chore(deps): update dependency renovate to v43.102.11 [security]#166
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency renovate to v43.102.11 [security]#166renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
76fd7af to
32a3011
Compare
32a3011 to
5d09ac0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
43.76.4→43.102.11Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance
GHSA-5vjq-5jmg-39xq
More information
Details
When using
lockFileMaintenanceusing the bazel-module or bazelisk managers between Renovate 43.65.0 (2026-03-12) and 43.102.11 (2026-04-02), there was the opportunity for remote code execution from a malicious dependency, if the Bazel module executes code that relies on a dependency.As this is an "unsafe" execution path, we have disabled this by default, and self-hosted administrators must add it to the
allowedUnsafeExecutionsallowlist.It is recommended to review whether you have enabled this functionality for these managers, and if so, whether any dependency updates may have led to remote code execution.
Impact
If Renovate suggested an update to a malicious dependency, and that dependency is referenced as part of the
bazel mod depscall - for instance as part of actx.executecall - this would call attacker-controlled code.This could lead to insider attackers and outside attackers, executing code that is distributed as part of the package.
Patches
This is patched in 43.102.11.
This does not affect any versions of Mend Renovate Self-Hosted.
Workarounds
lockFileMaintenancefor these managersWhy did this happen?
This was missed in code review (as part of https://github.com/renovatebot/renovate/pull/41507).
Severity
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
renovatebot/renovate (renovate)
v43.102.11Compare Source
Bug Fixes
allowedUnsafeExecutionsforbazel mod deps(#42323) (4d2d86f)Build System
v43.102.10Compare Source
Build System
v43.102.9Compare Source
Bug Fixes
Miscellaneous Chores
v43.102.8Compare Source
Build System
v43.102.7Compare Source
Bug Fixes
v43.102.6Compare Source
Miscellaneous Chores
Build System
v43.102.5Compare Source
Bug Fixes
from:range toPackage.resolved(#42303) (35dbc3b)v43.102.4Compare Source
Documentation
Miscellaneous Chores
Build System
v43.102.3Compare Source
Bug Fixes
Miscellaneous Chores
v43.102.2Compare Source
Build System
v43.102.1Compare Source
Bug Fixes
v43.102.0Compare Source
Features
Bug Fixes
Miscellaneous Chores
Code Refactoring
applyHostRulesandapplyNpmrcto functions (#41528) (e7f55d7)v43.101.7Compare Source
Bug Fixes
v43.101.6Compare Source
Miscellaneous Chores
Build System
v43.101.5Compare Source
Bug Fixes
v43.101.4Compare Source
Bug Fixes
Documentation
extends(#42270) (c8adab2)Miscellaneous Chores
v43.101.3Compare Source
Bug Fixes
Documentation
depTypeseach manager supports (#42142) (2d239d2)Miscellaneous Chores
JSON.stringify'd message (#42241) (c04e7b1)Continuous Integration
v43.101.2Compare Source
Bug Fixes
Miscellaneous Chores
v43.101.1Compare Source
Documentation
Miscellaneous Chores
Code Refactoring
packageFiletoupdateDependency(#42253) (3953a78)Build System
v43.101.0Compare Source
Features
reportFormattingoption to format JSON reports with Prettier (#42162) (1b58cd6)v43.100.2Compare Source
Miscellaneous Chores
Build System
v43.100.1Compare Source
Documentation
Build System
v43.100.0Compare Source
Features
Bug Fixes
Documentation
Miscellaneous Chores
v43.99.1Compare Source
Bug Fixes
Miscellaneous Chores
Code Refactoring
correctnesscategory (#42218) (b79ea93)v43.99.0Compare Source
Features
Miscellaneous Chores
Code Refactoring
v43.98.0Compare Source
Features
v43.97.0Compare Source
Features
Miscellaneous Chores
v43.96.0Compare Source
Features
Miscellaneous Chores
Tests
v43.95.0Compare Source
Features
@wuchale/vite-plugin(#42036) (cb86e66)v43.94.1Compare Source
Bug Fixes
--beforeto npm install when minimumReleaseAge is set (#42198) (a74da77)Miscellaneous Chores
v43.94.0Compare Source
Features
v43.93.1Compare Source
Bug Fixes
readypush option to ensure changes are not wip (#40960) (1472cd9)Documentation
Code Refactoring
utils(#41673) (ec71601)v43.93.0Compare Source
Features
Bug Fixes
--version/--help(#42183) (93985c3)@tsconfig/nodereferences (#42189) (be016be)Miscellaneous Chores
v43.92.1Compare Source
Bug Fixes
Miscellaneous Chores
v43.92.0Compare Source
Features
Bug Fixes
Miscellaneous Chores
Stringobjects (#42159) (30ddfe3)Build System
v43.91.6Compare Source
Bug Fixes
Miscellaneous Chores
Tests
prettyDepType(#42152) (41eba99), closes #42142Build System
v43.91.5Compare Source
Miscellaneous Chores
Build System
v43.91.4Compare Source
Build System
v43.91.3Compare Source
Build System
v43.91.2Compare Source
Build System
v43.91.1Compare Source
Bug Fixes
v43.91.0Compare Source
Features
v43.90.1Compare Source
Bug Fixes
v43.90.0Compare Source
Features
Miscellaneous Chores
v43.89.9Compare Source
Bug Fixes
Miscellaneous Chores
Continuous Integration
v43.89.8Compare Source
Bug Fixes
gitlabPipelineVersionspreset (#42130) (e5d5482)v43.89.7Compare Source
Bug Fixes
Miscellaneous Chores
v43.89.6Compare Source
Bug Fixes
v43.89.5Compare Source
Bug Fixes
v43.89.4Compare Source
Build System
v43.89.3Compare Source
Bug Fixes
v43.89.2Compare Source
Bug Fixes
v43.89.1Compare Source
Bug Fixes
Tests
PLATFORM_HOST_TYPESis in sync withgetPlatformList(#42110) (8aed44b)v43.89.0Compare Source
Features
Bug Fixes
v43.88.1Compare Source
Bug Fixes
Miscellaneous Chores
v43.88.0Compare Source
Features
Bug Fixes
Miscellaneous Chores
v43.87.1Compare Source
Build System
v43.87.0Compare Source
Features
Miscellaneous Chores
v43.86.2Compare Source
Miscellaneous Chores
Build System
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.