-
Notifications
You must be signed in to change notification settings - Fork 0
Comparing changes
Open a pull request
base repository: rasata/nodegit
base: master
head repository: nodegit/nodegit
compare: master
- 11 commits
- 27 files changed
- 4 contributors
Commits on Mar 6, 2026
-
fix: update transitive dependencies to resolve known vulnerabilities
Non-breaking semver-compatible updates via npm audit fix: - tar 7.4.3 to 7.5.10 (High: path traversal, symlink poisoning, hardlink attacks) - lodash 4.17.21 to 4.17.23 (Moderate: prototype pollution in _.unset/_.omit) - js-yaml 3.14.1 to 3.14.2, 4.1.0 to 4.1.1 (Moderate: prototype pollution in merge) - glob 10.4.5 to 10.5.0 (High: command injection via --cmd) - brace-expansion 1.1.11 to 1.1.12, 2.0.1 to 2.0.2 (Low: ReDoS) - minimatch 3.1.2 to 3.1.5, 9.0.5 to 9.0.9, 5.1.6 to 9.0.9 (High: ReDoS) - mocha 11.4.0 to 11.7.5 (within ^11.4.0) - jshint 2.13.4 to 2.13.6 (within ^2.10.0) All updates stay within declared semver ranges. Only package-lock.json changed. Resolves 5 of 11 reported npm audit vulnerabilities.
Configuration menu - View commit details
-
Copy full SHA for 9436ddc - Browse repository at this point
Copy the full SHA 9436ddcView commit details -
fix: add npm overrides to resolve remaining high-severity vulnerabili…
…ties Adds overrides in package.json for transitive dependencies that cannot be updated within their parent packages declared semver ranges: - mocha > diff: ^7.0.0 overridden to ^8.0.3 Fixes DoS in parsePatch/applyPatch (GHSA-73rr-hh4g-fpgx) - mocha > serialize-javascript: ^6.0.2 overridden to ^7.0.4 Fixes RCE via RegExp.flags and Date.prototype.toISOString (GHSA-5c6j-r48x-rmvq) - jshint > minimatch: ~3.0.2 overridden to 3.1.5 Fixes multiple ReDoS vulnerabilities (GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74) Remaining: aws-sdk v2 low-severity advisory (GHSA-j965-2qgj-vjmq) affects all of v2, requires migration to v3 which is out of scope. Lint (jshint) verified passing after minimatch override.
Configuration menu - View commit details
-
Copy full SHA for 65e36ee - Browse repository at this point
Copy the full SHA 65e36eeView commit details
Commits on Apr 1, 2026
-
Merge pull request nodegit#2039 from AlexaXs/fix/npm-audit-vulnerabil…
…ities Resolves npm audit high-severity vulnerabilities
Configuration menu - View commit details
-
Copy full SHA for b54fce6 - Browse repository at this point
Copy the full SHA b54fce6View commit details -
fix: resolve 5 Dependabot security alerts via npm overrides
Add and update npm overrides to resolve high and moderate severity vulnerabilities in transitive dependencies: - tar: upgrade to ^7.5.11 (GHSA-9ppj-qmqm-q256, high - symlink path traversal) - picomatch: upgrade to ^4.0.4 (GHSA-c2c7-rcm5-vvqj, high - ReDoS; GHSA-3v7f-55p6-f55p, medium - method injection) - serialize-javascript: upgrade override to ^7.0.5 (GHSA-qj8w-gfj5-8c6v, medium - CPU exhaustion DoS) - brace-expansion: upgrade to ^2.0.3 and ^1.1.13 (GHSA-f886-m6hf-6m8v, medium - process hang and memory exhaustion) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Configuration menu - View commit details
-
Copy full SHA for 6e0c570 - Browse repository at this point
Copy the full SHA 6e0c570View commit details
Commits on Apr 20, 2026
-
Merge pull request nodegit#2041 from zawata/fix/dependabot-alerts
Fix 5 Dependabot security alerts via npm overrides
Configuration menu - View commit details
-
Copy full SHA for 51a3cb1 - Browse repository at this point
Copy the full SHA 51a3cb1View commit details -
Configuration menu - View commit details
-
Copy full SHA for 4d0adcb - Browse repository at this point
Copy the full SHA 4d0adcbView commit details -
Configuration menu - View commit details
-
Copy full SHA for 6feda5c - Browse repository at this point
Copy the full SHA 6feda5cView commit details
Commits on Apr 21, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 5136a90 - Browse repository at this point
Copy the full SHA 5136a90View commit details -
Configuration menu - View commit details
-
Copy full SHA for 9167b9c - Browse repository at this point
Copy the full SHA 9167b9cView commit details
Commits on Apr 23, 2026
-
Configuration menu - View commit details
-
Copy full SHA for e6c71bc - Browse repository at this point
Copy the full SHA e6c71bcView commit details
Commits on Jul 16, 2026
-
Configuration menu - View commit details
-
Copy full SHA for bdcbe39 - Browse repository at this point
Copy the full SHA bdcbe39View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff master...master