Skip to content

build(deps-dev): bump @cyclonedx/cyclonedx-npm from 1.20.0 to 6.0.1 in /backend - #1398

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/backend/cyclonedx/cyclonedx-npm-6.0.1
Open

build(deps-dev): bump @cyclonedx/cyclonedx-npm from 1.20.0 to 6.0.1 in /backend#1398
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/backend/cyclonedx/cyclonedx-npm-6.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps @cyclonedx/cyclonedx-npm from 1.20.0 to 6.0.1.

Release notes

Sourced from @​cyclonedx/cyclonedx-npm's releases.

6.0.1

Maintenance release.


What's Changed

Full Changelog: CycloneDX/cyclonedx-node-npm@v6.0.0...v6.0.1

6.0.1-rc.0

testing during CycloneDX/cyclonedx-node-npm#1507

6.0.0

[!IMPORTANT]
This release includes a fix for a known security vulnerability.

BREAKING Changes

  • Reworked npm detection and handling.
    The behavior when npm_execpath is present remains unchanged.

Fixed

  • Eliminated a potential shell‑injection vulnerability in the --workspace argument on Windows (via #1489)
    See GHSA-q69g-4hcv-6jg4
  • Properly closing output file (via #1484)

Tests

  • Added more regression test for shell injections (via #1488)

#1484: CycloneDX/cyclonedx-node-npm#1484 #1488: CycloneDX/cyclonedx-node-npm#1488 #1489: CycloneDX/cyclonedx-node-npm#1489


... (truncated)

Changelog

Sourced from @​cyclonedx/cyclonedx-npm's changelog.

6.0.1 - 2026-08-11

Maintenance release.

6.0.0 - 2026-07-07

  • BREAKING Changes
    • Reworked npm detection and handling.
      The behavior when npm_execpath is present remains unchanged.
  • Fixed
    • Eliminated a potential shell‑injection vulnerability in the --workspace argument on Windows (via #1489)
      See GHSA-q69g-4hcv-6jg4
    • Properly closing output file (via #1484)
  • Tests
    • Added more regression test for shell injections (via #1488)

#1484: CycloneDX/cyclonedx-node-npm#1484 #1488: CycloneDX/cyclonedx-node-npm#1488 #1489: CycloneDX/cyclonedx-node-npm#1489

5.0.0 - 2026-06-16

  • BREAKING Changes
    • Reworked npm handling - npm is now executed explicitly rather than through a subshell.
      The behavior when npm_execpath is present remains unchanged.
  • Fixed
    • Eliminated a potential shell‑injection vulnerability in the --workspace argument (via #1476)
      See GHSA-v75r-vx73-82pj
  • Tests
    • Added regression test for shell injections (via #1476)

#1476: CycloneDX/cyclonedx-node-npm#1476

4.2.1 - 2026-03-09

  • Fixed
    • Properly generate PackageURLs for private packages (#1425 via #1426)

#1425: CycloneDX/cyclonedx-node-npm#1425 #1426: CycloneDX/cyclonedx-node-npm#1426

4.2.0 - 2026-03-03

  • Fixed
    • Qualified PackageURLs (via #1416)
  • Changed
    • Take care of PackageURL generation ourselves, now (via #1416)
      Previously, this was done at best-effort by a 3rd-party library.
  • Dependencies
    • Bumped dependency @cyclonedx/cyclonedx-library@^10.0.0 now, was @^8.4.0||^9.0.0 (via #1416)

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​cyclonedx/cyclonedx-npm since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@cyclonedx/cyclonedx-npm](https://github.com/CycloneDX/cyclonedx-node-npm) from 1.20.0 to 6.0.1.
- [Release notes](https://github.com/CycloneDX/cyclonedx-node-npm/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-node-npm/blob/main/HISTORY.md)
- [Commits](CycloneDX/cyclonedx-node-npm@v1.20.0...v6.0.1)

---
updated-dependencies:
- dependency-name: "@cyclonedx/cyclonedx-npm"
  dependency-version: 6.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the Backend label Sep 7, 2026
@dependabot
dependabot Bot requested a review from Calebux as a code owner September 7, 2026 06:30
@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the Backend label Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

📊 Coverage Report

Package Lines Statements Functions Branches Δ Lines Min (lines) Status
backend 55.00% ⚪ not run
client 0.00% ⚪ not run
sdk 0.00% ⚪ not run
contracts 0.00% ⚪ not run

Δ compares against the target branch. Minimums are ratchets — see coverage-thresholds.json.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants