Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency semantic-release to 17.2.3 [security] #222

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Nov 27, 2020

Mend Renovate

This PR contains the following updates:

Package Change
semantic-release 15.14.0 -> 17.2.3

GitHub Vulnerability Alerts

CVE-2020-26226

Impact

Secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that become encoded when included in a URL.

Patches

Fixed in v17.2.3

Workarounds

Secrets that do not contain characters that become encoded when included in a URL are already masked properly.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate
Copy link
Contributor Author

renovate bot commented Nov 27, 2020

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻️ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you check the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json
Unable to find image 'renovate/node:10.21.0' locally
10.21.0: Pulling from renovate/node
23884877105a: Pulling fs layer
bc38caa0f5b9: Pulling fs layer
2910811b6c42: Pulling fs layer
36505266dcc6: Pulling fs layer
35303b102bed: Pulling fs layer
5709091d716c: Pulling fs layer
9e568ac7fb42: Pulling fs layer
d53c5908b81b: Pulling fs layer
65493e024a36: Pulling fs layer
a46f2f0c7998: Pulling fs layer
4cf51dfde572: Pulling fs layer
853f92c74184: Pulling fs layer
5e8ddd24aba3: Pulling fs layer
ff2e60f54531: Pulling fs layer
204c8fcfef89: Pulling fs layer
e66113faa851: Pulling fs layer
42dc6a7e31de: Pulling fs layer
36505266dcc6: Waiting
35303b102bed: Waiting
5709091d716c: Waiting
9e568ac7fb42: Waiting
d53c5908b81b: Waiting
65493e024a36: Waiting
a46f2f0c7998: Waiting
4cf51dfde572: Waiting
853f92c74184: Waiting
5e8ddd24aba3: Waiting
ff2e60f54531: Waiting
204c8fcfef89: Waiting
e66113faa851: Waiting
42dc6a7e31de: Waiting
bc38caa0f5b9: Verifying Checksum
bc38caa0f5b9: Download complete
2910811b6c42: Verifying Checksum
2910811b6c42: Download complete
36505266dcc6: Verifying Checksum
36505266dcc6: Download complete
35303b102bed: Verifying Checksum
35303b102bed: Download complete
23884877105a: Verifying Checksum
23884877105a: Download complete
9e568ac7fb42: Verifying Checksum
9e568ac7fb42: Download complete
5709091d716c: Verifying Checksum
5709091d716c: Download complete
d53c5908b81b: Verifying Checksum
d53c5908b81b: Download complete
a46f2f0c7998: Verifying Checksum
a46f2f0c7998: Download complete
853f92c74184: Verifying Checksum
853f92c74184: Download complete
4cf51dfde572: Verifying Checksum
4cf51dfde572: Download complete
65493e024a36: Verifying Checksum
65493e024a36: Download complete
5e8ddd24aba3: Verifying Checksum
5e8ddd24aba3: Download complete
ff2e60f54531: Verifying Checksum
ff2e60f54531: Download complete
204c8fcfef89: Verifying Checksum
204c8fcfef89: Download complete
e66113faa851: Verifying Checksum
e66113faa851: Download complete
42dc6a7e31de: Verifying Checksum
42dc6a7e31de: Download complete
23884877105a: Pull complete
bc38caa0f5b9: Pull complete
2910811b6c42: Pull complete
36505266dcc6: Pull complete
35303b102bed: Pull complete
5709091d716c: Pull complete
9e568ac7fb42: Pull complete
d53c5908b81b: Pull complete
65493e024a36: Pull complete
a46f2f0c7998: Pull complete
4cf51dfde572: Pull complete
853f92c74184: Pull complete
5e8ddd24aba3: Pull complete
ff2e60f54531: Pull complete
204c8fcfef89: Pull complete
e66113faa851: Pull complete
42dc6a7e31de: Pull complete
Digest: sha256:f2e366290a65a0a031d7ff26e895dc8c62e5e70624fa280f74d74567d7985166
Status: Downloaded newer image for renovate/node:10.21.0
npm WARN deprecated [email protected]: request has been deprecated, see https://github.com/request/request/issues/3142
npm WARN deprecated [email protected]: this library is no longer supported

@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 7cbabae to b323910 Compare March 26, 2022 14:01
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v17 [security] chore(deps): update dependency semantic-release to v17.2.3 [security] Mar 26, 2022
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v17.2.3 [security] chore(deps): update dependency semantic-release to 17.2.3 [security] Mar 29, 2022
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to 17.2.3 [security] chore(deps): update dependency semantic-release to 17.2.3 [security] - autoclosed Apr 6, 2022
@renovate renovate bot closed this Apr 6, 2022
@renovate renovate bot deleted the renovate/npm-semantic-release-vulnerability branch April 6, 2022 16:27
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to 17.2.3 [security] - autoclosed chore(deps): update dependency semantic-release to 17.2.3 [security] Apr 6, 2022
@renovate renovate bot reopened this Apr 6, 2022
@renovate renovate bot restored the renovate/npm-semantic-release-vulnerability branch April 6, 2022 19:37
@renovate
Copy link
Contributor Author

renovate bot commented Mar 24, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant