Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Sep 25, 2024

This PR contains the following updates:

Package Change Age Confidence
mellium.im/xmpp v0.21.4 -> v0.22.0 age confidence

GitHub Vulnerability Alerts

CVE-2024-46957

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing because the stanza type is not checked. This is fixed in 0.22.0.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Contributor Author

renovate bot commented Sep 25, 2024

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
mellium.im/sasl v0.3.1 -> v0.3.2

@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 568bb27 to 4a64753 Compare October 12, 2024 15:19
@codecov
Copy link

codecov bot commented Oct 12, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 45.08%. Comparing base (3505bdc) to head (4a64753).
Report is 14 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #584      +/-   ##
==========================================
+ Coverage   44.56%   45.08%   +0.52%     
==========================================
  Files          84       86       +2     
  Lines        6815     6920     +105     
==========================================
+ Hits         3037     3120      +83     
- Misses       3484     3500      +16     
- Partials      294      300       +6     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 4a64753 to 321ba8d Compare November 17, 2024 16:53
@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 321ba8d to 1f77207 Compare December 22, 2024 16:04
@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 1f77207 to 8c332de Compare March 3, 2025 14:31
@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 8c332de to e492be8 Compare March 11, 2025 12:14
@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from e492be8 to 90cfb26 Compare April 8, 2025 12:23
@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 90cfb26 to ba672aa Compare May 7, 2025 17:47
@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from ba672aa to 8d4b434 Compare May 25, 2025 11:26
@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 8d4b434 to 285eb36 Compare September 21, 2025 14:16
@renovate renovate bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 285eb36 to 3af64ed Compare October 9, 2025 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant