chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - #203

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability
Open

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]#203
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Nov 22, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
zx (source)8.8.18.8.5ageconfidence

zx Uses Incorrectly-Resolved Name or Reference

CVE-2025-13437 / GHSA-w87r-vg9q-crqm

More information

Details

When zx is invoked with --prefer-local=, the CLI creates a symlink named ./node_modules pointing to /node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external /node_modules outside the current working directory.

Severity

  • CVSS Score: 5.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:U

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/zx (zx)

v8.8.5: — Temporary Reservoir

Compare Source

This release fixes the issue, when zx flushes external node_modules on linking #​1348#​1349#​1355

Also globby@15.0.0 arrives here.

v8.8.4: — Flange Coupling

Compare Source

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic.
#​1344webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

v8.8.3: — Sealing Gasket

Compare Source

Continues #​1339 to prevent injections via Proxy input or custom toString() manipulations.

v8.8.2: — Leaking Valve

Compare Source

Fixes potential cmd injection via kill() method for Windows platform. #​1337#​1339. Affects the versions range 8.7.1...8.8.1.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Upgrade or downgrade of project dependencies. label Nov 22, 2025
@renovate
renovateBot requested review from a team and sullivanpj as code ownersNovember 22, 2025 05:34
@renovate

renovateBot commented Nov 22, 2025

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovateBot requested a review from a team as a code ownerNovember 22, 2025 05:34
@renovate
renovateBot enabled auto-merge (squash) November 22, 2025 05:34
@deepsource-io

deepsource-ioBot commented Nov 22, 2025

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 242a5a8...3426dbc on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall GradeSecurity

Reliability

Complexity

Hygiene

Code Review Summary

AnalyzerStatusUpdated (UTC)Details
JavaScriptMar 13, 2026 5:19p.m.Review ↗
ShellMar 13, 2026 5:19p.m.Review ↗

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a303cc4 to 0b62127CompareDecember 3, 2025 20:10
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 0b62127 to 086a8e3CompareDecember 31, 2025 14:12
@socket-security

socket-securityBot commented Dec 31, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm vite is 91.0% likely obfuscated

Confidence: 0.91

Location:Package overview

From:pnpm-lock.yamlnpm/vite@7.1.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vite@7.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 086a8e3 to 9280907CompareJanuary 8, 2026 19:40
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 301e790 to 57ccde8CompareJanuary 23, 2026 19:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 57ccde8 to c81dbf4CompareFebruary 2, 2026 19:12
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 5aa14de to beed79bCompareFebruary 17, 2026 16:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from beed79b to a718ff4CompareMarch 5, 2026 15:33
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a718ff4 to 3426dbcCompareMarch 13, 2026 17:18
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedMar 27, 2026
@renovaterenovateBot closed this Mar 27, 2026
auto-merge was automatically disabled March 27, 2026 02:22

Pull request was closed

@renovate
renovateBot deleted the renovate/npm-zx-vulnerability branch March 27, 2026 02:22
@storm-softwarestorm-software locked and limited conversation to collaborators Mar 28, 2026
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Mar 30, 2026
@renovaterenovateBot reopened this Mar 30, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 16ccca6 to 1350aa7CompareApril 1, 2026 17:00
@renovate
renovateBot enabled auto-merge (squash) April 1, 2026 17:00
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1350aa7 to 0b1b306CompareApril 8, 2026 21:05
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedApr 27, 2026
@renovaterenovateBot closed this Apr 27, 2026
auto-merge was automatically disabled April 27, 2026 17:55

Pull request was closed

@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Apr 27, 2026
@renovaterenovateBot reopened this Apr 27, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 5d5ed08 to b8018b9CompareApril 29, 2026 09:39
@renovate
renovateBot enabled auto-merge (squash) April 29, 2026 09:39
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from f2a4234 to fe16e04CompareMay 18, 2026 12:38
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 0f6ca81 to 5db2db9CompareJune 1, 2026 20:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 5db2db9 to b249becCompareJune 11, 2026 11:13
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 8c209c6 to 4de2da2CompareJuly 24, 2026 22:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 4ac5e07 to 7d9ad14CompareJuly 30, 2026 18:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 7d9ad14 to 1babb9eCompareAugust 12, 2026 04:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1babb9e to 282db73CompareAugust 14, 2026 21:09
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependenciesUpgrade or downgrade of project dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - #203

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability
Open

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]#203
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Nov 22, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
zx (source)8.8.18.8.5ageconfidence

zx Uses Incorrectly-Resolved Name or Reference

CVE-2025-13437 / GHSA-w87r-vg9q-crqm

More information

Details

When zx is invoked with --prefer-local=, the CLI creates a symlink named ./node_modules pointing to /node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external /node_modules outside the current working directory.

Severity

  • CVSS Score: 5.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:U

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/zx (zx)

v8.8.5: — Temporary Reservoir

Compare Source

This release fixes the issue, when zx flushes external node_modules on linking #​1348#​1349#​1355

Also globby@15.0.0 arrives here.

v8.8.4: — Flange Coupling

Compare Source

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic.
#​1344webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

v8.8.3: — Sealing Gasket

Compare Source

Continues #​1339 to prevent injections via Proxy input or custom toString() manipulations.

v8.8.2: — Leaking Valve

Compare Source

Fixes potential cmd injection via kill() method for Windows platform. #​1337#​1339. Affects the versions range 8.7.1...8.8.1.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Upgrade or downgrade of project dependencies. label Nov 22, 2025
@renovate
renovateBot requested review from a team and sullivanpj as code ownersNovember 22, 2025 05:34
@renovate

renovateBot commented Nov 22, 2025

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovateBot requested a review from a team as a code ownerNovember 22, 2025 05:34
@renovate
renovateBot enabled auto-merge (squash) November 22, 2025 05:34
@deepsource-io

deepsource-ioBot commented Nov 22, 2025

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 242a5a8...3426dbc on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall GradeSecurity

Reliability

Complexity

Hygiene

Code Review Summary

AnalyzerStatusUpdated (UTC)Details
JavaScriptMar 13, 2026 5:19p.m.Review ↗
ShellMar 13, 2026 5:19p.m.Review ↗

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a303cc4 to 0b62127CompareDecember 3, 2025 20:10
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 0b62127 to 086a8e3CompareDecember 31, 2025 14:12
@socket-security

socket-securityBot commented Dec 31, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm vite is 91.0% likely obfuscated

Confidence: 0.91

Location:Package overview

From:pnpm-lock.yamlnpm/vite@7.1.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vite@7.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 086a8e3 to 9280907CompareJanuary 8, 2026 19:40
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 301e790 to 57ccde8CompareJanuary 23, 2026 19:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 57ccde8 to c81dbf4CompareFebruary 2, 2026 19:12
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 5aa14de to beed79bCompareFebruary 17, 2026 16:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from beed79b to a718ff4CompareMarch 5, 2026 15:33
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a718ff4 to 3426dbcCompareMarch 13, 2026 17:18
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedMar 27, 2026
@renovaterenovateBot closed this Mar 27, 2026
auto-merge was automatically disabled March 27, 2026 02:22

Pull request was closed

@renovate
renovateBot deleted the renovate/npm-zx-vulnerability branch March 27, 2026 02:22
@storm-softwarestorm-software locked and limited conversation to collaborators Mar 28, 2026
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Mar 30, 2026
@renovaterenovateBot reopened this Mar 30, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 16ccca6 to 1350aa7CompareApril 1, 2026 17:00
@renovate
renovateBot enabled auto-merge (squash) April 1, 2026 17:00
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1350aa7 to 0b1b306CompareApril 8, 2026 21:05
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedApr 27, 2026
@renovaterenovateBot closed this Apr 27, 2026
auto-merge was automatically disabled April 27, 2026 17:55

Pull request was closed

@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Apr 27, 2026
@renovaterenovateBot reopened this Apr 27, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 5d5ed08 to b8018b9CompareApril 29, 2026 09:39
@renovate
renovateBot enabled auto-merge (squash) April 29, 2026 09:39
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from f2a4234 to fe16e04CompareMay 18, 2026 12:38
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 0f6ca81 to 5db2db9CompareJune 1, 2026 20:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 5db2db9 to b249becCompareJune 11, 2026 11:13
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 8c209c6 to 4de2da2CompareJuly 24, 2026 22:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 4ac5e07 to 7d9ad14CompareJuly 30, 2026 18:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 7d9ad14 to 1babb9eCompareAugust 12, 2026 04:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1babb9e to 282db73CompareAugust 14, 2026 21:09
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependenciesUpgrade or downgrade of project dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - #203

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability
Open

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]#203
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Nov 22, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
zx (source)8.8.18.8.5ageconfidence

zx Uses Incorrectly-Resolved Name or Reference

CVE-2025-13437 / GHSA-w87r-vg9q-crqm

More information

Details

When zx is invoked with --prefer-local=, the CLI creates a symlink named ./node_modules pointing to /node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external /node_modules outside the current working directory.

Severity

  • CVSS Score: 5.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:U

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/zx (zx)

v8.8.5: — Temporary Reservoir

Compare Source

This release fixes the issue, when zx flushes external node_modules on linking #​1348#​1349#​1355

Also globby@15.0.0 arrives here.

v8.8.4: — Flange Coupling

Compare Source

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic.
#​1344webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

v8.8.3: — Sealing Gasket

Compare Source

Continues #​1339 to prevent injections via Proxy input or custom toString() manipulations.

v8.8.2: — Leaking Valve

Compare Source

Fixes potential cmd injection via kill() method for Windows platform. #​1337#​1339. Affects the versions range 8.7.1...8.8.1.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Upgrade or downgrade of project dependencies. label Nov 22, 2025
@renovate
renovateBot requested review from a team and sullivanpj as code ownersNovember 22, 2025 05:34
@renovate

renovateBot commented Nov 22, 2025

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovateBot requested a review from a team as a code ownerNovember 22, 2025 05:34
@renovate
renovateBot enabled auto-merge (squash) November 22, 2025 05:34
@deepsource-io

deepsource-ioBot commented Nov 22, 2025

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 242a5a8...3426dbc on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall GradeSecurity

Reliability

Complexity

Hygiene

Code Review Summary

AnalyzerStatusUpdated (UTC)Details
JavaScriptMar 13, 2026 5:19p.m.Review ↗
ShellMar 13, 2026 5:19p.m.Review ↗

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a303cc4 to 0b62127CompareDecember 3, 2025 20:10
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 0b62127 to 086a8e3CompareDecember 31, 2025 14:12
@socket-security

socket-securityBot commented Dec 31, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm vite is 91.0% likely obfuscated

Confidence: 0.91

Location:Package overview

From:pnpm-lock.yamlnpm/vite@7.1.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vite@7.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 086a8e3 to 9280907CompareJanuary 8, 2026 19:40
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 301e790 to 57ccde8CompareJanuary 23, 2026 19:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 57ccde8 to c81dbf4CompareFebruary 2, 2026 19:12
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 5aa14de to beed79bCompareFebruary 17, 2026 16:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from beed79b to a718ff4CompareMarch 5, 2026 15:33
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a718ff4 to 3426dbcCompareMarch 13, 2026 17:18
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedMar 27, 2026
@renovaterenovateBot closed this Mar 27, 2026
auto-merge was automatically disabled March 27, 2026 02:22

Pull request was closed

@renovate
renovateBot deleted the renovate/npm-zx-vulnerability branch March 27, 2026 02:22
@storm-softwarestorm-software locked and limited conversation to collaborators Mar 28, 2026
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Mar 30, 2026
@renovaterenovateBot reopened this Mar 30, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 16ccca6 to 1350aa7CompareApril 1, 2026 17:00
@renovate
renovateBot enabled auto-merge (squash) April 1, 2026 17:00
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1350aa7 to 0b1b306CompareApril 8, 2026 21:05
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedApr 27, 2026
@renovaterenovateBot closed this Apr 27, 2026
auto-merge was automatically disabled April 27, 2026 17:55

Pull request was closed

@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Apr 27, 2026
@renovaterenovateBot reopened this Apr 27, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 5d5ed08 to b8018b9CompareApril 29, 2026 09:39
@renovate
renovateBot enabled auto-merge (squash) April 29, 2026 09:39
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from f2a4234 to fe16e04CompareMay 18, 2026 12:38
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 0f6ca81 to 5db2db9CompareJune 1, 2026 20:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 5db2db9 to b249becCompareJune 11, 2026 11:13
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 8c209c6 to 4de2da2CompareJuly 24, 2026 22:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 4ac5e07 to 7d9ad14CompareJuly 30, 2026 18:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 7d9ad14 to 1babb9eCompareAugust 12, 2026 04:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1babb9e to 282db73CompareAugust 14, 2026 21:09
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependenciesUpgrade or downgrade of project dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - #203

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability
Open

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]#203
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Nov 22, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
zx (source)8.8.18.8.5ageconfidence

zx Uses Incorrectly-Resolved Name or Reference

CVE-2025-13437 / GHSA-w87r-vg9q-crqm

More information

Details

When zx is invoked with --prefer-local=, the CLI creates a symlink named ./node_modules pointing to /node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external /node_modules outside the current working directory.

Severity

  • CVSS Score: 5.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:U

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/zx (zx)

v8.8.5: — Temporary Reservoir

Compare Source

This release fixes the issue, when zx flushes external node_modules on linking #​1348#​1349#​1355

Also globby@15.0.0 arrives here.

v8.8.4: — Flange Coupling

Compare Source

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic.
#​1344webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

v8.8.3: — Sealing Gasket

Compare Source

Continues #​1339 to prevent injections via Proxy input or custom toString() manipulations.

v8.8.2: — Leaking Valve

Compare Source

Fixes potential cmd injection via kill() method for Windows platform. #​1337#​1339. Affects the versions range 8.7.1...8.8.1.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Upgrade or downgrade of project dependencies. label Nov 22, 2025
@renovate
renovateBot requested review from a team and sullivanpj as code ownersNovember 22, 2025 05:34
@renovate

renovateBot commented Nov 22, 2025

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovateBot requested a review from a team as a code ownerNovember 22, 2025 05:34
@renovate
renovateBot enabled auto-merge (squash) November 22, 2025 05:34
@deepsource-io

deepsource-ioBot commented Nov 22, 2025

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 242a5a8...3426dbc on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall GradeSecurity

Reliability

Complexity

Hygiene

Code Review Summary

AnalyzerStatusUpdated (UTC)Details
JavaScriptMar 13, 2026 5:19p.m.Review ↗
ShellMar 13, 2026 5:19p.m.Review ↗

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a303cc4 to 0b62127CompareDecember 3, 2025 20:10
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 0b62127 to 086a8e3CompareDecember 31, 2025 14:12
@socket-security

socket-securityBot commented Dec 31, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm vite is 91.0% likely obfuscated

Confidence: 0.91

Location:Package overview

From:pnpm-lock.yamlnpm/vite@7.1.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vite@7.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 086a8e3 to 9280907CompareJanuary 8, 2026 19:40
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 301e790 to 57ccde8CompareJanuary 23, 2026 19:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 57ccde8 to c81dbf4CompareFebruary 2, 2026 19:12
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 5aa14de to beed79bCompareFebruary 17, 2026 16:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from beed79b to a718ff4CompareMarch 5, 2026 15:33
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a718ff4 to 3426dbcCompareMarch 13, 2026 17:18
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedMar 27, 2026
@renovaterenovateBot closed this Mar 27, 2026
auto-merge was automatically disabled March 27, 2026 02:22

Pull request was closed

@renovate
renovateBot deleted the renovate/npm-zx-vulnerability branch March 27, 2026 02:22
@storm-softwarestorm-software locked and limited conversation to collaborators Mar 28, 2026
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Mar 30, 2026
@renovaterenovateBot reopened this Mar 30, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 16ccca6 to 1350aa7CompareApril 1, 2026 17:00
@renovate
renovateBot enabled auto-merge (squash) April 1, 2026 17:00
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1350aa7 to 0b1b306CompareApril 8, 2026 21:05
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedApr 27, 2026
@renovaterenovateBot closed this Apr 27, 2026
auto-merge was automatically disabled April 27, 2026 17:55

Pull request was closed

@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Apr 27, 2026
@renovaterenovateBot reopened this Apr 27, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 5d5ed08 to b8018b9CompareApril 29, 2026 09:39
@renovate
renovateBot enabled auto-merge (squash) April 29, 2026 09:39
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from f2a4234 to fe16e04CompareMay 18, 2026 12:38
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 0f6ca81 to 5db2db9CompareJune 1, 2026 20:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 5db2db9 to b249becCompareJune 11, 2026 11:13
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 8c209c6 to 4de2da2CompareJuly 24, 2026 22:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 4ac5e07 to 7d9ad14CompareJuly 30, 2026 18:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 7d9ad14 to 1babb9eCompareAugust 12, 2026 04:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1babb9e to 282db73CompareAugust 14, 2026 21:09
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependenciesUpgrade or downgrade of project dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - #203

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability
Open

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]#203
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Nov 22, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
zx (source)8.8.18.8.5ageconfidence

zx Uses Incorrectly-Resolved Name or Reference

CVE-2025-13437 / GHSA-w87r-vg9q-crqm

More information

Details

When zx is invoked with --prefer-local=, the CLI creates a symlink named ./node_modules pointing to /node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external /node_modules outside the current working directory.

Severity

  • CVSS Score: 5.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:U

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/zx (zx)

v8.8.5: — Temporary Reservoir

Compare Source

This release fixes the issue, when zx flushes external node_modules on linking #​1348#​1349#​1355

Also globby@15.0.0 arrives here.

v8.8.4: — Flange Coupling

Compare Source

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic.
#​1344webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

v8.8.3: — Sealing Gasket

Compare Source

Continues #​1339 to prevent injections via Proxy input or custom toString() manipulations.

v8.8.2: — Leaking Valve

Compare Source

Fixes potential cmd injection via kill() method for Windows platform. #​1337#​1339. Affects the versions range 8.7.1...8.8.1.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Upgrade or downgrade of project dependencies. label Nov 22, 2025
@renovate
renovateBot requested review from a team and sullivanpj as code ownersNovember 22, 2025 05:34
@renovate

renovateBot commented Nov 22, 2025

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovateBot requested a review from a team as a code ownerNovember 22, 2025 05:34
@renovate
renovateBot enabled auto-merge (squash) November 22, 2025 05:34
@deepsource-io

deepsource-ioBot commented Nov 22, 2025

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 242a5a8...3426dbc on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall GradeSecurity

Reliability

Complexity

Hygiene

Code Review Summary

AnalyzerStatusUpdated (UTC)Details
JavaScriptMar 13, 2026 5:19p.m.Review ↗
ShellMar 13, 2026 5:19p.m.Review ↗

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a303cc4 to 0b62127CompareDecember 3, 2025 20:10
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 0b62127 to 086a8e3CompareDecember 31, 2025 14:12
@socket-security

socket-securityBot commented Dec 31, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm vite is 91.0% likely obfuscated

Confidence: 0.91

Location:Package overview

From:pnpm-lock.yamlnpm/vite@7.1.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vite@7.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 086a8e3 to 9280907CompareJanuary 8, 2026 19:40
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 301e790 to 57ccde8CompareJanuary 23, 2026 19:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 57ccde8 to c81dbf4CompareFebruary 2, 2026 19:12
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 5aa14de to beed79bCompareFebruary 17, 2026 16:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from beed79b to a718ff4CompareMarch 5, 2026 15:33
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a718ff4 to 3426dbcCompareMarch 13, 2026 17:18
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedMar 27, 2026
@renovaterenovateBot closed this Mar 27, 2026
auto-merge was automatically disabled March 27, 2026 02:22

Pull request was closed

@renovate
renovateBot deleted the renovate/npm-zx-vulnerability branch March 27, 2026 02:22
@storm-softwarestorm-software locked and limited conversation to collaborators Mar 28, 2026
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Mar 30, 2026
@renovaterenovateBot reopened this Mar 30, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 16ccca6 to 1350aa7CompareApril 1, 2026 17:00
@renovate
renovateBot enabled auto-merge (squash) April 1, 2026 17:00
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1350aa7 to 0b1b306CompareApril 8, 2026 21:05
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedApr 27, 2026
@renovaterenovateBot closed this Apr 27, 2026
auto-merge was automatically disabled April 27, 2026 17:55

Pull request was closed

@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Apr 27, 2026
@renovaterenovateBot reopened this Apr 27, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 5d5ed08 to b8018b9CompareApril 29, 2026 09:39
@renovate
renovateBot enabled auto-merge (squash) April 29, 2026 09:39
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from f2a4234 to fe16e04CompareMay 18, 2026 12:38
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 0f6ca81 to 5db2db9CompareJune 1, 2026 20:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 5db2db9 to b249becCompareJune 11, 2026 11:13
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 8c209c6 to 4de2da2CompareJuly 24, 2026 22:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 4ac5e07 to 7d9ad14CompareJuly 30, 2026 18:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 7d9ad14 to 1babb9eCompareAugust 12, 2026 04:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1babb9e to 282db73CompareAugust 14, 2026 21:09
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependenciesUpgrade or downgrade of project dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - #203

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability
Open

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]#203
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Nov 22, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
zx (source)8.8.18.8.5ageconfidence

zx Uses Incorrectly-Resolved Name or Reference

CVE-2025-13437 / GHSA-w87r-vg9q-crqm

More information

Details

When zx is invoked with --prefer-local=, the CLI creates a symlink named ./node_modules pointing to /node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external /node_modules outside the current working directory.

Severity

  • CVSS Score: 5.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:U

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/zx (zx)

v8.8.5: — Temporary Reservoir

Compare Source

This release fixes the issue, when zx flushes external node_modules on linking #​1348#​1349#​1355

Also globby@15.0.0 arrives here.

v8.8.4: — Flange Coupling

Compare Source

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic.
#​1344webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

v8.8.3: — Sealing Gasket

Compare Source

Continues #​1339 to prevent injections via Proxy input or custom toString() manipulations.

v8.8.2: — Leaking Valve

Compare Source

Fixes potential cmd injection via kill() method for Windows platform. #​1337#​1339. Affects the versions range 8.7.1...8.8.1.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Upgrade or downgrade of project dependencies. label Nov 22, 2025
@renovate
renovateBot requested review from a team and sullivanpj as code ownersNovember 22, 2025 05:34
@renovate

renovateBot commented Nov 22, 2025

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovateBot requested a review from a team as a code ownerNovember 22, 2025 05:34
@renovate
renovateBot enabled auto-merge (squash) November 22, 2025 05:34
@deepsource-io

deepsource-ioBot commented Nov 22, 2025

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 242a5a8...3426dbc on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall GradeSecurity

Reliability

Complexity

Hygiene

Code Review Summary

AnalyzerStatusUpdated (UTC)Details
JavaScriptMar 13, 2026 5:19p.m.Review ↗
ShellMar 13, 2026 5:19p.m.Review ↗

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a303cc4 to 0b62127CompareDecember 3, 2025 20:10
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 0b62127 to 086a8e3CompareDecember 31, 2025 14:12
@socket-security

socket-securityBot commented Dec 31, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm vite is 91.0% likely obfuscated

Confidence: 0.91

Location:Package overview

From:pnpm-lock.yamlnpm/vite@7.1.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vite@7.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 086a8e3 to 9280907CompareJanuary 8, 2026 19:40
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 301e790 to 57ccde8CompareJanuary 23, 2026 19:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 57ccde8 to c81dbf4CompareFebruary 2, 2026 19:12
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 5aa14de to beed79bCompareFebruary 17, 2026 16:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from beed79b to a718ff4CompareMarch 5, 2026 15:33
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a718ff4 to 3426dbcCompareMarch 13, 2026 17:18
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedMar 27, 2026
@renovaterenovateBot closed this Mar 27, 2026
auto-merge was automatically disabled March 27, 2026 02:22

Pull request was closed

@renovate
renovateBot deleted the renovate/npm-zx-vulnerability branch March 27, 2026 02:22
@storm-softwarestorm-software locked and limited conversation to collaborators Mar 28, 2026
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Mar 30, 2026
@renovaterenovateBot reopened this Mar 30, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 16ccca6 to 1350aa7CompareApril 1, 2026 17:00
@renovate
renovateBot enabled auto-merge (squash) April 1, 2026 17:00
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1350aa7 to 0b1b306CompareApril 8, 2026 21:05
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedApr 27, 2026
@renovaterenovateBot closed this Apr 27, 2026
auto-merge was automatically disabled April 27, 2026 17:55

Pull request was closed

@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Apr 27, 2026
@renovaterenovateBot reopened this Apr 27, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 5d5ed08 to b8018b9CompareApril 29, 2026 09:39
@renovate
renovateBot enabled auto-merge (squash) April 29, 2026 09:39
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from f2a4234 to fe16e04CompareMay 18, 2026 12:38
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 0f6ca81 to 5db2db9CompareJune 1, 2026 20:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 5db2db9 to b249becCompareJune 11, 2026 11:13
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 8c209c6 to 4de2da2CompareJuly 24, 2026 22:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 4ac5e07 to 7d9ad14CompareJuly 30, 2026 18:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 7d9ad14 to 1babb9eCompareAugust 12, 2026 04:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1babb9e to 282db73CompareAugust 14, 2026 21:09
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependenciesUpgrade or downgrade of project dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - #203

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability
Open

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]#203
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Nov 22, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
zx (source)8.8.18.8.5ageconfidence

zx Uses Incorrectly-Resolved Name or Reference

CVE-2025-13437 / GHSA-w87r-vg9q-crqm

More information

Details

When zx is invoked with --prefer-local=, the CLI creates a symlink named ./node_modules pointing to /node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external /node_modules outside the current working directory.

Severity

  • CVSS Score: 5.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:U

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/zx (zx)

v8.8.5: — Temporary Reservoir

Compare Source

This release fixes the issue, when zx flushes external node_modules on linking #​1348#​1349#​1355

Also globby@15.0.0 arrives here.

v8.8.4: — Flange Coupling

Compare Source

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic.
#​1344webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

v8.8.3: — Sealing Gasket

Compare Source

Continues #​1339 to prevent injections via Proxy input or custom toString() manipulations.

v8.8.2: — Leaking Valve

Compare Source

Fixes potential cmd injection via kill() method for Windows platform. #​1337#​1339. Affects the versions range 8.7.1...8.8.1.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Upgrade or downgrade of project dependencies. label Nov 22, 2025
@renovate
renovateBot requested review from a team and sullivanpj as code ownersNovember 22, 2025 05:34
@renovate

renovateBot commented Nov 22, 2025

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovateBot requested a review from a team as a code ownerNovember 22, 2025 05:34
@renovate
renovateBot enabled auto-merge (squash) November 22, 2025 05:34
@deepsource-io

deepsource-ioBot commented Nov 22, 2025

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 242a5a8...3426dbc on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall GradeSecurity

Reliability

Complexity

Hygiene

Code Review Summary

AnalyzerStatusUpdated (UTC)Details
JavaScriptMar 13, 2026 5:19p.m.Review ↗
ShellMar 13, 2026 5:19p.m.Review ↗

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a303cc4 to 0b62127CompareDecember 3, 2025 20:10
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 0b62127 to 086a8e3CompareDecember 31, 2025 14:12
@socket-security

socket-securityBot commented Dec 31, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm vite is 91.0% likely obfuscated

Confidence: 0.91

Location:Package overview

From:pnpm-lock.yamlnpm/vite@7.1.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vite@7.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 086a8e3 to 9280907CompareJanuary 8, 2026 19:40
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 301e790 to 57ccde8CompareJanuary 23, 2026 19:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 57ccde8 to c81dbf4CompareFebruary 2, 2026 19:12
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 5aa14de to beed79bCompareFebruary 17, 2026 16:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from beed79b to a718ff4CompareMarch 5, 2026 15:33
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a718ff4 to 3426dbcCompareMarch 13, 2026 17:18
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedMar 27, 2026
@renovaterenovateBot closed this Mar 27, 2026
auto-merge was automatically disabled March 27, 2026 02:22

Pull request was closed

@renovate
renovateBot deleted the renovate/npm-zx-vulnerability branch March 27, 2026 02:22
@storm-softwarestorm-software locked and limited conversation to collaborators Mar 28, 2026
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Mar 30, 2026
@renovaterenovateBot reopened this Mar 30, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 16ccca6 to 1350aa7CompareApril 1, 2026 17:00
@renovate
renovateBot enabled auto-merge (squash) April 1, 2026 17:00
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1350aa7 to 0b1b306CompareApril 8, 2026 21:05
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedApr 27, 2026
@renovaterenovateBot closed this Apr 27, 2026
auto-merge was automatically disabled April 27, 2026 17:55

Pull request was closed

@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Apr 27, 2026
@renovaterenovateBot reopened this Apr 27, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 5d5ed08 to b8018b9CompareApril 29, 2026 09:39
@renovate
renovateBot enabled auto-merge (squash) April 29, 2026 09:39
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from f2a4234 to fe16e04CompareMay 18, 2026 12:38
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 0f6ca81 to 5db2db9CompareJune 1, 2026 20:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 5db2db9 to b249becCompareJune 11, 2026 11:13
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 8c209c6 to 4de2da2CompareJuly 24, 2026 22:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 4ac5e07 to 7d9ad14CompareJuly 30, 2026 18:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 7d9ad14 to 1babb9eCompareAugust 12, 2026 04:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1babb9e to 282db73CompareAugust 14, 2026 21:09
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependenciesUpgrade or downgrade of project dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - #203

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability
Open

chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]#203
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-zx-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Nov 22, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
zx (source)8.8.18.8.5ageconfidence

zx Uses Incorrectly-Resolved Name or Reference

CVE-2025-13437 / GHSA-w87r-vg9q-crqm

More information

Details

When zx is invoked with --prefer-local=, the CLI creates a symlink named ./node_modules pointing to /node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external /node_modules outside the current working directory.

Severity

  • CVSS Score: 5.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:U

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/zx (zx)

v8.8.5: — Temporary Reservoir

Compare Source

This release fixes the issue, when zx flushes external node_modules on linking #​1348#​1349#​1355

Also globby@15.0.0 arrives here.

v8.8.4: — Flange Coupling

Compare Source

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic.
#​1344webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

v8.8.3: — Sealing Gasket

Compare Source

Continues #​1339 to prevent injections via Proxy input or custom toString() manipulations.

v8.8.2: — Leaking Valve

Compare Source

Fixes potential cmd injection via kill() method for Windows platform. #​1337#​1339. Affects the versions range 8.7.1...8.8.1.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Upgrade or downgrade of project dependencies. label Nov 22, 2025
@renovate
renovateBot requested review from a team and sullivanpj as code ownersNovember 22, 2025 05:34
@renovate

renovateBot commented Nov 22, 2025

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovateBot requested a review from a team as a code ownerNovember 22, 2025 05:34
@renovate
renovateBot enabled auto-merge (squash) November 22, 2025 05:34
@deepsource-io

deepsource-ioBot commented Nov 22, 2025

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 242a5a8...3426dbc on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall GradeSecurity

Reliability

Complexity

Hygiene

Code Review Summary

AnalyzerStatusUpdated (UTC)Details
JavaScriptMar 13, 2026 5:19p.m.Review ↗
ShellMar 13, 2026 5:19p.m.Review ↗

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a303cc4 to 0b62127CompareDecember 3, 2025 20:10
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 0b62127 to 086a8e3CompareDecember 31, 2025 14:12
@socket-security

socket-securityBot commented Dec 31, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm vite is 91.0% likely obfuscated

Confidence: 0.91

Location:Package overview

From:pnpm-lock.yamlnpm/vite@7.1.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vite@7.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 086a8e3 to 9280907CompareJanuary 8, 2026 19:40
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 301e790 to 57ccde8CompareJanuary 23, 2026 19:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 57ccde8 to c81dbf4CompareFebruary 2, 2026 19:12
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 5aa14de to beed79bCompareFebruary 17, 2026 16:48
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from beed79b to a718ff4CompareMarch 5, 2026 15:33
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from a718ff4 to 3426dbcCompareMarch 13, 2026 17:18
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedMar 27, 2026
@renovaterenovateBot closed this Mar 27, 2026
auto-merge was automatically disabled March 27, 2026 02:22

Pull request was closed

@renovate
renovateBot deleted the renovate/npm-zx-vulnerability branch March 27, 2026 02:22
@storm-softwarestorm-software locked and limited conversation to collaborators Mar 28, 2026
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Mar 30, 2026
@renovaterenovateBot reopened this Mar 30, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 16ccca6 to 1350aa7CompareApril 1, 2026 17:00
@renovate
renovateBot enabled auto-merge (squash) April 1, 2026 17:00
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1350aa7 to 0b1b306CompareApril 8, 2026 21:05
@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedApr 27, 2026
@renovaterenovateBot closed this Apr 27, 2026
auto-merge was automatically disabled April 27, 2026 17:55

Pull request was closed

@renovaterenovateBot changed the title chore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security] - autoclosedchore(monorepo): update pnpm.catalog.default zx to v8.8.5 [security]Apr 27, 2026
@renovaterenovateBot reopened this Apr 27, 2026
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 5d5ed08 to b8018b9CompareApril 29, 2026 09:39
@renovate
renovateBot enabled auto-merge (squash) April 29, 2026 09:39
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from f2a4234 to fe16e04CompareMay 18, 2026 12:38
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 0f6ca81 to 5db2db9CompareJune 1, 2026 20:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 5db2db9 to b249becCompareJune 11, 2026 11:13
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 3 times, most recently from 8c209c6 to 4de2da2CompareJuly 24, 2026 22:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch 2 times, most recently from 4ac5e07 to 7d9ad14CompareJuly 30, 2026 18:11
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 7d9ad14 to 1babb9eCompareAugust 12, 2026 04:16
@renovate
renovateBotforce-pushed the renovate/npm-zx-vulnerability branch from 1babb9e to 282db73CompareAugust 14, 2026 21:09
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependenciesUpgrade or downgrade of project dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants