Skip to content

chore(deps): update dependency renovate to v43.102.11 [security]#320

Open
renovate-for-cybozu-oss[bot] wants to merge 1 commit into
masterfrom
renovate/npm-renovate-vulnerability
Open

chore(deps): update dependency renovate to v43.102.11 [security]#320
renovate-for-cybozu-oss[bot] wants to merge 1 commit into
masterfrom
renovate/npm-renovate-vulnerability

Conversation

@renovate-for-cybozu-oss

@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot commented May 14, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
renovate (source) devDependencies minor 43.66.043.102.11

Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance

GHSA-5vjq-5jmg-39xq

More information

Details

When using lockFileMaintenance using the bazel-module or bazelisk managers between Renovate 43.65.0 (2026-03-12) and 43.102.11 (2026-04-02), there was the opportunity for remote code execution from a malicious dependency, if the Bazel module executes code that relies on a dependency.

As this is an "unsafe" execution path, we have disabled this by default, and self-hosted administrators must add it to the allowedUnsafeExecutions allowlist.

It is recommended to review whether you have enabled this functionality for these managers, and if so, whether any dependency updates may have led to remote code execution.

Impact

If Renovate suggested an update to a malicious dependency, and that dependency is referenced as part of the bazel mod deps call - for instance as part of a ctx.execute call - this would call attacker-controlled code.

This could lead to insider attackers and outside attackers, executing code that is distributed as part of the package.

Patches

This is patched in 43.102.11.

This does not affect any versions of Mend Renovate Self-Hosted.

Workarounds
  • Upgrade your Renovate version
  • Disable lockFileMaintenance for these managers
Why did this happen?

This was missed in code review (as part of https://github.com/renovatebot/renovate/pull/41507).

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

renovatebot/renovate (renovate)

v43.102.11

Compare Source

Bug Fixes
  • bazel-module,bazelisk: add allowedUnsafeExecutions for bazel mod deps (#​42323) (4d2d86f)
Build System

v43.102.10

Compare Source

Build System

v43.102.9

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.33.3 (main) (#​42318) (aa2e7bf)
Miscellaneous Chores
  • deps: update dependency oxlint-tsgolint to v0.17.4 (main) (#​42316) (9535323)

v43.102.8

Compare Source

Build System

v43.102.7

Compare Source

Bug Fixes

v43.102.6

Compare Source

Miscellaneous Chores
Build System

v43.102.5

Compare Source

Bug Fixes

v43.102.4

Compare Source

Documentation
Miscellaneous Chores
Build System

v43.102.3

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.33.2 (main) (#​42299) (059db63)
Miscellaneous Chores
  • deps: update pdm-project/setup-pdm action to v4.5 (main) (#​42298) (21d4a04)

v43.102.2

Compare Source

Build System

v43.102.1

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.33.1 (main) (#​42294) (3883fc8)

v43.102.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.33.0 (main) (#​42292) (e914a5f)
Bug Fixes
Miscellaneous Chores
Code Refactoring

v43.101.7

Compare Source

Bug Fixes
  • http: fallback to github hostType for GHE platform endpoint (#​42287) (b8809ce)

v43.101.6

Compare Source

Miscellaneous Chores
  • deps: update docker/dockerfile docker tag to v1.23.0 (main) (#​42290) (5a77836)
Build System

v43.101.5

Compare Source

Bug Fixes

v43.101.4

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.32.2 (main) (#​42282) (37f8206)
  • presets: allow Aspire's organization move (#​42281) (502d11f)
Documentation
Miscellaneous Chores

v43.101.3

Compare Source

Bug Fixes
Documentation
Miscellaneous Chores
Continuous Integration

v43.101.2

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.32.1 (main) (#​42265) (b0f453d)
Miscellaneous Chores
  • deps: update dependency tar to v7.5.13 (main) (#​42256) (5cfbba3)
  • deps: update ghcr.io/containerbase/devcontainer docker tag to v14.6.9 (main) (#​42261) (d54e8da)

v43.101.1

Compare Source

Documentation
Miscellaneous Chores
Code Refactoring
Build System

v43.101.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.32.0 (main) (#​42252) (d1f917f)
  • dry-run: log commit contents (#​41718) (3951723)
  • report: add reportFormatting option to format JSON reports with Prettier (#​42162) (1b58cd6)

v43.100.2

Compare Source

Miscellaneous Chores
Build System

v43.100.1

Compare Source

Documentation
  • config: clarify commitMessagePrefix affects Dependency Dashboard (#​42236) (9a76a15)
Build System

v43.100.0

Compare Source

Features
Bug Fixes
  • swift: Parse pins without version key in Package.resolved (#​42220) (8ed5d0f)
Documentation
Miscellaneous Chores

v43.99.1

Compare Source

Bug Fixes
  • datasource/dart: Use npm versioning to make rangeStrategy=bump work again (#​42115) (ef9662a)
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.31.1 (main) (#​42226) (fa018c4)
Miscellaneous Chores
  • deps: update containerbase/internal-tools action to v4.5.6 (main) (#​42219) (d850027)
  • deps: update dependency markdownlint-cli2 to v0.22.0 (main) (#​42222) (8ae44af)
Code Refactoring

v43.99.0

Compare Source

Features
  • manager/kubernetes: extract image volume references from manifests (#​42038) (b438e57)
Miscellaneous Chores
Code Refactoring

v43.98.0

Compare Source

Features

v43.97.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.31.0 (main) (#​42211) (91049f0)
Miscellaneous Chores

v43.96.0

Compare Source

Features
Miscellaneous Chores
  • deps: update github/codeql-action action to v4.35.1 (main) (#​42209) (b6fa499)
Tests

v43.95.0

Compare Source

Features

v43.94.1

Compare Source

Bug Fixes
  • manager/npm: revert passing --before to npm install when minimumReleaseAge is set (#​42198) (a74da77)
Miscellaneous Chores
  • deps: update github/codeql-action action to v4.35.0 (main) (#​42200) (860230f)

v43.94.0

Compare Source

Features

v43.93.1

Compare Source

Bug Fixes
  • gerrit: use the ready push option to ensure changes are not wip (#​40960) (1472cd9)
Documentation
Code Refactoring

v43.93.0

Compare Source

Features
  • manager/npm: pass --before to npm install when minimumReleaseAge is set (#​42051) (c4d5697)
  • replacements: add replacement for Kotlin Logging maven package (#​42078) (b83db48)
Bug Fixes
  • cli: avoid printing logs on --version/--help (#​42183) (93985c3)
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.30.3 (main) (#​42191) (0ab23ef)
  • presets: allow short @tsconfig/node references (#​42189) (be016be)
  • use correct digest when replacing packages with replacementNameTemplate (#​40058) (f33f3f6)
Miscellaneous Chores

v43.92.1

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.30.2 (main) (#​42171) (2a1bbc9)
Miscellaneous Chores
  • deps: update dependency oxlint-tsgolint to v0.17.1 (main) (#​42170) (704b455)

v43.92.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.30.0 (main) (#​42163) (149f8d9)
Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.30.1 (main) (#​42168) (5dd56b1)
Miscellaneous Chores
Build System
  • deps: update dependency handlebars to v4.7.9 [security] (main) (#​42167) (772f4d8)

v43.91.6

Compare Source

Bug Fixes
  • platform/bitbucket: replace deprecated cross-workspace repos endpoint (#​42134) (413dcdd)
Miscellaneous Chores
Tests
Build System

v43.91.5

Compare Source

Miscellaneous Chores
Build System

v43.91.4

Compare Source

Build System
  • deps: update dependency yaml to v2.8.3 [security] (main) (#​42147) (5c21744)

v43.91.3

Compare Source

Build System

v43.91.2

Compare Source

Build System

v43.91.1

Compare Source

Bug Fixes

v43.91.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.29.0 (main) (#​42140) (c80f520)

v43.90.1

Compare Source

Bug Fixes
  • template: do not escape html character with double curly brackets (#​42136) (990c64e)

v43.90.0

Compare Source

Features
Miscellaneous Chores

v43.89.9

Compare Source

Bug Fixes
Miscellaneous Chores
Continuous Integration

v43.89.8

Compare Source

Bug Fixes
  • preset: restore subdirectory and prefix matching for gitlabPipelineVersions preset (#​42130) (e5d5482)

v43.89.7

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.28.8 (main) (#​42128) (f93ae9d)
Miscellaneous Chores

v43.89.6

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.28.7 (main) (#​42125) (a5c62c1)

v43.89.5

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.28.6 (main) (#​42124) (efbec6c)

v43.89.4

Compare Source

Build System

v43.89.3

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.28.5 (main) (#​42122) (a0820df)

v43.89.2

Compare Source

Bug Fixes
  • http: detect x-access-token prefix before hostType-based auth branching (#​42083) (0ae4481)

v43.89.1

Compare Source

Bug Fixes
Tests
  • platform: ensure PLATFORM_HOST_TYPES is in sync with getPlatformList (#​42110) (8aed44b)

v43.89.0

Compare Source

Features
Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.28.4 (main) (#​42109) (7e879ff)

v43.88.1

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.28.3 (main) (#​42107) (1b7fa64)
Miscellaneous Chores

v43.88.0

Compare Source

Features
Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.28.2 (main) (#​42105) (edebc9c)
  • scm-manager: invalid base url, due to double slashes and a fixed context path (#​42068) (bcf3fcd)
Miscellaneous Chores
  • deps: update dependency pdm to v2.26.7 (main) (#​42103) (2a3ea2c)
  • deps: update ghcr.io/containerbase/devcontainer docker tag to v14.6.8 (main) (#​42104) (814a1db)

v43.87.1

Compare Source

Build System

v43.87.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.28.1 (main) (#​42097) (2ba8d95)
Miscellaneous Chores

v43.86.2

Compare Source

Miscellaneous Chores
Build System
  • deps: update dependency google-auth-library to v10.6.2 (main) (#​42091) (d3bde51)
Continuous Integration

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot requested a review from a team as a code owner May 14, 2026 22:41
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot force-pushed the renovate/npm-renovate-vulnerability branch 11 times, most recently from 09ed5b6 to eff6399 Compare May 22, 2026 03:27
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot force-pushed the renovate/npm-renovate-vulnerability branch 11 times, most recently from 20996e7 to d8e408c Compare May 31, 2026 22:37
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot force-pushed the renovate/npm-renovate-vulnerability branch 5 times, most recently from 443f291 to aa59f12 Compare June 3, 2026 08:03
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot changed the title chore(deps): update dependency renovate to v43.102.11 [security] chore(deps): update dependency renovate to v43.102.11 [security] - autoclosed Jun 3, 2026
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot deleted the renovate/npm-renovate-vulnerability branch June 3, 2026 14:06
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot changed the title chore(deps): update dependency renovate to v43.102.11 [security] - autoclosed chore(deps): update dependency renovate to v43.102.11 [security] Jun 3, 2026
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot force-pushed the renovate/npm-renovate-vulnerability branch 11 times, most recently from b682df7 to 7310f0b Compare June 9, 2026 20:57
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot changed the title chore(deps): update dependency renovate to v43.102.11 [security] chore(deps): update dependency renovate to v43.102.11 [security] - autoclosed Jun 10, 2026
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot changed the title chore(deps): update dependency renovate to v43.102.11 [security] - autoclosed chore(deps): update dependency renovate to v43.102.11 [security] Jun 10, 2026
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot force-pushed the renovate/npm-renovate-vulnerability branch 9 times, most recently from 04153f3 to 8803886 Compare June 15, 2026 18:48
@renovate-for-cybozu-oss renovate-for-cybozu-oss Bot force-pushed the renovate/npm-renovate-vulnerability branch from 8803886 to b72a0a5 Compare June 15, 2026 20:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants