Update dependency semantic-release to v19 [SECURITY] - #13
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
March 5, 2024 05:32
de214ef to
118c61a
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
2 times, most recently
from
March 16, 2024 11:55
7131751 to
306341d
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
March 22, 2024 23:49
306341d to
080e33d
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
March 23, 2024 14:58
080e33d to
3baccf4
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
March 24, 2024 23:45
3baccf4 to
ee9eef2
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
March 25, 2024 23:49
ee9eef2 to
febadd3
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
April 15, 2024 05:49
febadd3 to
994a69b
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
April 17, 2024 05:37
994a69b to
a731a3b
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
April 21, 2024 20:55
a731a3b to
a0a320e
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
April 22, 2024 05:32
a0a320e to
f01425d
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
April 26, 2024 02:59
f01425d to
4dd79fc
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
April 27, 2024 11:56
4dd79fc to
be406c3
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
May 2, 2024 17:42
be406c3 to
e7e0874
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
May 3, 2024 02:15
e7e0874 to
bd36ee8
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
June 28, 2024 02:38
2dd85d3 to
25f26d4
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
June 29, 2024 08:27
25f26d4 to
78817a9
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
July 14, 2024 23:25
78817a9 to
2be1a1b
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
July 15, 2024 05:15
2be1a1b to
4d9d317
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
July 24, 2024 02:39
4d9d317 to
5afe85b
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
July 25, 2024 05:55
5afe85b to
663c475
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
2 times, most recently
from
July 30, 2024 08:29
567b1b4 to
d995ce8
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
October 10, 2024 14:57
d995ce8 to
94e084b
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
October 11, 2024 05:09
94e084b to
82335ce
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
2 times, most recently
from
October 31, 2024 05:38
2853cd3 to
1d97627
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
December 3, 2024 05:59
1d97627 to
733987a
Compare
renovate
Bot
force-pushed
the
renovate/npm-semantic-release-vulnerability
branch
from
December 5, 2024 23:48
733987a to
09e8eda
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^17.0.4→^19.0.3Exposure of Sensitive Information to an Unauthorized Actor in semantic-release
CVE-2022-31051 / GHSA-x2pg-mjhr-2m5x
More information
Details
Impact
What kind of vulnerability is it? Who is impacted?
Secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by encodeURI. Occurrence is further limited to execution contexts where push access to the related repository is not available without modifying the repository url to inject credentials.
Patches
Has the problem been patched? What versions should users upgrade to?
Fixed in 19.0.3
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
Secrets that do not contain characters that are excluded from encoding with
encodeURIwhen included in a URL are already masked properly.References
Are there any links users can visit to find out more?
For more information
If you have any questions or comments about this advisory:
Severity
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
semantic-release/semantic-release (semantic-release)
v19.0.3Compare Source
Bug Fixes
v19.0.2Compare Source
Bug Fixes
v19.0.1Compare Source
Bug Fixes
v19.0.0Compare Source
Bug Fixes
markedto resolve ReDos vulnerability (#2330) (d9e5bc0)BREAKING CHANGES
@semantic-release/npmhas also dropped support for node v15markedandmarked-terminalthat resolved the ReDoS vulnerability. removal of support of this node version should be low since it was not an LTS version and has been EOL for several months already.v18.0.1Compare Source
Bug Fixes
v18.0.0Compare Source
This is a maintenance release. An increasing amount of dependencies required a node version higher than the Node 10 version supported by
semantic-release@17. We decided to go straight to a recent Node LTS version because the release build is usually independent of others, requiring a higher node version is less disruptive to users, but helps us reduce the maintenance overhead.If you use GitHub Actions and need to bump the node version set up by
actions/node-setup, you can useoctoherd-script-bump-node-version-in-workflowsBREAKING CHANGES
node-version: the minimum required version of node is now v14.17
v17.4.7Compare Source
Bug Fixes
v17.4.6Compare Source
Bug Fixes
v17.4.5Compare Source
Bug Fixes
v17.4.4Compare Source
Bug Fixes
v17.4.3Compare Source
Bug Fixes
CVE-2021-23337(#1931) (55194c1)v17.4.2Compare Source
Bug Fixes
v17.4.1Compare Source
Bug Fixes
marked-terminal(#1829) (07f12b9)v17.4.0Compare Source
Features
v17.3.9Compare Source
Bug Fixes
v17.3.8Compare Source
Bug Fixes
v17.3.7Compare Source
Bug Fixes
v17.3.6Compare Source
Bug Fixes
v17.3.5Compare Source
Bug Fixes
v17.3.4Compare Source
Bug Fixes
v17.3.3Compare Source
Bug Fixes
v17.3.2Compare Source
Bug Fixes
v17.3.1Compare Source
Bug Fixes
v17.3.0Compare Source
Features
v17.2.4Compare Source
Bug Fixes
v17.2.3Compare Source
Bug Fixes
v17.2.2Compare Source
Bug Fixes
v17.2.1Compare Source
Reverts
v17.2.0Compare Source
Features
v17.1.2Compare Source
Bug Fixes
v17.1.1Compare Source
Bug Fixes
v17.1.0Compare Source
Features
v17.0.8Compare Source
Bug Fixes
v17.0.7Compare Source
Bug Fixes
v17.0.6Compare Source
Bug Fixes
v17.0.5Compare Source
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.