-
Notifications
You must be signed in to change notification settings - Fork 6
chore(deps): semantic-release [security] #192
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-semantic-release-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
59aa987 to
14a1828
Compare
14a1828 to
5ac20db
Compare
605ebac to
be0624c
Compare
be0624c to
54e36e1
Compare
54e36e1 to
0237af3
Compare
0237af3 to
9ef3077
Compare
38f9c64 to
7c2990e
Compare
7c2990e to
2307f02
Compare
6b9ea10 to
859ec76
Compare
859ec76 to
9991881
Compare
9991881 to
913b745
Compare
913b745 to
bcc3b4d
Compare
5f33a62 to
8fb57b6
Compare
8fb57b6 to
65ee666
Compare
e6cf8c3 to
a3d8257
Compare
a3d8257 to
b47cc4c
Compare
a426f56 to
2de519e
Compare
2de519e to
ccb1411
Compare
ccb1411 to
a5c60c8
Compare
f99d1b7 to
d302c3d
Compare
dfe4b09 to
a43b44f
Compare
a43b44f to
d2ea64d
Compare
84b0538 to
25b4b90
Compare
25b4b90 to
2ad06ae
Compare
2ad06ae to
508226e
Compare
508226e to
d09bdbb
Compare
d09bdbb to
4d2c2c8
Compare
4d2c2c8 to
5e93830
Compare
4f7a803 to
f1b839b
Compare
2ff0490 to
686db60
Compare
686db60 to
c18ad8c
Compare
b1cd7bd to
901673e
Compare
901673e to
9c08d01
Compare
9c08d01 to
4d82462
Compare
4d82462 to
f13739d
Compare
f13739d to
5ec310a
Compare
5ec310a to
9fbb86c
Compare
374118a to
8873ebd
Compare
8873ebd to
41e49f2
Compare
41e49f2 to
b4b6f03
Compare
9feab77 to
b71068f
Compare
b71068f to
af9d0de
Compare
af9d0de to
171a30c
Compare
171a30c to
7002e04
Compare
7002e04 to
1df13bd
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
15.13.3->17.2.3GitHub Vulnerability Alerts
CVE-2020-26226
Impact
Secrets that would normally be masked by
semantic-releasecan be accidentally disclosed if they contain characters that become encoded when included in a URL.Patches
Fixed in v17.2.3
Workarounds
Secrets that do not contain characters that become encoded when included in a URL are already masked properly.
Release Notes
semantic-release/semantic-release (semantic-release)
v17.2.3Compare Source
Bug Fixes
v17.2.2Compare Source
Bug Fixes
v17.2.1Compare Source
Reverts
v17.2.0Compare Source
Features
v17.1.2Compare Source
Bug Fixes
v17.1.1Compare Source
Bug Fixes
v17.1.0Compare Source
Features
v17.0.8Compare Source
Bug Fixes
v17.0.7Compare Source
Bug Fixes
v17.0.6Compare Source
Bug Fixes
v17.0.5Compare Source
Bug Fixes
v17.0.4Compare Source
Bug Fixes
repositoryUrlin logs (55be0ba)v17.0.3Compare Source
Bug Fixes
getGitAuthUrl(e7bede1)v17.0.2Compare Source
Bug Fixes
v17.0.1Compare Source
Bug Fixes
v17.0.0Compare Source
BREAKING CHANGES
v16.0.4Compare Source
Bug Fixes
v16.0.3Compare Source
Bug Fixes
--no-verifywhen testing the Git permissions (b54b20d)v16.0.2Compare Source
Bug Fixes
v16.0.1Compare Source
Bug Fixes
v16.0.0Compare Source
BREAKING CHANGES
v16.0.0@​betausers only:In v16, a JSON object stored in a Git note is used to keep track of the channels on which a version has been released, the
@{channel}suffix is no longer necessary.The tags formatted as v{version}@{channel} will now be ignored. If you have releases using this format you will have to upgrade them:
v{version}@​{channel}{"channels":["channel1","channel2"]}and usingnullfor the default channel (for example.{"channels":[null,"channel1","channel2"]})Require Node.js >= 10.13
Git CLI version 2.7.1 or higher is now required: The
--mergeoption of thegit tagcommand has been added in Git version 2.7.1 and is now used by semantic-releaseRegexp are not supported anymore for property matching in the
releaseRulesoption.Regex are replaced by globs. For example
/core-.*/should be changed to'core-*'.The
branchoption has been removed in favor ofbranchesThe new
branchesoption expect either an Array or a single branch definition. To migrate your configuration:master: nothing to changebranchconfiguration and want to publish only from one branch: replacebranchwithbranches("branch": "my-release-branch"=>"branches": "my-release-branch")Features
addChannelplugins to returnfalsein order to signify no release was done (e1c7269)publishplugins to returnfalsein order to signify no release was done (47484f5)Performance Improvements
git tag --merge <branch>to filter tags present in a branch history (cffe9a8)Bug Fixes
channelto publish success log (5744c5e)ERELEASEBRANCHESerror message (#1188) (37bcc9e)cioption via API and config file (2faff26)getTagHeadonly when necessary (de77a79)successplugin only once for releases added to a channel (9a023b4)addChannelfor 2 merged branches configured with the same channel (4aad9cd)false(751a5f1)getError(f96c660)await(9a1af4d)get-tagsalgorithm (00420a8)branchparameter frompushfunction (968b996)v15.14.0Compare Source
Features
envi-civalues to plugins context (a8c747d)v15.13.32Compare Source
Bug Fixes
v15.13.31Compare Source
Bug Fixes
v15.13.30Compare Source
Bug Fixes
v15.13.29Compare Source
Bug Fixes
v15.13.28Compare Source
Bug Fixes
v15.13.27Compare Source
Bug Fixes
v15.13.26Compare Source
Bug Fixes
v15.13.25Compare Source
Bug Fixes
v15.13.24Compare Source
Reverts
v15.13.23Compare Source
Bug Fixes
v15.13.22Compare Source
Bug Fixes
v15.13.21Compare Source
Bug Fixes
v15.13.20Compare Source
Bug Fixes
v15.13.19Compare Source
Bug Fixes
v15.13.18Compare Source
Bug Fixes
^1.0.0(6b3adf6)v15.13.17Compare Source
Bug Fixes
v15.13.16Compare Source
Bug Fixes
v15.13.15Compare Source
Bug Fixes
v15.13.14Compare Source
Bug Fixes
v15.13.13Compare Source
Bug Fixes
v15.13.12Compare Source
Bug Fixes
v15.13.11Compare Source
Bug Fixes
v15.13.10Compare Source
Bug Fixes
v15.13.9Compare Source
Bug Fixes
v15.13.8Compare Source
Bug Fixes
v15.13.7Compare Source
Bug Fixes
v15.13.6Compare Source
Bug Fixes
v15.13.5Compare Source
Bug Fixes
v15.13.4Compare Source
Bug Fixes
Configuration
📅 Schedule: Branch creation - "" in timezone America/Los_Angeles, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.