Skip to content
This repository was archived by the owner on Jun 7, 2022. It is now read-only.

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jul 7, 2020

This PR contains the following updates:

Package Type Update New value References Sourcegraph
npm-registry-fetch dependencies minor ^8.0.0 source code search for "npm-registry-fetch"

GitHub Vulnerability Alerts

GHSA-jmqm-f2gx-4fjv

Affected versions of npm-registry-fetch are vulnerable to an information exposure vulnerability through log files. The cli supports URLs like <protocol>://[<user>[:<password>]@&#8203;]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.


Release Notes

npm/registry-fetch

v8.1.1

Compare Source

v8.1.0

Compare Source

Features
  • add npm-command HTTP header (1bb4eb2)
8.0.3 (2020-05-13)
Bug Fixes
  • update minipass and make-fetch-happen to latest (3b6c5d0), closes #​23
8.0.2 (2020-05-04)
Bug Fixes
  • update make-fetch-happen to 8.0.6 (226df2c)

v8.0.3

Compare Source

v8.0.2

Compare Source


Renovate configuration

📅 Schedule: "" in timezone America/Los_Angeles.

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 4 times, most recently from 8a2f010 to 7a06a84 Compare July 17, 2020 00:43
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 2 times, most recently from a609225 to 3e9ad05 Compare July 28, 2020 19:22
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 2 times, most recently from d75965e to 06ce326 Compare August 6, 2020 01:17
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 3 times, most recently from 2c90c58 to 7906e4b Compare August 29, 2020 06:37
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch from 7906e4b to c3b69b5 Compare September 1, 2020 08:26
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch from c3b69b5 to 341a5d0 Compare September 8, 2020 23:28
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch from 341a5d0 to 2ab210c Compare September 19, 2020 08:57
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 2 times, most recently from 0dfe00d to d5bd8c8 Compare October 1, 2020 21:32
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 4 times, most recently from fb0dc9a to 594a2e2 Compare October 13, 2020 00:49
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch from 594a2e2 to 7d44a89 Compare October 15, 2020 23:45
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch 2 times, most recently from 7c96194 to f61426c Compare October 26, 2020 04:49
@renovate renovate bot closed this Oct 29, 2020
@renovate renovate bot force-pushed the renovate/npm-npm-registry-fetch-vulnerability branch from f61426c to 47c7f9d Compare October 29, 2020 14:21
@renovate
Copy link
Contributor Author

renovate bot commented Oct 29, 2020

Renovate Ignore Notification

As this PR has been closed unmerged, Renovate will now ignore this update (^8.0.0). You will still receive a PR once a newer version is released, so if you wish to permanently ignore this dependency, please add it to the ignoreDeps array of your renovate config.

If this PR was closed by mistake or you changed your mind, you can simply rename this PR and you will soon get a fresh replacement PR opened.

@renovate renovate bot deleted the renovate/npm-npm-registry-fetch-vulnerability branch October 29, 2020 14:23
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant