Skip to content

Bump nodemailer to 10.0.13 - #6

Open
katsugtgz wants to merge 1 commit into
nodeauth:mainfrom
katsugtgz:dep/nodemailer-10.0.13
Open

katsugtgz wants to merge 1 commit into
nodeauth:mainfrom
katsugtgz:dep/nodemailer-10.0.13

Conversation

@katsugtgz

Copy link
Copy Markdown

Updates nodemailer to address GHSA-v53p-9fqp-m79j and GHSA-g57g-f23g-4646.

Evidence:

  • package.json referenced nodemailer@10.0.5 (package-lock.json pinned 10.0.5)
  • osv-scanner --lockfile package-lock.json reported both advisories at 10.0.5, the high being the quadratic backtracking DoS in the addressparser (GHSA-v53p-9fqp-m79j, CVSS 7.5)
  • updated version: 10.0.13, clear of all current nodemailer advisories per the OSV query API (10.0.6 alone still sits in range for GHSA-g57g-f23g-4646)

Validation:

  • osv-scanner --lockfile package-lock.json reports no issues after the update
  • npm ci succeeds and reports 0 vulnerabilities with 10.0.13
  • npm run build passes

Scope: dependency/lockfile update only (package.json, package-lock.json).

…-4646

package.json pinned nodemailer 10.0.5, which osv-scanner reports against
GHSA-v53p-9fqp-m79j (high, CVSS 7.5) and GHSA-g57g-f23g-4646 (medium).
10.0.13 is clear of all current nodemailer advisories per the OSV query API.

Validation:
- osv-scanner --lockfile package-lock.json: no nodemailer findings after the bump
- npm ci succeeds and reports 0 vulnerabilities with 10.0.13
- npm run build (scripts/inject_vars.js) passes

Scope: dependency pin update in package.json and package-lock.json only.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant