renovate
9 known vulnerabilities · 0 critical · 0 high
Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance
Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file
Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository
Child processes spawned by Renovate incorrectly have full access to environment variables
Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies
Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file
Renovate vulnerable to arbitrary command injection via npm manager and malicious Renovate configuration
Renovate vulnerable to arbitrary command injection via Gradle Wrapper and malicious `distributionUrl`
Malicious code in renovate-config-doctolib (npm)