Skip to content

SONARAZDO-595 Bump @cyclonedx/cyclonedx-npm from 2.1.0 to 5.0.0 - #589

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/cyclonedx/cyclonedx-npm-5.0.0
Open

SONARAZDO-595 Bump @cyclonedx/cyclonedx-npm from 2.1.0 to 5.0.0#589
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/cyclonedx/cyclonedx-npm-5.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 23, 2026

Copy link
Copy Markdown
Contributor

Bumps @cyclonedx/cyclonedx-npm from 2.1.0 to 5.0.0.

Release notes

Sourced from @​cyclonedx/cyclonedx-npm's releases.

5.0.0

[!IMPORTANT]
This release includes a fix for a known security vulnerability.

BREAKING Changes

  • Reworked npm handling – npm is now executed explicitly rather than through a subshell.
    The behavior when npm_execpath is present remains unchanged.

Fixed

  • Eliminated a potential shell‑injection vulnerability in the --workspace argument (via #1476)
    See GHSA-v75r-vx73-82pj

#1476: CycloneDX/cyclonedx-node-npm#1476


What's Changed

New Contributors

Full Changelog: CycloneDX/cyclonedx-node-npm@v4.2.1...v5.0.0

4.2.1

Fixed

  • Properly generate PackageURLs for private packages (#1425 via #1426)

#1425: CycloneDX/cyclonedx-node-npm#1425 #1426: CycloneDX/cyclonedx-node-npm#1426


What's Changed

Full Changelog: CycloneDX/cyclonedx-node-npm@v4.2.0...v4.2.1

4.2.0

Fixed

  • Qualified PackageURLs (via #1416)

Changed

... (truncated)

Changelog

Sourced from @​cyclonedx/cyclonedx-npm's changelog.

5.0.0 - 2026-06-16

  • BREAKING Changes
    • Reworked npm handling - npm is now executed explicitly rather than through a subshell.
      The behavior when npm_execpath is present remains unchanged.
  • Fixed
    • Eliminated a potential shell‑injection vulnerability in the --workspace argument (via #1476)
      See GHSA-v75r-vx73-82pj

#1476: CycloneDX/cyclonedx-node-npm#1476

4.2.1 - 2026-03-09

  • Fixed
    • Properly generate PackageURLs for private packages (#1425 via #1426)

#1425: CycloneDX/cyclonedx-node-npm#1425 #1426: CycloneDX/cyclonedx-node-npm#1426

4.2.0 - 2026-03-03

  • Fixed
    • Qualified PackageURLs (via #1416)
  • Changed
    • Take care of PackageURL generation ourselves, now (via #1416)
      Previously, this was done at best-effort by a 3rd-party library.
  • Dependencies
    • Bumped dependency @cyclonedx/cyclonedx-library@^10.0.0 now, was @^8.4.0||^9.0.0 (via #1416)
    • Added dependency packageurl-js@^2.0.1 (via #1416)
    • Added dependency spdx-expression-parse@^3.0.1||^4.0.0 (via #1416)

#1416: CycloneDX/cyclonedx-node-npm#1416

4.1.2 - 2025-12-05

  • Runtime Dependencies
    • Support runtime-dependency xmlbuilder2@^3.0.2||^4.0.3, was @^3.0.2 (#1392 via #1390)
  • Style
    • Applied latest code standards (via #1388)

#1388: CycloneDX/cyclonedx-node-npm#1388 #1390: CycloneDX/cyclonedx-node-npm#1390 #1392: CycloneDX/cyclonedx-node-npm#1392

4.1.1 - 2025-11-11

  • Fixed
    • Create output dir properly if needed (via #1377)

#1377: CycloneDX/cyclonedx-node-npm#1377

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​cyclonedx/cyclonedx-npm since your current version.


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [@cyclonedx/cyclonedx-npm](https://github.com/CycloneDX/cyclonedx-node-npm) from 2.1.0 to 5.0.0.
- [Release notes](https://github.com/CycloneDX/cyclonedx-node-npm/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-node-npm/blob/main/HISTORY.md)
- [Commits](CycloneDX/cyclonedx-node-npm@v2.1.0...v5.0.0)

---
updated-dependencies:
- dependency-name: "@cyclonedx/cyclonedx-npm"
  dependency-version: 5.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 23, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner June 23, 2026 07:20
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 23, 2026
@hashicorp-vault-sonar-prod hashicorp-vault-sonar-prod Bot changed the title Bump @cyclonedx/cyclonedx-npm from 2.1.0 to 5.0.0 SONARAZDO-595 Bump @cyclonedx/cyclonedx-npm from 2.1.0 to 5.0.0 Jun 23, 2026
@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Jun 23, 2026

Copy link
Copy Markdown

SONARAZDO-595

@sonarqube-next

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed for 'Azure DevOps extension for SonarQube Server'

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
No data about Duplication

See analysis details on SonarQube

@sonarqube-next

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed for 'Azure DevOps extension for SonarQube Cloud'

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
No data about Duplication

See analysis details on SonarQube

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants