Skip to content

[deps]: Update ldapts to v8 #788

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jul 2, 2025
Merged

[deps]: Update ldapts to v8 #788

merged 1 commit into from
Jul 2, 2025

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 26, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
ldapts 7.4.0 -> 8.0.1 age adoption passing confidence

Release Notes

ldapts/ldapts (ldapts)

v8.0.1

Compare Source

Bug Fixes

v8.0.0

Compare Source

Bug Fixes
BREAKING CHANGES
  • Drop support for Node.js v18. Minimum required version is now Node.js v20.
  • Updated engines field in package.json
  • Updated CI configuration to test on supported versions only
  • Run CI jobs for PRs targeting main

Configuration

📅 Schedule: Branch creation - "every 2nd week starting on the 2 week of the year before 4am on Monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner May 26, 2025 01:23
@renovate renovate bot requested a review from BTreston May 26, 2025 01:23
@bitwarden-bot bitwarden-bot changed the title [deps]: Update ldapts to v8 [PM-22064] [deps]: Update ldapts to v8 May 26, 2025
@bitwarden-bot
Copy link

Internal tracking:

Copy link

codecov bot commented May 26, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 7.72%. Comparing base (32e3327) to head (8e4359d).
Report is 9 commits behind head on main.

✅ All tests successful. No failed tests found.

Additional details and impacted files
@@          Coverage Diff          @@
##            main    #788   +/-   ##
=====================================
  Coverage   7.72%   7.72%           
=====================================
  Files         68      68           
  Lines       2757    2757           
  Branches     475     475           
=====================================
  Hits         213     213           
  Misses      2529    2529           
  Partials      15      15           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate renovate bot changed the title [PM-22064] [deps]: Update ldapts to v8 [deps]: Update ldapts to v8 May 26, 2025
@renovate renovate bot force-pushed the renovate/ldapts-8.x branch from 91d0d56 to c4ed516 Compare June 6, 2025 14:00
@renovate renovate bot force-pushed the renovate/ldapts-8.x branch from c4ed516 to 8e4359d Compare July 1, 2025 01:50
Copy link

sonarqubecloud bot commented Jul 2, 2025

Copy link
Contributor

github-actions bot commented Jul 2, 2025

Logo
Checkmarx One – Scan Summary & Details15c22ca6-7a02-4952-b96c-6c9f45db4c27

New Issues (21)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL CVE-2025-3069 Npm-electron-34.1.1
detailsRecommended version: 34.5.6
Description: Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: g1wuQcxL1kx3jhpZmIS4vJQAeLicW0vbSTnqqUoKikQ%3D
Vulnerable Package
CRITICAL CVE-2025-4052 Npm-electron-34.1.1
detailsRecommended version: 34.5.5
Description: Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specif...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Qo8kXXY8CgYANyajNdNp0Yjp5HC8zQ3VGiOC%2F34pBpY%3D
Vulnerable Package
HIGH CVE-2025-0451 Npm-electron-34.1.1
detailsRecommended version: 34.5.2
Description: Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: HXbSW4ENi2wFWn109bLZaMDR3XZqLwvTxQOhdVu8qYE%3D
Vulnerable Package
HIGH CVE-2025-0995 Npm-electron-34.1.1
detailsRecommended version: 34.3.3
Description: Use After Free in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: UAUuBF7Ph9rJL6QjAL46nM%2F45gRS2TE7z66bn17yPkc%3D
Vulnerable Package
HIGH CVE-2025-0999 Npm-electron-34.1.1
detailsRecommended version: 34.3.3
Description: Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: idfaJQIiHqjuJ%2BH%2FLbHXNCYRUpJpaqmAT3dhRA5A%2BvI%3D
Vulnerable Package
HIGH CVE-2025-1914 Npm-electron-34.1.1
detailsRecommended version: 34.3.4
Description: An out-of-bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perform out-of-bounds memory access via a crafted ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: StRmVDVTU6n0Tkqp0RY5uHn0%2FqiUt7fZDjYtKKvuvsg%3D
Vulnerable Package
HIGH CVE-2025-1915 Npm-electron-34.1.1
detailsRecommended version: 34.5.7
Description: Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: LcjUPxwEYH%2FyAmqKH%2F1ROSoaurFJftKxhAH5PNzJKq8%3D
Vulnerable Package
HIGH CVE-2025-1919 Npm-electron-34.1.1
detailsRecommended version: 34.3.4
Description: An out-of-bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out-of-bounds memory access...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 9u0a%2FcaeYOuqLBMn%2BooqDDcAd0dD13FmvZD7hLBMaRQ%3D
Vulnerable Package
HIGH CVE-2025-2135 Npm-electron-34.1.1
detailsRecommended version: 34.5.7
Description: Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: yV0q38idPkOn9vKvovhkkmG5JrXaJza51FAwKhR6z14%3D
Vulnerable Package
HIGH CVE-2025-2136 Npm-electron-34.1.1
detailsRecommended version: 34.5.1
Description: Use After Free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: NhL78pGHeekAwrhrxTG7CAN894qoUtmhOlkSqdu3P%2F4%3D
Vulnerable Package
HIGH CVE-2025-2137 Npm-electron-34.1.1
detailsRecommended version: 34.5.7
Description: Out-of-bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out-of-bounds memory access via a crafted HTM...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: kZmn8EeR%2FPyZnuSzuxFxqTOd0Bz6fniGUm465ZURYFY%3D
Vulnerable Package
HIGH CVE-2025-2476 Npm-electron-34.1.1
detailsRecommended version: 34.5.7
Description: Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: qFvpy%2BWVUOdQPBQClaPaQpBpouDX2LToVczF63PG%2BCM%3D
Vulnerable Package
HIGH CVE-2025-4050 Npm-electron-34.1.1
detailsRecommended version: 34.5.6
Description: Out-of-bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specifi...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: thsebSj%2FNYhN%2BQ3FZVfJXYMgpma%2B1S4A%2BJSX2VF4bfo%3D
Vulnerable Package
HIGH CVE-2025-5063 Npm-electron-34.1.1
detailsRecommended version: 34.5.7
Description: Use After Free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafte...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: bzMM%2B9hV16u66WAXu3Vpl5%2BW%2F3VC1PkOkYflOv6Tp0w%3D
Vulnerable Package
MEDIUM CVE-2025-0444 Npm-electron-34.1.1
detailsRecommended version: 34.5.1
Description: Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: CJmph6lH%2F3TIv3ec82HF%2BswAmjtaKeqFThRmEH4YotU%3D
Vulnerable Package
MEDIUM CVE-2025-0445 Npm-electron-34.1.1
detailsRecommended version: 34.3.1
Description: Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: AhNLrA7IUWRkekYKf14HGkGAmWyb5ilbgcyGTKNUvIw%3D
Vulnerable Package
MEDIUM CVE-2025-0996 Npm-electron-34.1.1
detailsRecommended version: 34.3.3
Description: Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of th...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 8ctdFSsa%2FbRYaDqniOG7AtbPDe%2BrjgIdnI4Swhq8Lvg%3D
Vulnerable Package
MEDIUM CVE-2025-1923 Npm-electron-34.1.1
detailsRecommended version: 34.5.7
Description: Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a ma...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Nv9tnIwMOz4ZUQailyY8UCcJQXGjz%2F6jV2OLhqSqyiQ%3D
Vulnerable Package
MEDIUM CVE-2025-3070 Npm-electron-34.1.1
detailsRecommended version: 34.5.8
Description: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege esc...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Gs4wMmmFE99OcS27NhrWfoJVfb4xtC3PSSPUv0uvii0%3D
Vulnerable Package
MEDIUM CVE-2025-4664 Npm-electron-34.1.1
detailsRecommended version: 34.5.7
Description: Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafte...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 5hhZPJoeEHZN5fIDytH5dE6KDq64KLPJKViUsfoFrdU%3D
Vulnerable Package
MEDIUM CVE-2025-5067 Npm-electron-34.1.1
detailsRecommended version: 34.5.8
Description: Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HT...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: zISJXg8G5pXNAkihARr80skqx6A3hBI%2BYbTW6nQMXMc%3D
Vulnerable Package

Copy link
Member

@vincentsalucci vincentsalucci left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♦️ Major update
👍 High pass rate/confidence
🟢 All builds green

@vincentsalucci vincentsalucci merged commit 19937fc into main Jul 2, 2025
23 of 24 checks passed
@vincentsalucci vincentsalucci deleted the renovate/ldapts-8.x branch July 2, 2025 02:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants