Skip to content

⬆️ Updates Node.js to v17.9.1#3555

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/node-17.x
Open

⬆️ Updates Node.js to v17.9.1#3555
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/node-17.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 27, 2026

This PR contains the following updates:

Package Type Update Change Age Confidence
node (source) minor 17.1.017.9.1 age confidence
@types/node (source) devDependencies patch ^17.0.21^17.0.45 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

nodejs/node (node)

v17.9.1: 2022-06-01, Version 17.9.1 (Current), @​ruyadorno

Compare Source

Notable Changes
  • Upgrade npm to 8.11.0
Update to OpenSSL 3.0.3

This update can be treated as a security release as the issues addressed in OpenSSL 3.0.3 slightly affect Node.js 17.
See https://nodejs.org/en/blog/vulnerability/openssl-fixes-in-regular-releases-may2022/ for more information on how the May 2022 OpenSSL releases affect other Node.js release lines.

Commits

Configuration

📅 Schedule: (in timezone Europe/Moscow)

  • Branch creation
    • "after 10pm every weekday,before 5am every weekday,every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Apr 27, 2026

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.


  • Branch has one or more failed status checks

@auto-assign auto-assign Bot requested a review from AlexRogalskiy April 27, 2026 17:03
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scan Summary

Tool Critical High Medium Low Status
Dependency Scan (universal) 2 8 5 0
Kotlin Static Analysis 0 0 0 0
Security Audit for Infrastructure 14 92 8 32
Secrets Audit 0 4 0 0
Shell Script Analysis 0 0 0 195
Kotlin Security Audit 0 0 0 0
Python Source Analyzer 0 0 0 0

Recommendation

Please review the findings from Code scanning alerts before approving this pull request. You can also configure the build rules or add suppressions to customize this bot 👍

@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 27, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedcodeclimate-test-reporter@​0.5.1941009750100
Addedidentity-obj-proxy@​3.0.01001007275100
Added@​types/​node-fetch@​2.6.131001007381100
Addeddel-cli@​4.0.11001007581100
Added@​types/​puppeteer@​5.4.71001007780100
Added@​octokit/​rest@​18.12.0991008681100
Addedcross-env@​7.0.310010010082100
Addedcoveralls@​3.1.19210010082100
Addedenv-cmd@​10.1.09910010083100

View full report

@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 27, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: npm ejs template injection vulnerability

CVE: GHSA-phwq-j96m-2c2q ejs template injection vulnerability (CRITICAL)

Affected versions: < 3.1.7

Patched version: 3.1.7

From: ?npm/ejs@2.7.4

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ejs@2.7.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: ?npm/@compodoc/compodoc@1.2.1npm/entities@4.5.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@4.5.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions
Copy link
Copy Markdown
Contributor

Welcome, new contributor!

@renovate renovate Bot force-pushed the renovate/node-17.x branch from 2d82c3e to bb559ed Compare May 3, 2026 05:16
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scan Summary

Tool Critical High Medium Low Status
Dependency Scan (universal) 2 7 5 0
Kotlin Security Audit 0 0 0 0
Kotlin Static Analysis 0 0 0 0
Security Audit for Infrastructure 14 92 8 32
Secrets Audit 0 4 0 0
Shell Script Analysis 0 0 0 195
Python Source Analyzer 0 0 0 0

Recommendation

Please review the findings from Code scanning alerts before approving this pull request. You can also configure the build rules or add suppressions to customize this bot 👍

@renovate renovate Bot force-pushed the renovate/node-17.x branch from bb559ed to 718d014 Compare May 4, 2026 01:56
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot force-pushed the renovate/node-17.x branch from 718d014 to 00243be Compare May 10, 2026 05:07
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scan Summary

Tool Critical High Medium Low Status
Dependency Scan (universal) 2 11 5 0
Kotlin Security Audit 0 0 0 0
Kotlin Static Analysis 0 0 0 0
Security Audit for Infrastructure 14 92 8 32
Secrets Audit 0 4 0 0
Shell Script Analysis 0 0 0 195
Python Source Analyzer 0 0 0 0

Recommendation

Please review the findings from Code scanning alerts before approving this pull request. You can also configure the build rules or add suppressions to customize this bot 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants