Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency semantic-release to v19.0.3 [security] #427

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jun 10, 2022

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
semantic-release 19.0.2 -> 19.0.3 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-31051

Impact

What kind of vulnerability is it? Who is impacted?

Secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by encodeURI. Occurrence is further limited to execution contexts where push access to the related repository is not available without modifying the repository url to inject credentials.

Patches

Has the problem been patched? What versions should users upgrade to?

Fixed in 19.0.3

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

Secrets that do not contain characters that are excluded from encoding with encodeURI when included in a URL are already masked properly.

References

Are there any links users can visit to find out more?

For more information

If you have any questions or comments about this advisory:


Release Notes

semantic-release/semantic-release (semantic-release)

v19.0.3

Compare Source

Bug Fixes
  • log-repo: use the original form of the repo url to remove the need to mask credentials (#​2459) (58a226f), closes #​2449

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Zagreb, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch 2 times, most recently from bffb11c to b1eaa9f Compare June 19, 2022 04:11
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from b1eaa9f to 0c7c33e Compare June 26, 2022 04:13
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] chore(deps): update dependency semantic-release to v19.0.3 [SECURITY] Jun 27, 2022
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [SECURITY] chore(deps): update dependency semantic-release to v19.0.3 [security] Jun 28, 2022
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch 2 times, most recently from 2c142e2 to 2ddd8cf Compare July 9, 2022 00:52
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 2ddd8cf to bf9928b Compare July 23, 2022 01:12
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from bf9928b to f844d69 Compare August 7, 2022 04:10
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from f844d69 to a6c504a Compare August 20, 2022 02:01
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch 2 times, most recently from 6bdb1e8 to f5a3449 Compare August 28, 2022 12:18
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from f5a3449 to 927dacb Compare September 24, 2022 03:12
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 927dacb to bc1082a Compare October 9, 2022 05:04
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from bc1082a to b786d5e Compare October 23, 2022 04:15
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from b786d5e to 7f10a66 Compare November 12, 2022 03:36
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 7f10a66 to 9222f88 Compare November 20, 2022 05:07
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 9222f88 to 621a7cb Compare December 4, 2022 06:16
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed Dec 14, 2022
@renovate renovate bot closed this Dec 14, 2022
@renovate renovate bot deleted the renovate/npm-semantic-release-vulnerability branch December 14, 2022 04:00
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed chore(deps): update dependency semantic-release to v19.0.3 [security] Dec 14, 2022
@renovate renovate bot reopened this Dec 14, 2022
@renovate renovate bot restored the renovate/npm-semantic-release-vulnerability branch December 14, 2022 06:10
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 621a7cb to dbf6d01 Compare December 18, 2022 06:39
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed Dec 30, 2022
@renovate renovate bot closed this Dec 30, 2022
@renovate renovate bot deleted the renovate/npm-semantic-release-vulnerability branch December 30, 2022 02:59
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed chore(deps): update dependency semantic-release to v19.0.3 [security] Dec 30, 2022
@renovate renovate bot reopened this Dec 30, 2022
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed Jan 29, 2023
@renovate renovate bot closed this Jan 29, 2023
@renovate renovate bot deleted the renovate/npm-semantic-release-vulnerability branch January 29, 2023 02:40
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed chore(deps): update dependency semantic-release to v19.0.3 [security] Jan 29, 2023
@renovate renovate bot restored the renovate/npm-semantic-release-vulnerability branch January 29, 2023 05:41
@renovate renovate bot reopened this Jan 29, 2023
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 060d4b8 to a50dc74 Compare February 4, 2023 02:17
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from a50dc74 to 2fd62e4 Compare February 12, 2023 08:42
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed Mar 3, 2023
@renovate renovate bot closed this Mar 3, 2023
@renovate renovate bot deleted the renovate/npm-semantic-release-vulnerability branch March 3, 2023 03:49
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed chore(deps): update dependency semantic-release to v19.0.3 [security] Mar 3, 2023
@renovate renovate bot reopened this Mar 3, 2023
@renovate renovate bot restored the renovate/npm-semantic-release-vulnerability branch March 3, 2023 07:13
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 2fd62e4 to 26c186b Compare March 4, 2023 08:20
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch 2 times, most recently from 0c14b2e to 0f4f9fa Compare March 12, 2023 05:04
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed Apr 27, 2023
@renovate renovate bot closed this Apr 27, 2023
@renovate renovate bot deleted the renovate/npm-semantic-release-vulnerability branch April 27, 2023 01:26
@renovate renovate bot changed the title chore(deps): update dependency semantic-release to v19.0.3 [security] - autoclosed chore(deps): update dependency semantic-release to v19.0.3 [security] Apr 27, 2023
@renovate renovate bot reopened this Apr 27, 2023
@renovate renovate bot restored the renovate/npm-semantic-release-vulnerability branch April 27, 2023 05:19
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 0f4f9fa to f5d9242 Compare April 27, 2023 05:20
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch 2 times, most recently from 37d5a73 to 502e4a2 Compare July 29, 2023 00:03
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch 2 times, most recently from 444c1ee to 35ebb5c Compare April 20, 2024 01:37
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 35ebb5c to 6958680 Compare April 21, 2024 06:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants