Update dependency chownr to v1 [SECURITY] - #7
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
January 11, 2025 11:48
e2c117d to
d4abe30
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
January 15, 2025 19:40
d4abe30 to
b091b3b
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
January 17, 2025 11:45
b091b3b to
8f97c37
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
January 25, 2025 11:49
8f97c37 to
b857fa9
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
January 26, 2025 06:13
b857fa9 to
e404ccd
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
2 times, most recently
from
February 1, 2025 19:46
81d4cd5 to
3b87c63
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
February 9, 2025 11:31
3b87c63 to
94fdee2
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
February 12, 2025 07:54
94fdee2 to
a00ad56
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
March 5, 2025 03:43
a00ad56 to
486a136
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
March 8, 2025 03:32
486a136 to
e9d9ca7
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
2 times, most recently
from
March 15, 2025 11:18
cab8057 to
3d75a7c
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
March 19, 2025 23:58
3d75a7c to
e17a203
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
March 21, 2025 23:48
e17a203 to
1dd6baf
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
May 17, 2025 04:01
e8545af to
fd8c54a
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
May 18, 2025 19:27
fd8c54a to
74bc40e
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
May 24, 2025 11:32
74bc40e to
bc4f6b5
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
May 25, 2025 11:37
bc4f6b5 to
3b5a181
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
May 31, 2025 12:11
3b5a181 to
f75cdd9
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
June 1, 2025 19:14
f75cdd9 to
23e5dca
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
June 6, 2025 18:22
23e5dca to
aadc79b
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
June 8, 2025 10:34
aadc79b to
18afd4c
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
June 21, 2025 12:03
18afd4c to
1dc1b40
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
July 13, 2025 23:55
1dc1b40 to
334bc32
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
August 11, 2025 03:26
334bc32 to
28ab24f
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
August 16, 2025 11:48
28ab24f to
9eb4404
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
August 21, 2025 04:15
9eb4404 to
7e8d0ab
Compare
renovate
Bot
force-pushed
the
renovate/npm-chownr-vulnerability
branch
from
August 24, 2025 04:11
7e8d0ab to
1b7b2ef
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0→1.1.0Time-of-check Time-of-use (TOCTOU) Race Condition in chownr
CVE-2017-18869 / GHSA-c6rq-rjc2-86v2
More information
Details
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
Severity
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
isaacs/chownr (chownr)
v1.1.0Compare Source
v1.0.1Compare Source
v1.0.0Compare Source
v0.0.2Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.