Skip to content

Update dependency nodemailer to v6.4.16 [SECURITY]#625

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-nodemailer-vulnerability
Open

Update dependency nodemailer to v6.4.16 [SECURITY]#625
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-nodemailer-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate bot commented Feb 1, 2024

This PR contains the following updates:

Package Change Age Confidence
nodemailer (source) 6.4.66.4.16 age confidence

GitHub Vulnerability Alerts

CVE-2020-7769

This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.


Release Notes

nodemailer/nodemailer (nodemailer)

v6.4.16

Compare Source

  • Applied updated prettier formating rules

v6.4.15

Compare Source

  • Minor changes in header key casing

v6.4.14

Compare Source

  • Disabled postinstall script

v6.4.13

Compare Source

  • Fix normalizeHeaderKey method for single node messages

v6.4.12

Compare Source

  • Better handling of attachment filenames that include quote symbols
  • Includes all information from the oath2 error response in the error message (Normal Gaussian) [1787f22]

v6.4.11

Compare Source

  • Fixed escape sequence handling in address parsing

v6.4.10

Compare Source

  • Fixed RFC822 output for MailComposer when using invalid content-type value. Mostly relevant if message attachments have stragne content-type values set.

v6.4.8

Compare Source

v6.4.7

Compare Source

  • Always set charset=utf-8 for Content-Type headers
  • Catch error when using invalid crypto.sign input

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Copy Markdown
Author

renovate bot commented Feb 1, 2024

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: functions/package-lock.json
ERROR: npm is known not to run on Node.js v10.24.1
You'll need to upgrade to a newer Node.js version in order to use this
version of npm. You can find the latest version at https://nodejs.org/

@renovate renovate bot force-pushed the renovate/npm-nodemailer-vulnerability branch from 0ea8987 to b6a2995 Compare August 6, 2024 06:35
@renovate renovate bot changed the title Update dependency nodemailer to v6.9.9 [SECURITY] Update dependency nodemailer to v6.4.16 [SECURITY] Aug 6, 2024
@renovate renovate bot force-pushed the renovate/npm-nodemailer-vulnerability branch 2 times, most recently from 133d6ec to addd41c Compare August 15, 2025 16:06
@renovate renovate bot changed the title Update dependency nodemailer to v6.4.16 [SECURITY] Update dependency nodemailer to v6.9.9 [SECURITY] Aug 15, 2025
@renovate renovate bot force-pushed the renovate/npm-nodemailer-vulnerability branch from addd41c to 76096fd Compare October 15, 2025 22:15
@renovate renovate bot changed the title Update dependency nodemailer to v6.9.9 [SECURITY] Update dependency nodemailer to v6.4.16 [SECURITY] Oct 15, 2025
@renovate renovate bot changed the title Update dependency nodemailer to v6.4.16 [SECURITY] Update dependency nodemailer to v6.4.16 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate bot closed this Mar 27, 2026
@renovate renovate bot deleted the renovate/npm-nodemailer-vulnerability branch March 27, 2026 01:28
@renovate renovate bot changed the title Update dependency nodemailer to v6.4.16 [SECURITY] - autoclosed Update dependency nodemailer to v6.4.16 [SECURITY] Mar 30, 2026
@renovate renovate bot reopened this Mar 30, 2026
@renovate renovate bot force-pushed the renovate/npm-nodemailer-vulnerability branch 2 times, most recently from 76096fd to 56c9ce0 Compare March 30, 2026 17:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants