chore: upgrade nodemailer to ^8.0.11 to address GHSA-268h-hp4c-crq3#1328
Conversation
|
Warning Review limit reached
More reviews will be available in 4 minutes and 36 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits. 🚦 How do rate limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
WalkthroughA single line is added to ChangesChangelog entry for nodemailer upgrade
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~1 minute Possibly related PRs
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
190fbfd to
7591b5f
Compare
License Audit
Weak Copyleft Packages (informational)
Resolved Packages (20)
|
Refreshes the lockfile so nodemailer resolves to 8.0.11, which patches the CRLF injection in List-* header comments (GHSA-268h-hp4c-crq3). Generated with [Linear](https://linear.app/sourcebot/issue/SOU-1352/sourcebot-devsourcebot-ghsa-268h-hp4c-crq3-nodemailer-crlf-injection#agent-session-54dfebc0) Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>
7591b5f to
cd7a39e
Compare
Fixes SOU-1352
Refreshes the lockfile so
nodemailerresolves to8.0.11, patching the CRLF injection inList-*header comments (GHSA-268h-hp4c-crq3). The existing^8.0.5range inpackages/web/package.jsonalready admits the patched version, so this is a lockfile-only change (yarn up -R nodemailer).Summary by CodeRabbit