Skip to content
This repository has been archived by the owner on Nov 13, 2024. It is now read-only.

Update dependency nodejs/node to v20.15.1 #110

Merged
merged 2 commits into from
Jul 9, 2024

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 8, 2024

Mend Renovate

This PR contains the following updates:

Package Update Change
nodejs/node patch 20.15.0 -> 20.15.1

Release Notes

nodejs/node (nodejs/node)

v20.15.1: 2024-07-08, Version 20.15.1 'Iron' (LTS), @​RafaelGSS

Compare Source

This is a security release.

Notable Changes
  • CVE-2024-36138 - Bypass incomplete fix of CVE-2024-27980 (High)
  • CVE-2024-22020 - Bypass network import restriction via data URL (Medium)
  • CVE-2024-22018 - fs.lstat bypasses permission model (Low)
  • CVE-2024-36137 - fs.fchown/fchmod bypasses permission model (Low)
  • CVE-2024-37372 - Permission model improperly processes UNC paths (Low)
Commits

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies label Jul 8, 2024
@renovate renovate bot requested a review from a team as a code owner July 8, 2024 18:54
@pascalberger pascalberger enabled auto-merge (squash) July 9, 2024 07:53
Copy link

sonarqubecloud bot commented Jul 9, 2024

@pascalberger pascalberger merged commit 60105ed into develop Jul 9, 2024
10 checks passed
@pascalberger pascalberger deleted the renovate/nodejs-node-20.x branch July 9, 2024 07:54
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Development

Successfully merging this pull request may close these issues.

1 participant