Skip to content

Update dependency pacote to v21 [SECURITY] - #1290

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-pacote-vulnerability
Open

Update dependency pacote to v21 [SECURITY]#1290
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-pacote-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
pacote ^13.6.0^21.0.0 age confidence

pacote is vulnerable to Denial of Service (DoS) via the addGitSha function

CVE-2026-9496 / GHSA-w4pp-8pjf-rmxw

More information

Details

Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.

Severity

  • CVSS Score: 7.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

npm/pacote (pacote)

v21.5.1

Compare Source

Bug Fixes
Chores

v21.5.0

Compare Source

Features
Chores

v21.4.0

Compare Source

Features
Bug Fixes
Chores

v21.3.1

Compare Source

Bug Fixes
Chores

v21.3.0

Compare Source

Features

v21.2.0

Compare Source

Features

v21.1.0

Compare Source

Features

v21.0.4

Compare Source

Dependencies
Chores

v21.0.3

Compare Source

Dependencies

v21.0.2

Compare Source

Dependencies

v21.0.1

Compare Source

⚠️ BREAKING CHANGES
  • pacote now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
  • git specs using the https or git+https protocol now resolve to git+https URLs instead of being switched to git+ssh. Shortcut specs (e.g. github:user/repo, user/repo) and git+ssh/git:// specs are unchanged.
Features
Bug Fixes
Dependencies
Chores

v21.0.0

Compare Source

⚠️ BREAKING CHANGES
  • bun.lockb files are now included in the strict ignore list during packing
  • this module is now compatible with the following node versions: ^20.17.0 || >=22.9.0
Bug Fixes
Dependencies
Chores

v20.0.1

Compare Source

⚠️ BREAKING CHANGES
  • pacote now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
  • git specs using the https or git+https protocol now resolve to git+https URLs instead of being switched to git+ssh. Shortcut specs (e.g. github:user/repo, user/repo) and git+ssh/git:// specs are unchanged.
Features
Bug Fixes
Dependencies
Chores

v20.0.0

Compare Source

Dependencies
Chores

v19.0.2

Compare Source

Dependencies
Chores

v19.0.1

Compare Source

Bug Fixes
Dependencies

v19.0.0

Compare Source

Dependencies
Chores

v18.0.6

Compare Source

Bug Fixes

v18.0.5

Compare Source

Bug Fixes

v18.0.4

Compare Source

⚠️ BREAKING CHANGES
  • pacote now supports node ^18.17.0 || >=20.5.0
Bug Fixes
Dependencies
Chores

v18.0.3

Compare Source

Dependencies

v18.0.2

Compare Source

Bug Fixes

v18.0.1

Compare Source

Bug Fixes

v18.0.0

Compare Source

⚠️ BREAKING CHANGES
  • pacote now supports node ^18.17.0 || >=20.5.0
Bug Fixes
Dependencies
Chores

v17.0.7

Compare Source

Dependencies

v17.0.6

Compare Source

Dependencies
Chores

v17.0.5

Compare Source

Bug Fixes

v17.0.4

Compare Source

Dependencies

v17.0.3

Compare Source

Dependencies

v17.0.2

Compare Source

Dependencies

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants