GHSA-xjr7-3c3g-m763: Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file
The user-provided string depName in the gleam manager is appended to the gleam deps update command without proper sanitization.
References
Code Behaviors & Features
Detect and mitigate GHSA-xjr7-3c3g-m763 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →