Skip to content

chore(deps): update dependency node-sass to v7 [security]#333

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-node-sass-vulnerability
Open

chore(deps): update dependency node-sass to v7 [security]#333
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-node-sass-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate Bot commented Aug 6, 2024

This PR contains the following updates:

Package Change Age Confidence
node-sass 4.13.07.0.0 age confidence
node-sass ^4.11.0^7.0.0 age confidence

Improper Certificate Validation in node-sass

CVE-2020-24025 / GHSA-r8f7-9pfq-mjmv

More information

Details

Certificate validation in node-sass 2.0.0 to 6.0.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

sass/node-sass (node-sass)

v7.0.0

Compare Source

Breaking changes
Features
Dependencies
Community
Misc

Supported Environments

OS Architecture Node
Windows x86 & x64 12, 14, 16, 17
OSX x64 12, 14, 16, 17
Linux* x64 12, 14, 16, 17
Alpine Linux x64 12, 14, 16, 17
FreeBSD i386 amd64 12, 14

*Linux support refers to major distributions like Ubuntu, and Debian

v6.0.1

Compare Source

Dependencies
Misc

Supported Environments

OS Architecture Node
Windows x86 & x64 12, 14, 15, 16
OSX x64 12, 14, 15, 16
Linux* x64 12, 14, 15, 16
Alpine Linux x64 12, 14, 15, 16
FreeBSD i386 amd64 12, 14, 15

*Linux support refers to major distributions like Ubuntu, and Debian

v6.0.0

Compare Source

Breaking changes
Features
  • Add support for Node 16
Community

Supported Environments

OS Architecture Node
Windows x86 & x64 12, 14, 15, 16
OSX x64 12, 14, 15, 16
Linux* x64 12, 14, 15, 16
Alpine Linux x64 12, 14, 15, 16
FreeBSD i386 amd64 12, 14, 15

*Linux support refers to major distributions like Ubuntu, and Debian

v5.0.0

Compare Source

Breaking changes
Features
  • Add support for Node 15
  • New node-gyp version that supports building with Python 3
Community
Fixes

Supported Environments

OS Architecture Node
Windows x86 & x64 10, 12, 14, 15
OSX x64 10, 12, 14, 15
Linux* x64 10, 12, 14, 15
Alpine Linux x64 10, 12, 14, 15
FreeBSD i386 amd64 10, 12, 14, 15

*Linux support refers to major distributions like Ubuntu, and Debian

v4.14.1

Compare Source

Community
Fixes

Supported Environments

OS Architecture Node
Windows x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14
OSX x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14
Linux* x86 & x64 0.10, 0.12, 1, 2, 3, 4, 5, 6, 7, 8**, 9**, 10**^, 11**^, 12**^, 13**^, 14**^
Alpine Linux x64 6, 8, 10, 11, 12, 13, 14
FreeBSD i386 amd64 10, 12, 13

*Linux support refers to Ubuntu, Debian, and CentOS 5+
** Not available on CentOS 5
^ Only available on x64

v4.14.0

Compare Source

https://github.com/sass/node-sass/releases/tag/v4.14.0

v4.13.1

Compare Source

https://github.com/sass/node-sass/releases/tag/v4.13.1


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title chore(deps): update dependency node-sass to v7 [security] chore(deps): update dependency node-sass to v7 [security] - autoclosed Dec 8, 2024
@renovate renovate Bot closed this Dec 8, 2024
@renovate renovate Bot deleted the renovate/npm-node-sass-vulnerability branch December 8, 2024 19:01
@renovate renovate Bot changed the title chore(deps): update dependency node-sass to v7 [security] - autoclosed chore(deps): update dependency node-sass to v7 [security] Dec 8, 2024
@renovate renovate Bot reopened this Dec 8, 2024
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from 5519362 to 17d9510 Compare December 8, 2024 22:14
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch 2 times, most recently from f8d095b to 4fe6a47 Compare August 13, 2025 17:29
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from 4fe6a47 to 5c876f0 Compare September 25, 2025 16:01
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from 5c876f0 to c50150f Compare October 21, 2025 12:10
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from c50150f to 8d1059b Compare November 10, 2025 19:52
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from 8d1059b to 11c8b5d Compare November 18, 2025 23:03
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from 11c8b5d to a757fda Compare February 2, 2026 14:58
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from a757fda to 8e77275 Compare February 12, 2026 15:04
@renovate renovate Bot changed the title chore(deps): update dependency node-sass to v7 [security] chore(deps): update dependency node-sass to v7 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot changed the title chore(deps): update dependency node-sass to v7 [security] - autoclosed chore(deps): update dependency node-sass to v7 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch 2 times, most recently from 8e77275 to e4861c2 Compare March 30, 2026 17:45
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from e4861c2 to c172280 Compare April 8, 2026 14:56
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from c172280 to 29a9bdd Compare April 29, 2026 18:48
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from 29a9bdd to 3ea5586 Compare May 12, 2026 09:49
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from 3ea5586 to 69dae3f Compare May 28, 2026 16:10
@renovate renovate Bot force-pushed the renovate/npm-node-sass-vulnerability branch from 69dae3f to ddb5c96 Compare June 1, 2026 20:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants