Skip to content

chore(deps): bump cross-spawn to v7.0.5 [SECURITY]#454

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-cross-spawn-vulnerability
Open

chore(deps): bump cross-spawn to v7.0.5 [SECURITY]#454
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-cross-spawn-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Nov 19, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
cross-spawn 7.0.37.0.5 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-21538

Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

Severity
  • CVSS Score: 7.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P

Release Notes

moxystudio/node-cross-spawn (cross-spawn)

v7.0.5

Compare Source

v7.0.4

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added dependencies Pull requests that update a dependency file deps-prod labels Nov 19, 2024
@renovate renovate bot changed the title chore(deps): bump cross-spawn to v7.0.5 [SECURITY] chore(deps): bump cross-spawn to v7.0.5 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate bot closed this Mar 27, 2026
@renovate renovate bot deleted the renovate/npm-cross-spawn-vulnerability branch March 27, 2026 00:49
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot changed the title chore(deps): bump cross-spawn to v7.0.5 [SECURITY] - autoclosed chore(deps): bump cross-spawn to v7.0.5 [SECURITY] Mar 30, 2026
@renovate renovate bot reopened this Mar 30, 2026
@renovate renovate bot force-pushed the renovate/npm-cross-spawn-vulnerability branch 2 times, most recently from 98099cd to 365ac4a Compare March 30, 2026 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file deps-prod

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants