Protractor NES Release Notes

Detailed release notes for Protractor NES (Never‑Ending Support), including security updates, bug fixes, and dependency updates.

Version 7.0.1 (NES)

Major dependency updates to address potential security concerns and ensure continued compatibility. The following dependencies were updated: chalk, glob, yargs, webdriver-manager, mocha, marked, lodash, jshint, and express.

Security Updates

The following CVEs and vulnerabilities were resolved:

PackageIssueDescription
adm-zipDirectory Traversal attackSecurity fix
ajvGHSA-v88g-cgmw-v5xwPrototype Pollution
body-parserGHSA-qwcr-r2fm-qrc7DoS with url encoding enabled
bracesGHSA-grv7-fg5c-xmjgUncontrolled resource consumption
chalk/ansi-regexGHSA-93q8-gq69-wqmwInefficient Regular Expression Complexity
cookieGHSA-pxg6-pf52-xh8xCookie validation fixes
copy-propsGHSA-897m-rjf5-jp39Prototype Pollution
decode-uri-componentGHSA-w573-4hg7-7wgqDenial of Service
expressGHSA-qw6h-vgh9-j6wxXSS via response.redirect()
expressGHSA-rv95-896h-c2vcRedirect in malformed URLs
flatGHSA-2j2x-2gpw-g8fmPrototype Pollution
glob-parentGHSA-ww39-953v-wcq6Regular Expression DoS
hosted-git-infoGHSA-43f8-2h32-f4cjRegular Expression DoS
iniGHSA-qqgx-2p2h-9c37Prototype Pollution
json-schemaGHSA-896r-f27r-55mwPrototype Pollution
json-schemaGHSA-36fh-84j7-cv5hPath Traversal via loadAsync
jszipGHSA-jg8v-48h5-wgxgPrototype Pollution
lodashGHSA-29mw-wpgm-hmr9Regular Expression DoS
lodashGHSA-p6mc-m468-83gwPrototype Pollution
markedGHSA-rrrm-qjm4-v8hfInefficient Regular Expression
markedGHSA-5v2h-r2cx-5xgjInefficient Regular Expression
micromatchGHSA-952p-6rrq-rcjvRegular Expression DoS
minimatchGHSA-f8q6-p94x-37v3Regular Expression DoS
minimistGHSA-xvch-5gv4-984hPrototype Pollution
path-parseGHSA-hj48-42vr-x3v9Regular Expression DoS
path-to-regexpGHSA-9wv6-86v2-598jBacktracking Regular Expressions
qsGHSA-hrpp-h998-j3ppPrototype Pollution
semverGHSA-c2qf-rxjj-qqgwRegular Expression DoS
sendGHSA-m6fv-jmcg-4jfgTemplate Injection
serve-staticGHSA-cm22-4g7w-348pTemplate Injection
shelljsGHSA-64g7-mvw6-v9qjImproper Privilege Management
shelljsGHSA-4rq4-32rv-6wp6Improper Privilege Management
y18nGHSA-c4w7-xm78-47vhPrototype Pollution
yargs-parserGHSA-p9pc-299p-vxgpPrototype Pollution

Version 7.0.0 (NES)

First release under HeroDevs Never Ending Support (NES).