Skip to content

fix(deps): update dependency pg-native to v3.0.1 [security]#69

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-pg-native-vulnerability
Open

fix(deps): update dependency pg-native to v3.0.1 [security]#69
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-pg-native-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate bot commented Sep 25, 2022

This PR contains the following updates:

Package Change Age Confidence
pg-native (source) 3.0.03.0.1 age confidence

GitHub Vulnerability Alerts

CVE-2022-25852

pg-native before 3.0.1 and libpq before 1.8.10 are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. Note: pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.


Release Notes

brianc/node-postgres (pg-native)

v3.0.1

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the security label Sep 25, 2022
@renovate renovate bot changed the title fix(deps): update dependency pg-native to v3.0.1 [security] fix(deps): update dependency pg-native to v3.0.1 [security] - autoclosed Dec 8, 2024
@renovate renovate bot closed this Dec 8, 2024
@renovate renovate bot deleted the renovate/npm-pg-native-vulnerability branch December 8, 2024 18:43
@renovate renovate bot changed the title fix(deps): update dependency pg-native to v3.0.1 [security] - autoclosed fix(deps): update dependency pg-native to v3.0.1 [security] Dec 8, 2024
@renovate renovate bot reopened this Dec 8, 2024
@renovate renovate bot force-pushed the renovate/npm-pg-native-vulnerability branch from 9945316 to 3914ccf Compare August 10, 2025 14:13
@renovate renovate bot force-pushed the renovate/npm-pg-native-vulnerability branch from 3914ccf to 77e9728 Compare February 12, 2026 10:48
@renovate renovate bot force-pushed the renovate/npm-pg-native-vulnerability branch from 77e9728 to 58f797e Compare March 5, 2026 21:04
@renovate renovate bot changed the title fix(deps): update dependency pg-native to v3.0.1 [security] fix(deps): update dependency pg-native to v3.0.1 [security] - autoclosed Mar 27, 2026
@renovate renovate bot closed this Mar 27, 2026
@renovate renovate bot changed the title fix(deps): update dependency pg-native to v3.0.1 [security] - autoclosed fix(deps): update dependency pg-native to v3.0.1 [security] Mar 30, 2026
@renovate renovate bot reopened this Mar 30, 2026
@renovate renovate bot force-pushed the renovate/npm-pg-native-vulnerability branch 2 times, most recently from 58f797e to 914157f Compare March 30, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant