Skip to content

chore(deps): update dependency simple-git to v3.16.0 [security] #84

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Mar 16, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
simple-git (source) 3.7.1 -> 3.16.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-25912

The package simple-git before 3.15.0 is vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of CVE-2022-24066.

CVE-2022-25860

Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of CVE-2022-25912.


Release Notes

steveukx/git-js (simple-git)

v3.16.0

Compare Source

Minor Changes
  • 97fde2c: Support the use of -B in place of the default -b in checkout methods
  • 0a623e5: Adds vulnerability detection to prevent use of --upload-pack and --receive-pack without explicitly opting in.
Patch Changes
  • ec97a39: Include restricting the use of git push --exec with other allowUnsafePack exclusions, thanks to @​stsewd for the suggestion.

v3.15.1

Compare Source

Patch Changes
  • de570ac: Resolves an issue whereby non-strings can be passed into the config switch detector.

v3.15.0

Compare Source

Minor Changes
  • 7746480: Disables the use of inline configuration arguments to prevent unitentionally allowing non-standard remote protocols without explicitly opting in to this practice with the new allowUnsafeProtocolOverride property having been enabled.
Patch Changes
  • 7746480: - Upgrade repo dependencies - lerna and jest
    • Include node@19 in the test matrix

v3.14.1

Compare Source

Patch Changes
  • 5a2e7e4: Add version parsing support for non-numeric patches (including "built from source" style 1.11.GIT)

v3.14.0

Compare Source

Minor Changes
  • 19029fc: Create the abort plugin to allow cancelling all pending and future tasks.
  • 4259b26: Add .version to return git version information, including whether the git binary is installed.

v3.13.0

Compare Source

Minor Changes
  • 87b0d75: Increase the level of deprecation notices for use of simple-git/promise, which will be fully removed in the next major
  • d0dceda: Allow supplying just one of to/from in the options supplied to git.log
Patch Changes
  • 6b3e05c: Use shared test utilities bundle in simple-git tests, to enable consistent testing across packages in the future

v3.12.0

Compare Source

Minor Changes
  • bfd652b: Add a new configuration option to enable trimming white-space from the response to git.raw

v3.11.0

Compare Source

Minor Changes
  • 80d54bd: Added fields updated + deleted branch info to fetch response, closes #​823
Patch Changes
  • 75dfcb4: Add prettier configuration and apply formatting throughout.

v3.10.0

Compare Source

Minor Changes
  • 2f021e7: Support for importing as an ES module with TypeScript moduleResolution node16 or newer by adding
    simpleGit as a named export.

v3.9.0

Compare Source

Minor Changes
  • a0d4eb8: Branches that have been checked out as a linked work tree will now be included in the BranchSummary output, with a linkedWorkTree property set to true in the BranchSummaryBranch.

v3.8.0

Compare Source

Minor Changes
  • 25230cb: Support for additional log formats in diffSummary / log / stashList.

    Adds support for the --numstat, --name-only and --name-stat in addition to the existing --stat option.

Patch Changes
  • 2cfc16f: Update CI environments to run build and test in node v18, drop node v12 now out of life.
  • 13197f1: Update debug dependency to latest 4.x

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Rome, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from 207c145 to e3a67fb Compare May 28, 2023 11:31
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from e3a67fb to e4457be Compare June 29, 2023 09:49
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from e4457be to a312cd3 Compare September 26, 2023 15:50
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from a312cd3 to ee5b09a Compare December 3, 2023 09:59
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from ee5b09a to ef90fe6 Compare January 28, 2024 09:56
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from ef90fe6 to 7cd754f Compare March 20, 2024 12:22
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from 7cd754f to 1fb04f6 Compare April 14, 2024 12:17
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from 1fb04f6 to 21fffe4 Compare June 4, 2024 11:47
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from 21fffe4 to e3bedf8 Compare July 21, 2024 14:47
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from e3bedf8 to e825068 Compare August 6, 2024 06:17
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from e825068 to 24e1337 Compare September 17, 2024 01:39
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from 24e1337 to fbe6c47 Compare October 9, 2024 09:44
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch 2 times, most recently from edaa557 to 8dad16e Compare January 30, 2025 14:45
@renovate renovate bot force-pushed the renovate/npm-simple-git-vulnerability branch from 8dad16e to 64a74f9 Compare February 9, 2025 12:31
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants