-
Notifications
You must be signed in to change notification settings - Fork 14
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency mongodb to v4.17.0 [SECURITY] #1384
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-mongodb-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
September 19, 2023 10:04
8f6e8e8
to
2815e14
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
September 28, 2023 14:24
7842605
to
295f28b
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
October 15, 2023 15:49
fa8e862
to
7979c37
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
October 23, 2023 13:48
7979c37
to
948d2e1
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
November 6, 2023 07:29
948d2e1
to
331643d
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
November 16, 2023 11:06
331643d
to
cf82452
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
December 3, 2023 11:47
cf82452
to
a179498
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
February 4, 2024 11:35
68dbd37
to
633488a
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
February 25, 2024 09:51
633488a
to
2ef5666
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
March 12, 2024 10:59
2ef5666
to
d6b0e61
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
March 24, 2024 14:31
b78e5be
to
64e1a7e
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
April 14, 2024 10:42
64e1a7e
to
9ec4851
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
April 21, 2024 11:04
9ec4851
to
e2456ad
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 4, 2024 13:58
e2456ad
to
ddcf6e9
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
July 21, 2024 14:25
ddcf6e9
to
0dc31ac
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
August 6, 2024 06:08
0dc31ac
to
eadde7d
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
August 28, 2024 11:24
eadde7d
to
bd9e75e
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
October 9, 2024 08:15
bd9e75e
to
9ac1f93
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
December 2, 2024 08:42
9ac1f93
to
139b624
Compare
renovate
bot
changed the title
Update dependency mongodb to v4.17.0 [SECURITY]
Update dependency mongodb to v4.17.0 [SECURITY] - autoclosed
Dec 8, 2024
renovate
bot
changed the title
Update dependency mongodb to v4.17.0 [SECURITY] - autoclosed
Update dependency mongodb to v4.17.0 [SECURITY]
Dec 8, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
December 8, 2024 21:49
1cd4a64
to
139b624
Compare
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
December 9, 2024 01:49
139b624
to
d611bd7
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.3.0
->4.17.0
GitHub Vulnerability Alerts
CVE-2021-32050
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.
Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).
This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).
Release Notes
mongodb/node-mongodb-native (mongodb)
v4.17.0
Compare Source
The MongoDB Node.js team is pleased to announce version 4.17.0 of the
mongodb
package!Release Notes
mongodb-js/saslprep
is now installed by defaultUntil v6, the driver included the
saslprep
package as an optional dependency for SCRAM-SHA-256 authentication.saslprep
breaks when bundled with webpack because it attempted to read a file relative to the package location and consequently the driver would throw errors when using SCRAM-SHA-256 if it were bundled.The driver now depends on
mongodb-js/saslprep
, a fork ofsaslprep
that can be bundled with webpack because it includes the necessary saslprep data in memory upon loading. This will be installed by default but will only be used if SCRAM-SHA-256 authentication is used.Remove credential availability on
ConnectionPoolCreatedEvent
In order to avoid mistakenly printing credentials the
ConnectionPoolCreatedEvent
will replace the credentials option with an empty object. The credentials are still accessble via MongoClient options:client.options.credentials
.Features
Bug Fixes
Documentation
We invite you to try the
mongodb
library immediately, and report any issues to the NODE project.v4.16.0
Compare Source
The MongoDB Node.js team is pleased to announce version 4.16.0 of the
mongodb
package!Features
Bug Fixes
Documentation
We invite you to try the
mongodb
library immediately, and report any issues to the NODE project.v4.15.0
Compare Source
The MongoDB Node.js team is pleased to announce version 4.15.0 of the mongodb package!
Features
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.14.0
Compare Source
The MongoDB Node.js team is pleased to announce version 4.14.0 of the mongodb package!
Deprecations
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.13.0
Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.12.1
Compare Source
v4.12.0
Compare Source
Features
Bug Fixes
v4.11.0
Compare Source
Features
Bug Fixes
v4.10.0
Compare Source
Features
Bug Fixes
v4.9.1
Compare Source
The MongoDB Node.js team is pleased to announce version 4.9.1 of the mongodb package!
Release Highlights
This is a bug fix release as noted below.
Bug Fixes
v4.9.0
Compare Source
Features
Bug Fixes
oplogReplay
option as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.8.1
Compare Source
v4.8.0
Compare Source
Features
Bug Fixes
v4.7.0
Compare Source
Features
Bug Fixes
v4.6.0
Compare Source
Features
Bug Fixes
v4.5.0
Compare Source
Features
comment
field (#3167) (4e2f9bf)Bug Fixes
watch
type parameter to extendChangeStream
type parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.4.1
Compare Source
v4.4.0
Compare Source
Features
Bug Fixes
4.3.1 (2022-01-18)
Bug Fixes
v4.3.1
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.