Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Jun 18, 2022

Mend Renovate

This PR contains the following updates:

Package Change
node-fetch 2.6.5 -> 2.6.7

GitHub Vulnerability Alerts

CVE-2022-0235

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor


Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Tokyo, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the deps Pull requests that update a dependency file label Jun 18, 2022
@renovate renovate bot changed the title chore(deps): update dependency node-fetch to 2.6.7 [security] chore(deps): update dependency node-fetch to 2.6.7 [security] - autoclosed Mar 23, 2023
@renovate renovate bot closed this Mar 23, 2023
@renovate renovate bot deleted the renovate/npm-node-fetch-vulnerability branch March 23, 2023 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deps Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants