Skip to content
This repository has been archived by the owner on Feb 13, 2025. It is now read-only.

Update dependency node-fetch to v2.6.7 [SECURITY] #13

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Nov 15, 2022

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
node-fetch 2.6.1 -> 2.6.7 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-0235

node-fetch forwards secure headers such as authorization, www-authenticate, cookie, & cookie2 when redirecting to a untrusted site.


Release Notes

node-fetch/node-fetch (node-fetch)

v2.6.7

Compare Source

Security patch release

Recommended to upgrade, to not leak sensitive cookie and authentication header information to 3th party host while a redirect occurred

What's Changed

Full Changelog: node-fetch/node-fetch@v2.6.6...v2.6.7

v2.6.6

Compare Source

What's Changed

Full Changelog: node-fetch/node-fetch@v2.6.5...v2.6.6

v2.6.5

Compare Source

v2.6.4

Compare Source

v2.6.3

Compare Source

v2.6.2

Compare Source

fixed main path in package.json


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the renovate label Nov 15, 2022
@renovate renovate bot force-pushed the renovate/npm-node-fetch-vulnerability branch 2 times, most recently from 40ae5e5 to ad7a6a7 Compare January 18, 2023 01:35
@renovate renovate bot changed the title Update dependency node-fetch to v2.6.7 [SECURITY] Update dependency node-fetch to v2.6.7 [SECURITY] - autoclosed Jan 25, 2023
@renovate renovate bot closed this Jan 25, 2023
@renovate renovate bot deleted the renovate/npm-node-fetch-vulnerability branch January 25, 2023 03:36
@renovate renovate bot changed the title Update dependency node-fetch to v2.6.7 [SECURITY] - autoclosed Update dependency node-fetch to v2.6.7 [SECURITY] Jan 25, 2023
@renovate renovate bot reopened this Jan 25, 2023
@renovate renovate bot restored the renovate/npm-node-fetch-vulnerability branch January 25, 2023 06:34
@renovate renovate bot force-pushed the renovate/npm-node-fetch-vulnerability branch 2 times, most recently from 1e5ba40 to fb9d490 Compare February 2, 2023 06:06
@renovate
Copy link
Contributor Author

renovate bot commented Mar 24, 2023

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: yarn.lock
Error response from daemon: toomanyrequests: You have reached your pull rate limit. You may increase the limit by authenticating and upgrading: https://www.docker.com/increase-rate-limit

@renovate renovate bot force-pushed the renovate/npm-node-fetch-vulnerability branch from fb9d490 to 7e6dac6 Compare March 24, 2023 17:03
@renovate renovate bot force-pushed the renovate/npm-node-fetch-vulnerability branch from 7e6dac6 to bba2c68 Compare January 23, 2025 18:17
@renovate renovate bot requested a review from a team as a code owner January 23, 2025 18:17
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Development

Successfully merging this pull request may close these issues.

0 participants