Skip to content

fix(deps): update dependency chrome-launcher to ^0.13.0 [security]#106

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-chrome-launcher-vulnerability
Open

fix(deps): update dependency chrome-launcher to ^0.13.0 [security]#106
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-chrome-launcher-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 18, 2023

This PR contains the following updates:

Package Change Age Confidence
chrome-launcher ^0.11.2^0.13.0 age confidence

GitHub Vulnerability Alerts

CVE-2020-7645

chrome-launcher prior to 0.13.2 is subject to OS Command Injection via the $HOME environment variable in Linux operating systems. This issue is patched in version 0.13.2.


Release Notes

GoogleChrome/chrome-launcher (chrome-launcher)

v0.13.2

Compare Source

  • 7c1ea547 deps: bump to is-wsl@​2.2.0 (#​187)
  • 2ae5591d fix: sanitize environment variables used in RegExp (#​197)

v0.13.1

Compare Source

  • bf2957ac deps: update various dependencies (#​192)

v0.13.0

Compare Source

  • 83da1e41 feat: add killAll function (#​186)
  • b8c89f84 flags: disable the default browser check (#​181) (#​182)
  • 6112555c fix: log taskkill error based on logging opts (#​178) (#​179)
  • 7c935efa docs: add missing quote in README.md example (#​180)
  • 2e829c7d Skip --disable-setuid-sandbox flag when ignoreDefaultFlags = true (#​171)

v0.12.0

Compare Source

  • 66a5e226 flags: add new --disable flags to reduce noise and disable backgrounding (#​170)
    • --disable-component-extensions-with-background-pages
    • --disable-backgrounding-occluded-windows
    • --disable-renderer-backgrounding
    • --disable-background-timer-throttling
  • c4890ee3 feat: expose public interface for locating Chrome installations (#​177)
    • Launcher.getInstallations() returns an array of paths to available Chrome binaries
  • a5ccaa4e deps: update assorted dependencies (#​175)
  • e67a10df --disable-translation is now --disable-features=TranslateUI (#​167)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-chrome-launcher-vulnerability branch from c398e2d to a36ddb8 Compare August 10, 2025 14:47
@socket-security
Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedis-docker@​2.2.11001006976100
Updatedis-wsl@​2.1.1 ⏵ 2.2.010010072 +176100
Addedrimraf@​3.0.210010010076100
Updatedchrome-launcher@​0.11.2 ⏵ 0.13.496 +1100 +75100 +182100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants