Skip to content

chore(deps): update dependency degit to v2.8.6 [security] - #1127

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-degit-vulnerability
Open

chore(deps): update dependency degit to v2.8.6 [security]#1127
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-degit-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
degit 2.8.42.8.6 age confidence

degit has a Command Injection issue

CVE-2026-11572 / GHSA-77c7-pq4r-6mcq

More information

Details

Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exec() method by _cloneWithGit() and fetchRefs() functions. An attacker can execute arbitrary operating system commands as the process user by supplying a specially crafted git repository name.

Severity

  • CVSS Score: 7.4 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

Rich-Harris/degit (degit)

v2.8.6

Compare Source

v2.8.5

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@netlify

netlify Bot commented Aug 26, 2026

Copy link
Copy Markdown

Deploy Preview for vue-devtools-docs canceled.

Name Link
🔨 Latest commit 12dcf01
🔍 Latest deploy log https://app.netlify.com/projects/vue-devtools-docs/deploys/6a9ce2517a886b0008c695bb

@renovate
renovate Bot force-pushed the renovate/npm-degit-vulnerability branch from bb37ce6 to a2dd4ed Compare September 2, 2026 22:52
@pkg-pr-new

pkg-pr-new Bot commented Sep 2, 2026

Copy link
Copy Markdown

Open in StackBlitz

@vue/devtools-applet

npm i https://pkg.pr.new/@vue/devtools-applet@1127

@vue/devtools-core

npm i https://pkg.pr.new/@vue/devtools-core@1127

@vue/devtools

npm i https://pkg.pr.new/@vue/devtools@1127

@vue/devtools-api

npm i https://pkg.pr.new/@vue/devtools-api@1127

@vue/devtools-kit

npm i https://pkg.pr.new/@vue/devtools-kit@1127

@vue/devtools-electron

npm i https://pkg.pr.new/@vue/devtools-electron@1127

@vue/devtools-shared

npm i https://pkg.pr.new/@vue/devtools-shared@1127

@vue/devtools-ui

npm i https://pkg.pr.new/@vue/devtools-ui@1127

vite-plugin-vue-devtools

npm i https://pkg.pr.new/vite-plugin-vue-devtools@1127

commit: 12dcf01

@renovate
renovate Bot force-pushed the renovate/npm-degit-vulnerability branch from a2dd4ed to 12dcf01 Compare September 6, 2026 03:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants