Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. renovate
  4. ›
  5. GMS-2019-51

GMS-2019-51: Moderate severity vulnerability that affects renovate

October 21, 2019 (updated August 11, 2022)

Go Modules Vulnerability Disclosure

Impact

Temporary repository tokens were leaked into Pull Requests comments in during certain Go Modules update failure scenarios.

Patches

The problem has been patched. Self-hosted users should upgrade to v19.38.7 or later.

Workarounds

Disable Go Modules support.

References

Blog post: https://renovatebot.com/blog/go-modules-vulnerability-disclosure

For more information

If you have any questions or comments about this advisory:

  • Open an issue in Renovate
  • Email us at support@renovatebot.com

References

  • github.com/advisories/GHSA-v7x3-7hw7-pcjg
  • github.com/renovatebot/renovate/security/advisories/GHSA-v7x3-7hw7-pcjg
  • snyk.io/vuln/SNYK-JS-RENOVATE-536203

Code Behaviors & Features

Detect and mitigate GMS-2019-51 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 13.87.0 before 19.38.7

Fixed versions

  • 19.38.7

Solution

Upgrade to version 19.38.7 or above.

Source file

npm/renovate/GMS-2019-51.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:27 +0000.