Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 19, 2024

This PR contains the following updates:

Package Type Update Change Age Confidence
node (source) patch 20.11.0 -> 20.11.1 age confidence
pnpm (source) uses-with patch 8.10.2 -> 8.10.5 age confidence
pnpm/action-setup action patch v2.4.0 -> v2.4.1 age confidence

Release Notes

nodejs/node (node)

v20.11.1: 2024-02-14, Version 20.11.1 'Iron' (LTS), @​RafaelGSS prepared by @​marco-ippolito

Compare Source

Notable changes

This is a security release.

Notable changes
  • CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
  • CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
  • CVE-2024-21896 - Path traversal by monkey-patching Buffer internals- (High)
  • CVE-2024-22017 - setuid() does not drop all privileges due to io_uring - (High)
  • CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
  • CVE-2024-21891 - Multiple permission model bypasses due to improper path traversal sequence sanitization - (Medium)
  • CVE-2024-21890 - Improper handling of wildcards in --allow-fs-read and --allow-fs-write (Medium)
  • CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
  • undici version 5.28.3
  • libuv version 1.48.0
  • OpenSSL version 3.0.13+quic1
Commits
pnpm/pnpm (pnpm)

v8.10.5

Compare Source

Patch Changes
  • Don't fail on an empty pnpm-workspace.yaml file #​7307.

v8.10.4

Compare Source

Patch Changes
  • Fixed out-of-memory exception that was happening on dependencies with many peer dependencies, when node-linker was set to hoisted #​6227.

v8.10.3

Compare Source

Patch Changes
  • (Important) Increased the default amount of allowed concurrent network request on systems that have more than 16 CPUs #​7285.

  • pnpm patch should reuse existing patch when shared-workspace-file=false #​7252.

  • Don't retry fetching missing packages, since the retries will never work #​7276.

  • When using pnpm store prune --force alien directories are removed from the store #​7272.

  • Downgraded npm-packlist because the newer version significantly slows down the installation of local directory dependencies, making it unbearably slow.

    npm-packlist was upgraded in this PR to fix #​6997. We added our own file deduplication to fix the issue of duplicate file entries.

  • Fixed a performance regression on running installation on a project with an up to date lockfile #​7297.

  • Throw an error on invalid pnpm-workspace.yaml file #​7273.

pnpm/action-setup (pnpm/action-setup)

v2.4.1

Compare Source

Updated the bundled pnpm version to v7 to fix the ERR_INVALID_THIS error.


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from sullivanpj as a code owner February 19, 2024 02:09
@renovate renovate bot enabled auto-merge (rebase) February 19, 2024 02:09
stormie-bot
stormie-bot previously approved these changes Feb 19, 2024
@renovate renovate bot changed the title chore(deps): update dependency node to v20.11.1 chore(deps): update dependencies-non-major (patch) Jul 8, 2024
@renovate renovate bot force-pushed the renovate/patch-dependencies-non-major branch from 12f61a3 to 3367f76 Compare July 8, 2024 01:16
stormie-bot
stormie-bot previously approved these changes Jul 8, 2024
@renovate renovate bot force-pushed the renovate/patch-dependencies-non-major branch from 3367f76 to 0a17a43 Compare August 11, 2025 00:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants