Skip to content

chore(deps): update dependency pacote to v21 [security] j:cdx-227 - #1565

Open
renovate-coveo[bot] wants to merge 1 commit into
masterfrom
renovate/npm-pacote-vulnerability
Open

chore(deps): update dependency pacote to v21 [security] j:cdx-227#1565
renovate-coveo[bot] wants to merge 1 commit into
masterfrom
renovate/npm-pacote-vulnerability

Conversation

@renovate-coveo

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
pacote devDependencies major 15.1.321.5.1

pacote is vulnerable to Denial of Service (DoS) via the addGitSha function

CVE-2026-9496 / GHSA-w4pp-8pjf-rmxw

More information

Details

Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.

Severity

  • CVSS Score: 7.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

npm/pacote (pacote)

v21.5.1

Compare Source

Bug Fixes
Chores

v21.5.0

Compare Source

Features
Chores

v21.4.0

Compare Source

Features
Bug Fixes
Chores

v21.3.1

Compare Source

Bug Fixes
Chores

v21.3.0

Compare Source

Features

v21.2.0

Compare Source

Features

v21.1.0

Compare Source

Features

v21.0.4

Compare Source

Dependencies
Chores

v21.0.3

Compare Source

Dependencies

v21.0.2

Compare Source

Dependencies

v21.0.1

Compare Source

⚠️ BREAKING CHANGES
  • pacote now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
  • git specs using the https or git+https protocol now resolve to git+https URLs instead of being switched to git+ssh. Shortcut specs (e.g. github:user/repo, user/repo) and git+ssh/git:// specs are unchanged.
Features
Bug Fixes
Dependencies
Chores

v21.0.0

Compare Source

⚠️ BREAKING CHANGES
  • bun.lockb files are now included in the strict ignore list during packing
  • this module is now compatible with the following node versions: ^20.17.0 || >=22.9.0
Bug Fixes
Dependencies
Chores

v20.0.1

Compare Source

⚠️ BREAKING CHANGES
  • pacote now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
  • git specs using the https or git+https protocol now resolve to git+https URLs instead of being switched to git+ssh. Shortcut specs (e.g. github:user/repo, user/repo) and git+ssh/git:// specs are unchanged.
Features
Bug Fixes
Dependencies
Chores

v20.0.0

Compare Source

Dependencies
Chores

v19.0.2

Compare Source

Dependencies
Chores

v19.0.1

Compare Source

Bug Fixes
Dependencies

v19.0.0

Compare Source

Dependencies
Chores

v18.0.6

Compare Source

Bug Fixes

v18.0.5

Compare Source

Bug Fixes

v18.0.4

Compare Source

⚠️ BREAKING CHANGES
  • pacote now supports node ^18.17.0 || >=20.5.0
Bug Fixes
Dependencies
Chores

v18.0.3

Compare Source

Dependencies

v18.0.2

Compare Source

Bug Fixes

v18.0.1

Compare Source

Bug Fixes

v18.0.0

Compare Source

⚠️ BREAKING CHANGES
  • pacote now supports node ^18.17.0 || >=20.5.0
Bug Fixes
Dependencies
Chores

v17.0.7

Compare Source

Dependencies

v17.0.6

Compare Source

Dependencies
Chores

v17.0.5

Compare Source

Bug Fixes

v17.0.4

Compare Source

Dependencies

v17.0.3

Compare Source

Dependencies

v17.0.2

Compare Source

Dependencies

v17.0.1

Compare Source

Dependencies

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@renovate-coveo renovate-coveo Bot added the dependencies Pull requests that update a dependency file label Aug 27, 2026
@renovate-coveo
renovate-coveo Bot requested a review from a team as a code owner August 27, 2026 20:19
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ❌ 1 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
See the Details below.

Vulnerabilities

package-lock.json

NameVersionVulnerabilitySeverity
pacote15.2.0pacote is vulnerable to Denial of Service (DoS) via the addGitSha functionhigh
Only included vulnerabilities with severity high or higher.

Scanned Files

  • package-lock.json
  • packages/cli-e2e/package.json

@github-actions

Copy link
Copy Markdown
Contributor

Thanks for your contribution @renovate-coveo[bot] !
When your pull-request is ready to be merged, check the box below to merge it

  • Merge! :shipit:

@github-actions

Copy link
Copy Markdown
Contributor

Pull Request Report

PR Title

✅ Title follows the conventional commit spec.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants