Semantic-release Project

Semantic-release

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.76%
  • Veröffentlicht 09.06.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:47

semantic-release is an open source npm package for automated version management and package publishing. In affected versions secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are e...

  • EPSS 0.17%
  • Veröffentlicht 18.11.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:19:35

In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain ch...