Update dependency npm to v6.14.6 [SECURITY] - #6
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.14.3->6.14.6GitHub Vulnerability Alerts
CVE-2020-15095
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like
<protocol>://[<user>[:<password>]@​]<hostname>[:<port>][:][/]<path>. The password value is not redacted and is printed to stdout and also to any generated log files.Release Notes
npm/cli
v6.14.6Compare Source
6.14.6 (2020-07-07)
BUG FIXES
a9857b8f6chore: remove auth info from logs (@claudiahdz)b7ad77598#1416 fix: wrongnpm doctorcommand result (@vanishcode)DEPENDENCIES
94eca6377npm-registry-fetch@4.0.5(@claudiahdz)c49b6ae28#1418spdx-license-ids@3.0.5(@kemitchell)v6.14.5Compare Source
6.14.5 (2020-05-04)
BUG FIXES
33ec41f18#758 fix: relativize file links when inflating shrinkwrap (@jsnajdr)94ed456df#1162 fix: npm init help output (@mum-never-proud)DEPENDENCIES
5587ac01fnpm-registry-fetch@4.0.4fc5d94c39fix: removed default timeout07a4d8884graceful-fs@4.2.48228d1f2emkdirp@0.5.5e6d208317nopt@4.0.3v6.14.4Compare Source
6.14.4 (2020-03-25)
DEPENDENCIES
136832dcamkdirp@0.5.4minimist@1.2.5transitive dep to resolve security issue9c554fd8cupdate-notifier@2.5.0deep-extend@1.2.5is-ci@1.2.1is-retry-allowed@1.2.0rc@1.2.8registry-auth-token@3.4.0widest-line@2.0.18bf99b2b5#1053 deps: updates term-size to use signed binaryRenovate configuration
📅 Schedule: "" (UTC).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by WhiteSource Renovate. View repository job log here.