Skip to content

chore(deps): update dependency semantic-release to v19 [security]#110

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-semantic-release-vulnerability
Open

chore(deps): update dependency semantic-release to v19 [security]#110
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-semantic-release-vulnerability

Conversation

@renovate
Copy link

@renovate renovate bot commented Jun 18, 2022

This PR contains the following updates:

Package Change Age Confidence
semantic-release 17.4.119.0.3 age confidence

GitHub Vulnerability Alerts

CVE-2022-31051

Impact

What kind of vulnerability is it? Who is impacted?

Secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by encodeURI. Occurrence is further limited to execution contexts where push access to the related repository is not available without modifying the repository url to inject credentials.

Patches

Has the problem been patched? What versions should users upgrade to?

Fixed in 19.0.3

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

Secrets that do not contain characters that are excluded from encoding with encodeURI when included in a URL are already masked properly.

References

Are there any links users can visit to find out more?

For more information

If you have any questions or comments about this advisory:


Release Notes

semantic-release/semantic-release (semantic-release)

v19.0.3

Compare Source

Bug Fixes
  • log-repo: use the original form of the repo url to remove the need to mask credentials (#​2459) (58a226f), closes #​2449

v19.0.2

Compare Source

Bug Fixes
  • npm-plugin: upgraded to the stable version (0eca144)

v19.0.1

Compare Source

Bug Fixes
  • npm-plugin: upgraded to the latest beta version (8097afb)

v19.0.0

Compare Source

Bug Fixes
  • npm-plugin: upgraded to the beta, which upgrades npm to v8 (f634b8c)
  • upgrade marked to resolve ReDos vulnerability (#​2330) (d9e5bc0)
BREAKING CHANGES
  • npm-plugin: @semantic-release/npm has also dropped support for node v15
  • node v15 has been removed from our defined supported versions of node. this was done to upgrade to compatible versions of marked and marked-terminal that resolved the ReDoS vulnerability. removal of support of this node version should be low since it was not an LTS version and has been EOL for several months already.

v18.0.1

Compare Source

Bug Fixes

v18.0.0

Compare Source

This is a maintenance release. An increasing amount of dependencies required a node version higher than the Node 10 version supported by semantic-release@17. We decided to go straight to a recent Node LTS version because the release build is usually independent of others, requiring a higher node version is less disruptive to users, but helps us reduce the maintenance overhead.

If you use GitHub Actions and need to bump the node version set up by actions/node-setup, you can use octoherd-script-bump-node-version-in-workflows

BREAKING CHANGES

node-version: the minimum required version of node is now v14.17

v17.4.7

Compare Source

Bug Fixes
  • engines: fixed defined node version to account for the higher requirement from the npm plugin (#​2088) (ea52e17)

v17.4.6

Compare Source

Bug Fixes

v17.4.5

Compare Source

Bug Fixes
  • deps: update dependency marked to v3 (6e4beb8)

v17.4.4

Compare Source

Bug Fixes

v17.4.3

Compare Source

Bug Fixes
  • bump minimal version of lodash to address CVE-2021-23337 (#​1931) (55194c1)

v17.4.2

Compare Source

Bug Fixes

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov
Copy link

codecov bot commented Jun 18, 2022

Codecov Report

Merging #110 (b020539) into master (13c6c93) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #110   +/-   ##
=======================================
  Coverage   96.47%   96.47%           
=======================================
  Files           6        6           
  Lines          85       85           
  Branches       11       11           
=======================================
  Hits           82       82           
  Partials        3        3           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 13c6c93...b020539. Read the comment docs.

@codecov-commenter
Copy link

codecov-commenter commented Aug 4, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.47%. Comparing base (13c6c93) to head (7678400).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #110   +/-   ##
=======================================
  Coverage   96.47%   96.47%           
=======================================
  Files           6        6           
  Lines          85       85           
  Branches       11       11           
=======================================
  Hits           82       82           
  Partials        3        3           

Continue to review full report in Codecov by Sentry.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 13c6c93...7678400. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch 2 times, most recently from 7d31bb7 to 0d67ec6 Compare August 13, 2025 11:49
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 0d67ec6 to 098e919 Compare August 19, 2025 12:44
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 098e919 to a1d3766 Compare September 25, 2025 20:07
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from a1d3766 to b92be7b Compare October 21, 2025 10:04
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from b92be7b to 61e01b4 Compare November 10, 2025 13:59
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 61e01b4 to e6394d4 Compare November 18, 2025 12:00
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from e6394d4 to f5d0ca2 Compare December 31, 2025 15:58
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from f5d0ca2 to a051b62 Compare January 19, 2026 18:25
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from a051b62 to 9f54504 Compare February 2, 2026 17:32
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 9f54504 to 6c0ee7f Compare February 12, 2026 11:52
@renovate renovate bot force-pushed the renovate/npm-semantic-release-vulnerability branch from 6c0ee7f to 7678400 Compare March 5, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant