Skip to content
This repository has been archived by the owner on Mar 26, 2022. It is now read-only.

Update dependency npm-registry-fetch to 4.0.5 [SECURITY] #309

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 3, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change
npm-registry-fetch 3.9.0 -> 4.0.5

GitHub Vulnerability Alerts

GHSA-jmqm-f2gx-4fjv

Affected versions of npm-registry-fetch are vulnerable to an information exposure vulnerability through log files. The cli supports URLs like <protocol>://[<user>[:<password>]@&#8203;]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled due to failing status checks.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 21 times, most recently from 131c3e0 to 865f977 Compare March 8, 2021 23:31
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 3 times, most recently from 6f6b96b to 218a805 Compare March 19, 2021 04:38
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 4 times, most recently from 8b54d75 to 230d609 Compare March 30, 2021 09:05
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch from 230d609 to c45f974 Compare April 19, 2021 20:04
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch from c45f974 to 4ec6b77 Compare May 4, 2021 23:44
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 9 times, most recently from db3cd71 to 8b1c406 Compare May 7, 2021 22:17
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 4 times, most recently from 023220f to e5ec866 Compare May 29, 2021 02:32
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 4 times, most recently from 9e186f8 to 5a59e2c Compare June 15, 2021 16:43
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 3 times, most recently from 3ec1a9e to 7964b87 Compare August 11, 2021 01:33
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch from 7964b87 to 26c4278 Compare October 8, 2021 01:13
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 2 times, most recently from 9d87e8f to 626e910 Compare October 26, 2021 04:41
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch from 626e910 to b052d83 Compare October 26, 2021 05:05
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant