chore(deps): update dependency npm:renovate to v43.102.11 [security]#174
Merged
renovate-sh-app[bot] merged 1 commit intomainfrom Apr 16, 2026
Merged
Conversation
| datasource | package | from | to | | ---------- | -------- | ------- | --------- | | npm | renovate | 43.92.1 | 43.102.11 | Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
martincostello
approved these changes
Apr 16, 2026
Merged
zeitlinger
added a commit
that referenced
this pull request
Apr 16, 2026
### Added - *(release)* migrate from release-please to release-plz ([#171](#171)) ### Fixed - *(release)* use correct template variable in pr_body ([#178](#178)) - *(release)* suppress component prefix in release-please tags ([#166](#166)) - *(release)* add workflow_dispatch to retrigger for existing tags ([#167](#167)) ### Other - move icon to assets/ to fix release-plz ([#177](#177)) - *(deps)* update dependency npm:renovate to v43.102.11 [security] ([#174](#174)) - *(deps)* update rust crate similar to v3.1.0 ([#173](#173)) - *(deps)* update dependency github:mvdan/sh to v3.13.1 ([#163](#163)) > [!IMPORTANT] > Close and reopen this PR to trigger CI checks. --------- Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
This was referenced Apr 16, 2026
Closed
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
43.92.1→43.102.11Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance
GHSA-5vjq-5jmg-39xq
More information
Details
When using
lockFileMaintenanceusing the bazel-module or bazelisk managers between Renovate 43.65.0 (2026-03-12) and 43.102.11 (2026-04-02), there was the opportunity for remote code execution from a malicious dependency, if the Bazel module executes code that relies on a dependency.As this is an "unsafe" execution path, we have disabled this by default, and self-hosted administrators must add it to the
allowedUnsafeExecutionsallowlist.It is recommended to review whether you have enabled this functionality for these managers, and if so, whether any dependency updates may have led to remote code execution.
Impact
If Renovate suggested an update to a malicious dependency, and that dependency is referenced as part of the
bazel mod depscall - for instance as part of actx.executecall - this would call attacker-controlled code.This could lead to insider attackers and outside attackers, executing code that is distributed as part of the package.
Patches
This is patched in 43.102.11.
This does not affect any versions of Mend Renovate Self-Hosted.
Workarounds
lockFileMaintenancefor these managersWhy did this happen?
This was missed in code review (as part of https://github.com/renovatebot/renovate/pull/41507).
Severity
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
renovatebot/renovate (npm:renovate)
v43.102.11Compare Source
Bug Fixes
allowedUnsafeExecutionsforbazel mod deps(#42323) (4d2d86f)Build System
v43.102.10Compare Source
Build System
v43.102.9Compare Source
Bug Fixes
Miscellaneous Chores
v43.102.8Compare Source
Build System
v43.102.7Compare Source
Bug Fixes
v43.102.6Compare Source
Miscellaneous Chores
Build System
v43.102.5Compare Source
Bug Fixes
from:range toPackage.resolved(#42303) (35dbc3b)v43.102.4Compare Source
Documentation
Miscellaneous Chores
Build System
v43.102.3Compare Source
Bug Fixes
Miscellaneous Chores
v43.102.2Compare Source
Build System
v43.102.1Compare Source
Bug Fixes
v43.102.0Compare Source
Features
Bug Fixes
Miscellaneous Chores
Code Refactoring
applyHostRulesandapplyNpmrcto functions (#41528) (e7f55d7)v43.101.7Compare Source
Bug Fixes
v43.101.6Compare Source
Miscellaneous Chores
Build System
v43.101.5Compare Source
Bug Fixes
v43.101.4Compare Source
Bug Fixes
Documentation
extends(#42270) (c8adab2)Miscellaneous Chores
v43.101.3Compare Source
Bug Fixes
Documentation
depTypeseach manager supports (#42142) (2d239d2)Miscellaneous Chores
JSON.stringify'd message (#42241) (c04e7b1)Continuous Integration
v43.101.2Compare Source
Bug Fixes
Miscellaneous Chores
v43.101.1Compare Source
Documentation
Miscellaneous Chores
Code Refactoring
packageFiletoupdateDependency(#42253) (3953a78)Build System
v43.101.0Compare Source
Features
reportFormattingoption to format JSON reports with Prettier (#42162) (1b58cd6)v43.100.2Compare Source
Miscellaneous Chores
Build System
v43.100.1Compare Source
Documentation
Build System
v43.100.0Compare Source
Features
Bug Fixes
Documentation
Miscellaneous Chores
v43.99.1Compare Source
Bug Fixes
Miscellaneous Chores
Code Refactoring
correctnesscategory (#42218) (b79ea93)v43.99.0Compare Source
Features
Miscellaneous Chores
Code Refactoring
v43.98.0Compare Source
Features
v43.97.0Compare Source
Features
Miscellaneous Chores
v43.96.0Compare Source
Features
Miscellaneous Chores
Tests
v43.95.0Compare Source
Features
@wuchale/vite-plugin(#42036) (cb86e66)v43.94.1Compare Source
Bug Fixes
--beforeto npm install when minimumReleaseAge is set (#42198) (a74da77)Miscellaneous Chores
v43.94.0Compare Source
Features
v43.93.1Compare Source
Bug Fixes
readypush option to ensure changes are not wip (#40960) (1472cd9)Documentation
Code Refactoring
utils(#41673) (ec71601)v43.93.0Compare Source
Features
Bug Fixes
--version/--help(#42183) (93985c3)@tsconfig/nodereferences (#42189) (be016be)Miscellaneous Chores
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
Need help?
You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.