You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argument File leads to os command injection. The attack needs to be performed locally. Upgrading to version 13.0.8 is recommended to address this issue. The name of the patch is 087a7290264cc6fb7154ea8c2552a7b2cb8b33a3. It is advisable to upgrade the affected component.
Ensure that babel ignores do not cause the transpiler to fall over, by supporting the null return from loadOptions which occurs when a file is ignored.
It's been 7 years since I looked at danger init and err, the world of CI has changed quite a bit since then. So, Danger JS's init command now knows that GitHub Actions exists and will correctly offer some advice on how to set up a Dangerfile for it. - [@orta]
Bumping to 12.x because we've raised the minimum to node version from 14 to 18. This is due to some of our dependencies
requiring a newer version of node. This is a breaking change for some folk! Also, 14 has been out of support for quite a while
now and Node 18 gives us a full year. - [@orta]
Remove the user checks in GitHub comment/inline comment lookups, to allow using app tokens [#1433] - [@orta]
Upgrade node engine from >=14.13.1 to >=18 [@heltoft]
Upgrade @types/node from ^10.11.3 to 18.19.18 [@heltoft]
GitLab: [#1386] Move from @gitbeaker/node to @gitbeaker/rest [@heltoft]
GitLab: [#1412] Danger fails to create inline comments on Gitlab [@heltoft]
GitLab: [#1405] Can't post multiple inline comments [@heltoft]
GitLab: Do not delete system resolved danger inline comments [@heltoft]
Bumping to 12.x because we've raised the minimum to node version from 14 to 18. This is due to some of our dependencies
requiring a newer version of node. This is a breaking change for some folk! Also, 14 has been out of support for quite a while
now and Node 18 gives us a full year. - [@orta]
Remove the user checks in GitHub comment/inline comment lookups, to allow using app tokens [#1433] - [@orta]
Upgrade node engine from >=14.13.1 to >=18 [@heltoft]
Upgrade @types/node from ^10.11.3 to 18.19.18 [@heltoft]
GitLab: [#1386] Move from @gitbeaker/node to @gitbeaker/rest [@heltoft]
GitLab: [#1412] Danger fails to create inline comments on Gitlab [@heltoft]
Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.
This PR includes no changesets
When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^11.0.2→^13.0.0danger allows local OS command injection through crafted file paths
CVE-2026-16629 / GHSA-3x93-p86w-5jvh
More information
Details
A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argument File leads to os command injection. The attack needs to be performed locally. Upgrading to version 13.0.8 is recommended to address this issue. The name of the patch is 087a7290264cc6fb7154ea8c2552a7b2cb8b33a3. It is advisable to upgrade the affected component.
Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
danger/danger-js (danger)
v13.0.8Compare Source
v13.0.7Compare Source
v13.0.5Compare Source
v13.0.4Compare Source
v13.0.3Compare Source
v13.0.2Compare Source
v13.0.1Compare Source
v13.0.0Compare Source
@octokit/restfrom 18 to 20 to prevent transitive CVEs - Fixes #1479 [@fbartho]v12.3.4Compare Source
nullreturn fromloadOptionswhich occurs when a file is ignored.v12.3.3Compare Source
v12.3.2Compare Source
dangerfile.mts/dangerfile.mjs) [@matthewh]v12.3.1Compare Source
v12.3.0Compare Source
v12.2.1Compare Source
v12.2.0Compare Source
v12.1.0Compare Source
It's been 7 years since I looked at
danger initand err, the world of CI has changed quite a bit since then. So, Danger JS'sinitcommand now knows that GitHub Actions exists and will correctly offer some advice on how to set up a Dangerfile for it. - [@orta]v12.0.1Compare Source
Bumping to 12.x because we've raised the minimum to node version from 14 to 18. This is due to some of our dependencies
requiring a newer version of node. This is a breaking change for some folk! Also, 14 has been out of support for quite a while
now and Node 18 gives us a full year. - [@orta]
nodeengine from>=14.13.1to>=18[@heltoft]@types/nodefrom^10.11.3to18.19.18[@heltoft]@gitbeaker/nodeto@gitbeaker/rest[@heltoft]v12.0.0Compare Source
Bumping to 12.x because we've raised the minimum to node version from 14 to 18. This is due to some of our dependencies
requiring a newer version of node. This is a breaking change for some folk! Also, 14 has been out of support for quite a while
now and Node 18 gives us a full year. - [@orta]
nodeengine from>=14.13.1to>=18[@heltoft]@types/nodefrom^10.11.3to18.19.18[@heltoft]@gitbeaker/nodeto@gitbeaker/rest[@heltoft]v11.3.1Compare Source
pull_numberintothisPRin the GitHub SDL [@radimsv]DANGER_GHE_ACTIONS_BOT_USER_ID#1404 [@dimitar-hristov]Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.