Skip to content

chore(deps): update dependency npm:renovate to v43.102.11 [security]#174

Merged
renovate-sh-app[bot] merged 1 commit intomainfrom
grafanarenovatebot/npm-npm-renovate-vulnerability
Apr 16, 2026
Merged

chore(deps): update dependency npm:renovate to v43.102.11 [security]#174
renovate-sh-app[bot] merged 1 commit intomainfrom
grafanarenovatebot/npm-npm-renovate-vulnerability

Conversation

@renovate-sh-app
Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
npm:renovate (source) 43.92.143.102.11 age confidence

Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance

GHSA-5vjq-5jmg-39xq

More information

Details

When using lockFileMaintenance using the bazel-module or bazelisk managers between Renovate 43.65.0 (2026-03-12) and 43.102.11 (2026-04-02), there was the opportunity for remote code execution from a malicious dependency, if the Bazel module executes code that relies on a dependency.

As this is an "unsafe" execution path, we have disabled this by default, and self-hosted administrators must add it to the allowedUnsafeExecutions allowlist.

It is recommended to review whether you have enabled this functionality for these managers, and if so, whether any dependency updates may have led to remote code execution.

Impact

If Renovate suggested an update to a malicious dependency, and that dependency is referenced as part of the bazel mod deps call - for instance as part of a ctx.execute call - this would call attacker-controlled code.

This could lead to insider attackers and outside attackers, executing code that is distributed as part of the package.

Patches

This is patched in 43.102.11.

This does not affect any versions of Mend Renovate Self-Hosted.

Workarounds
  • Upgrade your Renovate version
  • Disable lockFileMaintenance for these managers
Why did this happen?

This was missed in code review (as part of https://github.com/renovatebot/renovate/pull/41507).

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

renovatebot/renovate (npm:renovate)

v43.102.11

Compare Source

Bug Fixes
  • bazel-module,bazelisk: add allowedUnsafeExecutions for bazel mod deps (#​42323) (4d2d86f)
Build System

v43.102.10

Compare Source

Build System

v43.102.9

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.33.3 (main) (#​42318) (aa2e7bf)
Miscellaneous Chores
  • deps: update dependency oxlint-tsgolint to v0.17.4 (main) (#​42316) (9535323)

v43.102.8

Compare Source

Build System

v43.102.7

Compare Source

Bug Fixes

v43.102.6

Compare Source

Miscellaneous Chores
Build System

v43.102.5

Compare Source

Bug Fixes

v43.102.4

Compare Source

Documentation
Miscellaneous Chores
Build System

v43.102.3

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.33.2 (main) (#​42299) (059db63)
Miscellaneous Chores
  • deps: update pdm-project/setup-pdm action to v4.5 (main) (#​42298) (21d4a04)

v43.102.2

Compare Source

Build System

v43.102.1

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.33.1 (main) (#​42294) (3883fc8)

v43.102.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.33.0 (main) (#​42292) (e914a5f)
Bug Fixes
Miscellaneous Chores
Code Refactoring

v43.101.7

Compare Source

Bug Fixes
  • http: fallback to github hostType for GHE platform endpoint (#​42287) (b8809ce)

v43.101.6

Compare Source

Miscellaneous Chores
  • deps: update docker/dockerfile docker tag to v1.23.0 (main) (#​42290) (5a77836)
Build System

v43.101.5

Compare Source

Bug Fixes

v43.101.4

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.32.2 (main) (#​42282) (37f8206)
  • presets: allow Aspire's organization move (#​42281) (502d11f)
Documentation
Miscellaneous Chores

v43.101.3

Compare Source

Bug Fixes
Documentation
Miscellaneous Chores
Continuous Integration

v43.101.2

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.32.1 (main) (#​42265) (b0f453d)
Miscellaneous Chores
  • deps: update dependency tar to v7.5.13 (main) (#​42256) (5cfbba3)
  • deps: update ghcr.io/containerbase/devcontainer docker tag to v14.6.9 (main) (#​42261) (d54e8da)

v43.101.1

Compare Source

Documentation
Miscellaneous Chores
Code Refactoring
Build System

v43.101.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.32.0 (main) (#​42252) (d1f917f)
  • dry-run: log commit contents (#​41718) (3951723)
  • report: add reportFormatting option to format JSON reports with Prettier (#​42162) (1b58cd6)

v43.100.2

Compare Source

Miscellaneous Chores
Build System

v43.100.1

Compare Source

Documentation
  • config: clarify commitMessagePrefix affects Dependency Dashboard (#​42236) (9a76a15)
Build System

v43.100.0

Compare Source

Features
Bug Fixes
  • swift: Parse pins without version key in Package.resolved (#​42220) (8ed5d0f)
Documentation
Miscellaneous Chores

v43.99.1

Compare Source

Bug Fixes
  • datasource/dart: Use npm versioning to make rangeStrategy=bump work again (#​42115) (ef9662a)
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.31.1 (main) (#​42226) (fa018c4)
Miscellaneous Chores
  • deps: update containerbase/internal-tools action to v4.5.6 (main) (#​42219) (d850027)
  • deps: update dependency markdownlint-cli2 to v0.22.0 (main) (#​42222) (8ae44af)
Code Refactoring

v43.99.0

Compare Source

Features
  • manager/kubernetes: extract image volume references from manifests (#​42038) (b438e57)
Miscellaneous Chores
Code Refactoring

v43.98.0

Compare Source

Features

v43.97.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.31.0 (main) (#​42211) (91049f0)
Miscellaneous Chores

v43.96.0

Compare Source

Features
Miscellaneous Chores
  • deps: update github/codeql-action action to v4.35.1 (main) (#​42209) (b6fa499)
Tests

v43.95.0

Compare Source

Features

v43.94.1

Compare Source

Bug Fixes
  • manager/npm: revert passing --before to npm install when minimumReleaseAge is set (#​42198) (a74da77)
Miscellaneous Chores
  • deps: update github/codeql-action action to v4.35.0 (main) (#​42200) (860230f)

v43.94.0

Compare Source

Features

v43.93.1

Compare Source

Bug Fixes
  • gerrit: use the ready push option to ensure changes are not wip (#​40960) (1472cd9)
Documentation
Code Refactoring

v43.93.0

Compare Source

Features
  • manager/npm: pass --before to npm install when minimumReleaseAge is set (#​42051) (c4d5697)
  • replacements: add replacement for Kotlin Logging maven package (#​42078) (b83db48)
Bug Fixes
  • cli: avoid printing logs on --version/--help (#​42183) (93985c3)
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.30.3 (main) (#​42191) (0ab23ef)
  • presets: allow short @tsconfig/node references (#​42189) (be016be)
  • use correct digest when replacing packages with replacementNameTemplate (#​40058) (f33f3f6)
Miscellaneous Chores

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Need help?

You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

| datasource | package  | from    | to        |
| ---------- | -------- | ------- | --------- |
| npm        | renovate | 43.92.1 | 43.102.11 |


Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@renovate-sh-app renovate-sh-app Bot merged commit a5d0556 into main Apr 16, 2026
14 checks passed
@renovate-sh-app renovate-sh-app Bot deleted the grafanarenovatebot/npm-npm-renovate-vulnerability branch April 16, 2026 08:28
@github-actions github-actions Bot mentioned this pull request Apr 16, 2026
zeitlinger added a commit that referenced this pull request Apr 16, 2026
### Added

- *(release)* migrate from release-please to release-plz
([#171](#171))

### Fixed

- *(release)* use correct template variable in pr_body
([#178](#178))
- *(release)* suppress component prefix in release-please tags
([#166](#166))
- *(release)* add workflow_dispatch to retrigger for existing tags
([#167](#167))

### Other

- move icon to assets/ to fix release-plz
([#177](#177))
- *(deps)* update dependency npm:renovate to v43.102.11 [security]
([#174](#174))
- *(deps)* update rust crate similar to v3.1.0
([#173](#173))
- *(deps)* update dependency github:mvdan/sh to v3.13.1
([#163](#163))

> [!IMPORTANT]
> Close and reopen this PR to trigger CI checks.

---------

Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
This was referenced Apr 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant