-
Notifications
You must be signed in to change notification settings - Fork 62
chore(deps): update dependency mongodb to v4.17.0 [security] #899
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-mongodb-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Contributor
Author
Branch automerge failureThis PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.
|
f9aa5f9 to
8d5c58e
Compare
efecbc3 to
15e3bc1
Compare
8f49438 to
57c1807
Compare
57c1807 to
edd5496
Compare
edd5496 to
d9fa614
Compare
d9fa614 to
2bd3430
Compare
2bd3430 to
210b58e
Compare
210b58e to
48fc2ce
Compare
48fc2ce to
567971b
Compare
b0b58bd to
5a5993b
Compare
5a5993b to
a85d29b
Compare
a85d29b to
8135bca
Compare
c06fb52 to
33693c2
Compare
9d3897d to
ef2fc9d
Compare
ef2fc9d to
a44b701
Compare
a44b701 to
2ca5b63
Compare
2ca5b63 to
ffd2715
Compare
ffd2715 to
b8431c0
Compare
b8431c0 to
184a365
Compare
184a365 to
d1c0704
Compare
d1c0704 to
25fec96
Compare
25fec96 to
98f16d1
Compare
98f16d1 to
c477a63
Compare
c477a63 to
d133143
Compare
3f854b1 to
1286229
Compare
fae8ad3 to
14e9540
Compare
14e9540 to
422b0b3
Compare
422b0b3 to
97b6349
Compare
72f4fbc to
eec6eb2
Compare
eec6eb2 to
158fa39
Compare
158fa39 to
2480134
Compare
692d335 to
7573303
Compare
7573303 to
0d9f27b
Compare
0d9f27b to
e58065a
Compare
e58065a to
056f57a
Compare
056f57a to
f6a538b
Compare
f6a538b to
41ab428
Compare
41ab428 to
bb4a4d2
Compare
bb4a4d2 to
37205c7
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.14.0->4.17.0GitHub Vulnerability Alerts
CVE-2021-32050
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.
Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).
This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).
Release Notes
mongodb/node-mongodb-native (mongodb)
v4.17.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.17.0 of the
mongodbpackage!Release Notes
mongodb-js/saslprepis now installed by defaultUntil v6, the driver included the
saslpreppackage as an optional dependency for SCRAM-SHA-256 authentication.saslprepbreaks when bundled with webpack because it attempted to read a file relative to the package location and consequently the driver would throw errors when using SCRAM-SHA-256 if it were bundled.The driver now depends on
mongodb-js/saslprep, a fork ofsaslprepthat can be bundled with webpack because it includes the necessary saslprep data in memory upon loading. This will be installed by default but will only be used if SCRAM-SHA-256 authentication is used.Remove credential availability on
ConnectionPoolCreatedEventIn order to avoid mistakenly printing credentials the
ConnectionPoolCreatedEventwill replace the credentials option with an empty object. The credentials are still accessble via MongoClient options:client.options.credentials.Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.16.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.16.0 of the
mongodbpackage!Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.15.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.15.0 of the mongodb package!
Features
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.