - 2024-03-12

    1.114.0 - 2024-03-12

    • feat: report browser visibility state in replay (#1071)
    • fix: typo in deny list (#1073)
    • fix(posthog-js): manually bump patch (#1072)
  • 1.113.4 - 2024-03-12

    1.113.4 - 2024-03-12

    • fix(posthog-js): manually bump patch (#1072)
    • fix: no empty requests (#1063)
  • 1.113.3 - 2024-03-12

    1.113.2 - 2024-03-11

    • fix: Send beacon request encoding (#1068)
  • 1.113.2 - 2024-03-11

    1.113.2 - 2024-03-11

    • fix: Send beacon request encoding (#1068)
  • 1.113.1 - 2024-03-11

    1.113.1 - 2024-03-11

    • fix: clarify redaction message (#1069)
  • 1.113.0 - 2024-03-11

    1.113.0 - 2024-03-11

    • feat: scrub payloads with forbidden words (#1059)
    • chore: remove unused path (#1066)
  • 1.112.1 - 2024-03-11

    1.112.1 - 2024-03-11

    • Fix compression (#1062)
  • 1.112.0 - 2024-03-08
  • 1.111.3 - 2024-03-07
  • 1.111.2 - 2024-03-06
  • 1.111.1 - 2024-03-06
  • 1.111.0 - 2024-03-05
from posthog-js GitHub release notes
Commit messages
Package name: posthog-js

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

*Originally created by @simlarsen on 4/5/2024* <p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to upgrade posthog-js from 1.111.0 to 1.115.0.</h3> :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project. <hr/> - The recommended version is **14 versions** ahead of your current version. - The recommended version was released **22 days ago**, on 2024-03-14. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- <img src="https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png" width="20" height="20" title="medium severity"/> | Information Exposure<br/> [SNYK-JS-FOLLOWREDIRECTS-6444610](https://snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6444610) | **504/1000** <br/> **Why?** Proof of Concept exploit, Recently disclosed, CVSS 6.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised. <details> <summary><b>Release notes</b></summary> <br/> <details> <summary>Package name: <b>posthog-js</b></summary> <ul> <li> <b>1.115.0</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.115.0">2024-03-14</a></br><h2>1.115.0 - 2024-03-14</h2> <ul> <li>feat: track recording URL without pageview capture (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2182652454" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1076" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1076/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1076">#1076</a>)</li> <li>fix: return typing of global functions (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2185968908" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1081" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1081/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1081">#1081</a>)</li> </ul> </li> <li> <b>1.114.2</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.114.2">2024-03-12</a></br><h2>1.114.2 - 2024-03-12</h2> <ul> <li>fix: patch rrweb zero width canvas bug (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2181670471" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1075" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1075/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1075">#1075</a>)</li> </ul> </li> <li> <b>1.114.1</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.114.1">2024-03-12</a></br><h2>1.114.1 - 2024-03-12</h2> <ul> <li>fix: Disabled compression and application json (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2181373880" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1074" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1074/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1074">#1074</a>)</li> </ul> </li> <li> <b>1.114.0</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.114.0">2024-03-12</a></br><h2>1.114.0 - 2024-03-12</h2> <ul> <li>feat: report browser visibility state in replay (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2180269248" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1071" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1071/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1071">#1071</a>)</li> <li>fix: typo in deny list (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2181341929" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1073" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1073/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1073">#1073</a>)</li> <li>fix(posthog-js): manually bump patch (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2180885871" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1072" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1072/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1072">#1072</a>)</li> </ul> </li> <li> <b>1.113.4</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.113.4">2024-03-12</a></br><h2>1.113.4 - 2024-03-12</h2> <ul> <li>fix(posthog-js): manually bump patch (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2180885871" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1072" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1072/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1072">#1072</a>)</li> <li>fix: no empty requests (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2176882915" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1063" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1063/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1063">#1063</a>)</li> </ul> </li> <li> <b>1.113.3</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.113.3">2024-03-12</a></br><h2>1.113.2 - 2024-03-11</h2> <ul> <li>fix: Send beacon request encoding (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2179202256" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1068" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1068/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1068">#1068</a>)</li> </ul> </li> <li> <b>1.113.2</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.113.2">2024-03-11</a></br><h2>1.113.2 - 2024-03-11</h2> <ul> <li>fix: Send beacon request encoding (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2179202256" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1068" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1068/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1068">#1068</a>)</li> </ul> </li> <li> <b>1.113.1</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.113.1">2024-03-11</a></br><h2>1.113.1 - 2024-03-11</h2> <ul> <li>fix: clarify redaction message (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2179336665" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1069" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1069/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1069">#1069</a>)</li> </ul> </li> <li> <b>1.113.0</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.113.0">2024-03-11</a></br><h2>1.113.0 - 2024-03-11</h2> <ul> <li>feat: scrub payloads with forbidden words (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2175991224" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1059" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1059/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1059">#1059</a>)</li> <li>chore: remove unused path (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2177964802" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1066" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1066/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1066">#1066</a>)</li> </ul> </li> <li> <b>1.112.1</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.112.1">2024-03-11</a></br><h2>1.112.1 - 2024-03-11</h2> <ul> <li>Fix compression (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2176456204" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1062" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1062/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1062">#1062</a>)</li> </ul> </li> <li> <b>1.112.0</b> - 2024-03-08 </li> <li> <b>1.111.3</b> - 2024-03-07 </li> <li> <b>1.111.2</b> - 2024-03-06 </li> <li> <b>1.111.1</b> - 2024-03-06 </li> <li> <b>1.111.0</b> - 2024-03-05 </li> </ul> from <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases">posthog-js GitHub release notes</a> </details> </details> <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>posthog-js</b></summary> <ul> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/b635a77f5dd9032cb51a32993e6c081df02359b0">b635a77</a> chore: Bump version to 1.115.0</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/cdb1fb9b921fcc590dea77a9f20dcc9ca4e3e2da">cdb1fb9</a> feat: track recording URL without pageview capture (#1076)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/f6442ef59c3c4858ffb8b50fa7263e4e997533b8">f6442ef</a> fix: return typing of global functions (#1081)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/18479b4ff36b709fc05c970ce392c23b1732381a">18479b4</a> chore: Bump version to 1.114.2</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/48e6e7b6919841e65fdc0b9c6b6720b7e6d4e5e4">48e6e7b</a> fix: patch rrweb zero width canvas bug (#1075)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/b9b07e8f8b04e176772137227f2e79c014ae1c70">b9b07e8</a> chore: Bump version to 1.114.1</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/27142bb9596aab4cc12f4defe74d28d96ea4b675">27142bb</a> fix: Disabled compression and application json (#1074)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/26dcfe6697f10f0609c654541fa00e89470357e5">26dcfe6</a> chore: Bump version to 1.114.0</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/ff634e32b5892737bf7296c1d25a48daca6a3d14">ff634e3</a> feat: report browser visibility state in replay (#1071)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/eab2aa001e546b5e2c3a62e703761062befd3bf4">eab2aa0</a> fix: typo in deny list (#1073)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/873f2622acc00473a6cffce45e07128221e884ef">873f262</a> chore: Bump version to 1.113.4</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/809dff3cfac7e95dcbafd5aa9b80851ded5bd789">809dff3</a> fix(posthog-js): manually bump patch (#1072)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/f22bd3d244be7c5c63d28b2b278f33170b4291b3">f22bd3d</a> fix: no empty requests (#1063)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/e45f2a74d95bec7d93838b5b9b975dd30b6a7117">e45f2a7</a> fix (#1070)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/6e045581af8153cc2f130dafb76c362f60ec8b99">6e04558</a> chore: Bump version to 1.113.2</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/ada306b69f878b60bf5697688030a8d0e00d6dfc">ada306b</a> fix: Send beacon request encoding (#1068)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/cdb16349c7c266287c8d121ab20d76e3a1ab18bc">cdb1634</a> chore: Bump version to 1.113.1</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/64bb26060eae09525a98a2c42c15752975d94b3e">64bb260</a> fix: clarify redaction message (#1069)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/5bdcec3e4361d1f5b35cc0e07296d3c48f904ffd">5bdcec3</a> chore: Bump version to 1.113.0</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/07b8c7b5a0eee0051955e57c18d8b72e6e7fc671">07b8c7b</a> feat: scrub payloads with forbidden words (#1059)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/832fe124e5fad00a54df83bd6c9ccdc9728fbbc4">832fe12</a> chore: remove unused path (#1066)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/142213214c55de188cae8e1756e5cd468ac13faa">1422132</a> chore: Bump version to 1.112.1</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/68bcb1d2223d6b559dc4db6f52183819109a1001">68bcb1d</a> Fix compression (#1062)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/2999fb627315672cd9ba172ca50acae2f2f2f3d0">2999fb6</a> chore: Bump version to 1.112.0</li> </ul> <a href="https://snyk.io/redirect/github/PostHog/posthog-js/compare/7c236692be8426d50ccc07ef21bcb4eac9d4232d...b635a77f5dd9032cb51a32993e6c081df02359b0">Compare</a> </details> </details> <hr/> **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI0ODNjM2U1My0wMmM1LTQ1MTgtYjUyMi0xMjAzNWI1YTdkMDciLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjQ4M2MzZTUzLTAyYzUtNDUxOC1iNTIyLTEyMDM1YjVhN2QwNyJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213/settings/integration?pkg&#x3D;posthog-js&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades) <!--- (snyk:metadata:{"prId":"483c3e53-02c5-4518-b522-12035b5a7d07","prPublicId":"483c3e53-02c5-4518-b522-12035b5a7d07","dependencies":[{"name":"posthog-js","from":"1.111.0","to":"1.115.0"}],"packageManager":"npm","type":"auto","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213?utm_source=github&utm_medium=referral&page=upgrade-pr","projectPublicId":"f6446ec8-d441-487e-b58f-38373430e213","env":"prod","prType":"upgrade","vulns":["SNYK-JS-FOLLOWREDIRECTS-6444610"],"issuesToFix":[{"issueId":"SNYK-JS-FOLLOWREDIRECTS-6444610","severity":"medium","title":"Information Exposure","exploitMaturity":"proof-of-concept","priorityScore":504,"priorityScoreFactors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"freshness","label":true,"score":71},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}]}],"upgrade":["SNYK-JS-FOLLOWREDIRECTS-6444610"],"upgradeInfo":{"versionsDiff":14,"publishedDate":"2024-03-14T13:17:11.203Z"},"templateVariants":["priorityScore"],"hasFixes":true,"isMajorUpgrade":false,"isBreakingChange":false,"priorityScoreList":[504]}) --->
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#1070