Skip to content

chore(deps): update dependency mversion to v2 [security] - abandoned#169

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-mversion-vulnerability
Open

chore(deps): update dependency mversion to v2 [security] - abandoned#169
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-mversion-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jun 18, 2020

Copy link
Copy Markdown
Contributor

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
mversion 1.13.0 -> 2.0.1 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2020-4059

Impact

This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input.

Patches

Patched by version 2.0.0. Previous releases are deprecated in npm.

Workarounds

Make sure to escape git commit messages when using the commitMessage option for the update function.

CVE-2020-7688

The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.


Release Notes

mikaelbr/mversion

v2.0.1

Compare Source

v2.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate Bot force-pushed the renovate/npm-mversion-vulnerability branch from 104f370 to 15764cc Compare June 21, 2020 00:10
@renovate renovate Bot force-pushed the renovate/npm-mversion-vulnerability branch 2 times, most recently from fa819d9 to 7a5b68b Compare July 5, 2020 00:25
@renovate renovate Bot force-pushed the renovate/npm-mversion-vulnerability branch from 7a5b68b to 6693c0f Compare August 2, 2020 00:28
@renovate renovate Bot force-pushed the renovate/npm-mversion-vulnerability branch from 6693c0f to 1c245e8 Compare August 16, 2020 00:31
@renovate renovate Bot force-pushed the renovate/npm-mversion-vulnerability branch from 1c245e8 to 3864044 Compare June 6, 2021 19:53
@renovate renovate Bot force-pushed the renovate/npm-mversion-vulnerability branch from 3864044 to a321261 Compare April 25, 2022 02:35
@renovate

renovate Bot commented Mar 24, 2023

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@renovate renovate Bot changed the title chore(deps): update dependency mversion to v2 [security] chore(deps): update dependency mversion to v2 [security] - abandoned Mar 15, 2026
@renovate

renovate Bot commented Mar 15, 2026

Copy link
Copy Markdown
Contributor Author

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant