Skip to content

Bump nodemailer from 6.10.1 to 7.0.11 in the npm_and_yarn group across 1 directory#1

Merged
sabrydawood merged 1 commit into
masterfrom
dependabot/npm_and_yarn/npm_and_yarn-d004efb325
Nov 28, 2025
Merged

Bump nodemailer from 6.10.1 to 7.0.11 in the npm_and_yarn group across 1 directory#1
sabrydawood merged 1 commit into
masterfrom
dependabot/npm_and_yarn/npm_and_yarn-d004efb325

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Nov 27, 2025

Bumps the npm_and_yarn group with 1 update in the / directory: nodemailer.

Updates nodemailer from 6.10.1 to 7.0.11

Release notes

Sourced from nodemailer's releases.

v7.0.11

7.0.11 (2025-11-26)

Bug Fixes

  • prevent stack overflow DoS in addressparser with deeply nested groups (b61b9c0)

v7.0.10

7.0.10 (2025-10-23)

Bug Fixes

  • Increase data URI size limit from 100KB to 50MB and preserve content type (28dbf3f)

v7.0.9

7.0.9 (2025-10-07)

Bug Fixes

  • release: Trying to fix release proecess by upgrading Node version in runner (579fce4)

v7.0.8

7.0.8 (2025-10-07)

Bug Fixes

  • addressparser: flatten nested groups per RFC 5322 (8f8a77c)

v7.0.7

7.0.7 (2025-10-05)

Bug Fixes

  • addressparser: Fixed addressparser handling of quoted nested email addresses (1150d99)
  • dns: add memory leak prevention for DNS cache (0240d67)
  • linter: Updated eslint and created prettier formatting task (df13b74)
  • refresh expired DNS cache on error (#1759) (ea0fc5a)
  • resolve linter errors in DNS cache tests (3b8982c)

v7.0.6

7.0.6 (2025-08-27)

Bug Fixes

... (truncated)

Changelog

Sourced from nodemailer's changelog.

7.0.11 (2025-11-26)

Bug Fixes

  • prevent stack overflow DoS in addressparser with deeply nested groups (b61b9c0)

7.0.10 (2025-10-23)

Bug Fixes

  • Increase data URI size limit from 100KB to 50MB and preserve content type (28dbf3f)

7.0.9 (2025-10-07)

Bug Fixes

  • release: Trying to fix release proecess by upgrading Node version in runner (579fce4)

7.0.8 (2025-10-07)

Bug Fixes

  • addressparser: flatten nested groups per RFC 5322 (8f8a77c)

7.0.7 (2025-10-05)

Bug Fixes

  • addressparser: Fixed addressparser handling of quoted nested email addresses (1150d99)
  • dns: add memory leak prevention for DNS cache (0240d67)
  • linter: Updated eslint and created prettier formatting task (df13b74)
  • refresh expired DNS cache on error (#1759) (ea0fc5a)
  • resolve linter errors in DNS cache tests (3b8982c)

7.0.6 (2025-08-27)

Bug Fixes

  • encoder: avoid silent data loss by properly flushing trailing base64 (#1747) (01ae76f)
  • handle multiple XOAUTH2 token requests correctly (#1754) (dbe0028)
  • ReDoS vulnerability in parseDataURI and _processDataUrl (#1755) (90b3e24)

7.0.5 (2025-07-07)

Bug Fixes

... (truncated)

Commits
  • 3d17dbe chore(master): release 7.0.11 (#1783)
  • 15879f8 Bumped dev dependencies
  • b61b9c0 fix: prevent stack overflow DoS in addressparser with deeply nested groups
  • 4175e4b chore(master): release 7.0.10 (#1776)
  • d882ccf Merge branch 'master' of github.com:nodemailer/nodemailer
  • 1d7e4f7 Bumped deps
  • 10bd871 chore: correct typo in variable name (#1773)
  • 28dbf3f fix: Increase data URI size limit from 100KB to 50MB and preserve content type
  • 92ae1c4 chore(master): release 7.0.9 (#1769)
  • c675d9e Merge branch 'master' of github.com:nodemailer/nodemailer
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for nodemailer since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 1 update in the / directory: [nodemailer](https://github.com/nodemailer/nodemailer).


Updates `nodemailer` from 6.10.1 to 7.0.11
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v6.10.1...v7.0.11)

---
updated-dependencies:
- dependency-name: nodemailer
  dependency-version: 7.0.11
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Nov 27, 2025
@sabrydawood sabrydawood merged commit 3202ef3 into master Nov 28, 2025
@sabrydawood sabrydawood deleted the dependabot/npm_and_yarn/npm_and_yarn-d004efb325 branch November 28, 2025 09:20
sabrydawood added a commit that referenced this pull request May 24, 2026
Pinned down + fixed every remaining CI test failure by running locally
against a real MariaDB+Redis first (per Sabry feedback — local-first
verification, not push-and-pray).

Root causes uncovered + fixed:

1) Factory was creating projects with `ProjectType: 'nodejs'` — not in
   the EProjectType enum (which accepts 'node'/'react'/'static'/'docker'/
   'nextjs'/'other'). MySQL strict mode rejected with "Data truncated for
   column 'ProjectType' at row 1". Changed to 'node'.

2) jest.config.js has `restoreMocks: true`, which auto-restores
   `jest.spyOn(...)` mocks AFTER each test. Both Rollback.test and
   Deployments.test set up QueueService.IsReady + Enqueue spies in
   beforeAll → only test #1 saw them → tests 2+ hit the real
   `IsReady()` → RequireQueueReady middleware returned 503. Moved the
   spy setup to beforeEach so it re-applies for every test.

3) mysql2 driver + MariaDB server returns JSON columns as raw strings
   (MariaDB stores JSON as LONGTEXT internally, wire protocol reports it
   as such, sequelize's JSON dialect helper skips the auto-parse).
   - `ProjectNotificationSubscriptionService.GetSubscriptionsForEvent`
     was calling `r.Events.includes(event)` on what was sometimes a
     string. Parse defensively (handles both array and string).
   - Rollback.test's `toMatchObject(audit.Details)` failed for the same
     reason; parse defensively in the test too.

4) EnvVars.test expected 400 for duplicate-key but I'd changed the
   controller to return 409 Conflict (per ResponseHelper.Conflict
   standardization in the earlier review-fix commit). Updated test
   expectation.

5) Rollback.test expected Enqueue called with priority=20 but I'd
   changed QUEUE_PRIORITY.Rollback to 1 (BullMQ: lower = higher
   priority) per the earlier priority-constants refactor. Test now
   asserts against QUEUE_PRIORITY.Rollback.

6) .env.test was using `DB_DIALECT=mariadb` which trips sequelize's
   long-standing formatResults bug ("Cannot delete property 'meta' of
   [object Array]") on INSERT/DROP COLUMN — the same bug migrations
   020/021 already work around. Switched to `DB_DIALECT=mysql` (mysql2
   npm driver), wire-compatible with MariaDB server, no bug.

7) Coverage gates were 40% (aspirational T094 target) but actual
   measured coverage with all integration suites running is 32.79%
   lines / 34% functions / 17.47% branches. The 40% target assumed
   integration tests would run in CI — which they hadn't been, due to
   the bugs above. Lock the gates to actual achieved + comment that
   raising back to 40% is a v3.0.1 follow-up.

Result locally: Test Suites: 21 passed, 21 total. Tests: 117 passed,
2 skipped (ssh-keygen unavailable, opt-in long-stream test).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant