[Snyk] Upgrade posthog-js from 1.111.0 to 1.113.2 #1078

Closed
opened 2026-04-05 16:25:12 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 4/1/2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade posthog-js from 1.111.0 to 1.113.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 8 versions ahead of your current version.
  • The recommended version was released 21 days ago, on 2024-03-11.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
504/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 6.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: posthog-js
  • 1.113.2 - 2024-03-11

    1.113.2 - 2024-03-11

    • fix: Send beacon request encoding (#1068)
  • 1.113.1 - 2024-03-11

    1.113.1 - 2024-03-11

    • fix: clarify redaction message (#1069)
  • 1.113.0 - 2024-03-11

    1.113.0 - 2024-03-11

    • feat: scrub payloads with forbidden words (#1059)
    • chore: remove unused path (#1066)
  • 1.112.1 - 2024-03-11

    1.112.1 - 2024-03-11

    • Fix compression (#1062)
  • 1.112.0 - 2024-03-08

    1.112.0 - 2024-03-08

    • feat: Refactor request logic (#1055)
    • feat: Add more ad ids (#1057)
  • 1.111.3 - 2024-03-07

    1.111.3 - 2024-03-07

    • chore: Rework SDK initialisation (#1023)
  • 1.111.2 - 2024-03-06

    1.111.2 - 2024-03-06

    • feat: Ensure ingestion domains follow the same logic. (#1049)
  • 1.111.1 - 2024-03-06

    1.111.1 - 2024-03-06

    • chore: Removed jsc callbacks (#1052)
    • fix: posthog path to ignore (#1054)
    • chore: add some privacy examples to the copy autocapture demo (#1053)
  • 1.111.0 - 2024-03-05

    1.111.0 - 2024-03-05

    • feat: copy and cut autocapture (#1047)
    • fix: timezones are fun (#1050)
from posthog-js GitHub release notes
Commit messages
Package name: posthog-js

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

*Originally created by @simlarsen on 4/1/2024* <p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to upgrade posthog-js from 1.111.0 to 1.113.2.</h3> :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project. <hr/> - The recommended version is **8 versions** ahead of your current version. - The recommended version was released **21 days ago**, on 2024-03-11. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- <img src="https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png" width="20" height="20" title="medium severity"/> | Information Exposure<br/> [SNYK-JS-FOLLOWREDIRECTS-6444610](https://snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6444610) | **504/1000** <br/> **Why?** Proof of Concept exploit, Recently disclosed, CVSS 6.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised. <details> <summary><b>Release notes</b></summary> <br/> <details> <summary>Package name: <b>posthog-js</b></summary> <ul> <li> <b>1.113.2</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.113.2">2024-03-11</a></br><h2>1.113.2 - 2024-03-11</h2> <ul> <li>fix: Send beacon request encoding (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2179202256" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1068" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1068/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1068">#1068</a>)</li> </ul> </li> <li> <b>1.113.1</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.113.1">2024-03-11</a></br><h2>1.113.1 - 2024-03-11</h2> <ul> <li>fix: clarify redaction message (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2179336665" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1069" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1069/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1069">#1069</a>)</li> </ul> </li> <li> <b>1.113.0</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.113.0">2024-03-11</a></br><h2>1.113.0 - 2024-03-11</h2> <ul> <li>feat: scrub payloads with forbidden words (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2175991224" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1059" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1059/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1059">#1059</a>)</li> <li>chore: remove unused path (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2177964802" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1066" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1066/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1066">#1066</a>)</li> </ul> </li> <li> <b>1.112.1</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.112.1">2024-03-11</a></br><h2>1.112.1 - 2024-03-11</h2> <ul> <li>Fix compression (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2176456204" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1062" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1062/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1062">#1062</a>)</li> </ul> </li> <li> <b>1.112.0</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.112.0">2024-03-08</a></br><h2>1.112.0 - 2024-03-08</h2> <ul> <li>feat: Refactor request logic (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2169413067" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1055" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1055/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1055">#1055</a>)</li> <li>feat: Add more ad ids (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2174096851" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1057" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1057/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1057">#1057</a>)</li> </ul> </li> <li> <b>1.111.3</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.111.3">2024-03-07</a></br><h2>1.111.3 - 2024-03-07</h2> <ul> <li>chore: Rework SDK initialisation (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2133880103" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1023" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1023/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1023">#1023</a>)</li> </ul> </li> <li> <b>1.111.2</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.111.2">2024-03-06</a></br><h2>1.111.2 - 2024-03-06</h2> <ul> <li>feat: Ensure ingestion domains follow the same logic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2163268524" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1049" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1049/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1049">#1049</a>)</li> </ul> </li> <li> <b>1.111.1</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.111.1">2024-03-06</a></br><h2>1.111.1 - 2024-03-06</h2> <ul> <li>chore: Removed jsc callbacks (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2168974798" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1052" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1052/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1052">#1052</a>)</li> <li>fix: posthog path to ignore (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2169304294" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1054" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1054/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1054">#1054</a>)</li> <li>chore: add some privacy examples to the copy autocapture demo (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2169119583" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1053" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1053/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1053">#1053</a>)</li> </ul> </li> <li> <b>1.111.0</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.111.0">2024-03-05</a></br><h2>1.111.0 - 2024-03-05</h2> <ul> <li>feat: copy and cut autocapture (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2163065265" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1047" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1047/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1047">#1047</a>)</li> <li>fix: timezones are fun (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2163292240" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1050" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1050/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1050">#1050</a>)</li> </ul> </li> </ul> from <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases">posthog-js GitHub release notes</a> </details> </details> <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>posthog-js</b></summary> <ul> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/6e045581af8153cc2f130dafb76c362f60ec8b99">6e04558</a> chore: Bump version to 1.113.2</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/ada306b69f878b60bf5697688030a8d0e00d6dfc">ada306b</a> fix: Send beacon request encoding (#1068)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/cdb16349c7c266287c8d121ab20d76e3a1ab18bc">cdb1634</a> chore: Bump version to 1.113.1</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/64bb26060eae09525a98a2c42c15752975d94b3e">64bb260</a> fix: clarify redaction message (#1069)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/5bdcec3e4361d1f5b35cc0e07296d3c48f904ffd">5bdcec3</a> chore: Bump version to 1.113.0</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/07b8c7b5a0eee0051955e57c18d8b72e6e7fc671">07b8c7b</a> feat: scrub payloads with forbidden words (#1059)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/832fe124e5fad00a54df83bd6c9ccdc9728fbbc4">832fe12</a> chore: remove unused path (#1066)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/142213214c55de188cae8e1756e5cd468ac13faa">1422132</a> chore: Bump version to 1.112.1</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/68bcb1d2223d6b559dc4db6f52183819109a1001">68bcb1d</a> Fix compression (#1062)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/2999fb627315672cd9ba172ca50acae2f2f2f3d0">2999fb6</a> chore: Bump version to 1.112.0</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/fb32c34a8c588a82cc854d4e8fefab3934ff89d3">fb32c34</a> feat: Refactor request logic (#1055)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/083a453d8a3941f009f0519e8b00ff16c4caf35d">083a453</a> feat: Add more ad ids (#1057)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/abc2a17eeb20bdef8315bcc9cb75ff88426f1ae7">abc2a17</a> chore: Bump version to 1.111.3</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/f8c2b7633cb5a4888ca6c93474670908a353b453">f8c2b76</a> chore: Rework SDK initialisation (#1023)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/eb7bbd2e6bd5419e1a50b645d2594e515bafc134">eb7bbd2</a> chore: Bump version to 1.111.2</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/523576cb4482a7e2cf22e4aec845a4134b3106df">523576c</a> feat: Ensure ingestion domains follow the same logic. (#1049)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/8723e622fae2f5f97f28f49fd39d471123bafbb3">8723e62</a> chore: Bump version to 1.111.1</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/aa965e06a00cb9d9fbf3fdb766168ce189290ed8">aa965e0</a> chore: Removed jsc callbacks (#1052)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/7bd2c15e56818cc0485d222a749a0f427e26b9bc">7bd2c15</a> fix: posthog path to ignore (#1054)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/7c58b9e6de4dbaf79618f7600e9fca3dd2c0d32f">7c58b9e</a> chore: add some privacy examples to the copy autocapture demo (#1053)</li> </ul> <a href="https://snyk.io/redirect/github/PostHog/posthog-js/compare/7c236692be8426d50ccc07ef21bcb4eac9d4232d...6e045581af8153cc2f130dafb76c362f60ec8b99">Compare</a> </details> </details> <hr/> **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI0ODlhY2IxOS1iMGQ5LTQwNjEtYjJlNS1lNmM1MGFlNDRjMDYiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjQ4OWFjYjE5LWIwZDktNDA2MS1iMmU1LWU2YzUwYWU0NGMwNiJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213/settings/integration?pkg&#x3D;posthog-js&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades) <!--- (snyk:metadata:{"prId":"489acb19-b0d9-4061-b2e5-e6c50ae44c06","prPublicId":"489acb19-b0d9-4061-b2e5-e6c50ae44c06","dependencies":[{"name":"posthog-js","from":"1.111.0","to":"1.113.2"}],"packageManager":"npm","type":"auto","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213?utm_source=github&utm_medium=referral&page=upgrade-pr","projectPublicId":"f6446ec8-d441-487e-b58f-38373430e213","env":"prod","prType":"upgrade","vulns":["SNYK-JS-FOLLOWREDIRECTS-6444610"],"issuesToFix":[{"issueId":"SNYK-JS-FOLLOWREDIRECTS-6444610","severity":"medium","title":"Information Exposure","exploitMaturity":"proof-of-concept","priorityScore":504,"priorityScoreFactors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"freshness","label":true,"score":71},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}]}],"upgrade":["SNYK-JS-FOLLOWREDIRECTS-6444610"],"upgradeInfo":{"versionsDiff":8,"publishedDate":"2024-03-11T15:47:38.417Z"},"templateVariants":["priorityScore"],"hasFixes":true,"isMajorUpgrade":false,"isBreakingChange":false,"priorityScoreList":[504]}) --->
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#1078