Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency npm to v6.14.6 [SECURITY] - autoclosed #1025

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Aug 4, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
npm (source) 6.13.6 -> 6.14.6 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2020-15095

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like <protocol>://[<user>[:<password>]@&#8203;]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.


Release Notes

npm/cli (npm)

v6.14.6

Compare Source

6.14.6 (2020-07-07)

BUG FIXES
DEPENDENCIES

v6.14.5

Compare Source

6.14.5 (2020-05-04)

BUG FIXES
DEPENDENCIES

v6.14.4

Compare Source

6.14.4 (2020-03-25)

DEPENDENCIES
  • 136832dca mkdirp@0.5.4
  • Bump minimist@1.2.5 transitive dep to resolve security issue
    • 9c554fd8c update-notifier@2.5.0
    • bump deep-extend@1.2.5
    • bump is-ci@1.2.1
    • bump is-retry-allowed@1.2.0
    • bump rc@1.2.8
    • bump registry-auth-token@3.4.0
    • bump widest-line@2.0.1
  • 8bf99b2b5 #​1053 deps: updates term-size to use signed binary

v6.14.3

Compare Source

6.14.3 (2020-03-19)

DOCUMENTATION
DEPENDENCIES

v6.14.2

Compare Source

6.14.2 (2020-03-03)

DOCUMENTATION
DEPENDENCIES

v6.14.1

Compare Source

6.14.1 (2020-02-26)

  • 303e5c11e hosted-git-info@2.8.7 Fixes a regression where scp-style git urls are passed to the WhatWG URL parser, which does not handle them properly. (@​isaacs)

v6.14.0

Compare Source

6.14.0 (2020-02-25)

FEATURES
BUG FIXES
DEPENDENCIES
DOCUMENTATION
MISCELLANEOUS

v6.13.7

Compare Source

6.13.7 (2020-01-28)

BUG FIXES
DEPENDENCIES

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch 2 times, most recently from 8807e4c to 1af61fe Compare August 4, 2023 16:36
@oscrx oscrx force-pushed the main branch 2 times, most recently from 9381ad9 to 08e8e7a Compare August 4, 2023 23:37
@renovate renovate bot changed the title Update dependency npm to v6.14.6 [SECURITY] Update dependency npm to v6.14.6 [SECURITY] - autoclosed Aug 4, 2023
@renovate renovate bot closed this Aug 4, 2023
@renovate renovate bot deleted the renovate/npm-npm-vulnerability branch August 4, 2023 23:54
@renovate renovate bot changed the title Update dependency npm to v6.14.6 [SECURITY] - autoclosed Update dependency npm to v6.14.6 [SECURITY] Aug 5, 2023
@renovate renovate bot reopened this Aug 5, 2023
@renovate renovate bot restored the renovate/npm-npm-vulnerability branch August 5, 2023 00:10
@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch from 1af61fe to 4e3d733 Compare August 5, 2023 00:12
@codecov
Copy link

codecov bot commented Aug 5, 2023

Codecov Report

Patch and project coverage have no change.

Comparison is base (a502fca) 22.34% compared to head (5e270b2) 22.34%.
Report is 1 commits behind head on main.

❗ Current head 5e270b2 differs from pull request most recent head 0f18483. Consider uploading reports for the commit 0f18483 to get more accurate results

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1025   +/-   ##
=======================================
  Coverage   22.34%   22.34%           
=======================================
  Files          14       14           
  Lines         179      179           
  Branches       21       21           
=======================================
  Hits           40       40           
  Misses        121      121           
  Partials       18       18           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch 2 times, most recently from fd64316 to b86d4f1 Compare August 5, 2023 01:29
@oscrx oscrx force-pushed the main branch 3 times, most recently from 30c2322 to 255c6ae Compare August 5, 2023 01:48
@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch 6 times, most recently from dbe2f55 to 483d5e3 Compare August 5, 2023 10:12
@renovate
Copy link
Contributor Author

renovate bot commented Aug 5, 2023

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pils-frontend/package-lock.json
/usr/local/bin/docker: line 4: .: filename argument required
.: usage: . filename [arguments]
npm ERR! code ERESOLVE
npm ERR! ERESOLVE could not resolve
npm ERR! 
npm ERR! While resolving: copy-webpack-plugin@5.1.1
npm ERR! Found: webpack@3.12.0
npm ERR! node_modules/webpack
npm ERR!   dev webpack@"3.12.0" from the root project
npm ERR!   peer webpack@">=2" from babel-loader@8.0.6
npm ERR!   node_modules/babel-loader
npm ERR!     dev babel-loader@"8.0.6" from the root project
npm ERR!   7 more (extract-text-webpack-plugin, ...)
npm ERR! 
npm ERR! Could not resolve dependency:
npm ERR! peer webpack@"^4.0.0 || ^5.0.0" from copy-webpack-plugin@5.1.1
npm ERR! node_modules/copy-webpack-plugin
npm ERR!   dev copy-webpack-plugin@"5.1.1" from the root project
npm ERR! 
npm ERR! Conflicting peer dependency: webpack@5.88.2
npm ERR! node_modules/webpack
npm ERR!   peer webpack@"^4.0.0 || ^5.0.0" from copy-webpack-plugin@5.1.1
npm ERR!   node_modules/copy-webpack-plugin
npm ERR!     dev copy-webpack-plugin@"5.1.1" from the root project
npm ERR! 
npm ERR! Fix the upstream dependency conflict, or retry
npm ERR! this command with --force or --legacy-peer-deps
npm ERR! to accept an incorrect (and potentially broken) dependency resolution.
npm ERR! 
npm ERR! 
npm ERR! For a full report see:
npm ERR! /tmp/worker/f6eb40/048c02/cache/others/npm/_logs/2023-08-07T18_40_55_501Z-eresolve-report.txt

npm ERR! A complete log of this run can be found in: /tmp/worker/f6eb40/048c02/cache/others/npm/_logs/2023-08-07T18_40_55_501Z-debug-0.log

@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch from 483d5e3 to cd3db2c Compare August 5, 2023 12:12
@oscrx oscrx force-pushed the main branch 3 times, most recently from f9236fa to 1ac6805 Compare August 5, 2023 12:27
@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch from cbe3f2c to c673397 Compare August 6, 2023 20:30
@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch 3 times, most recently from e8412a1 to a38d124 Compare August 6, 2023 23:31
@oscrx oscrx force-pushed the main branch 3 times, most recently from 4e06394 to 369bee3 Compare August 6, 2023 23:53
@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch 5 times, most recently from ef17e45 to 338b085 Compare August 7, 2023 03:19
@oscrx oscrx force-pushed the main branch 2 times, most recently from 887a911 to 0984725 Compare August 7, 2023 03:23
@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch 8 times, most recently from 356bfea to 2c2c552 Compare August 7, 2023 18:21
@renovate renovate bot force-pushed the renovate/npm-npm-vulnerability branch from 2c2c552 to 0f18483 Compare August 7, 2023 18:41
@sonarcloud
Copy link

sonarcloud bot commented Aug 7, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@renovate renovate bot changed the title Update dependency npm to v6.14.6 [SECURITY] Update dependency npm to v6.14.6 [SECURITY] - autoclosed Aug 7, 2023
@renovate renovate bot closed this Aug 7, 2023
@renovate renovate bot deleted the renovate/npm-npm-vulnerability branch August 7, 2023 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants