[Security] Bump nodemailer from 6.4.5 to 6.4.16 in /backend
Created by: dependabot-preview[bot]
This pull request was created by Dependabot Preview, and you've upgraded to Dependabot. This means it won't respond to dependabot
commands nor will it be automatically closed if a new version is found.
If you close this pull request, Dependabot will re-create it the next time it checks for updates and everything will work as expected.
Bumps nodemailer from 6.4.5 to 6.4.16. This update includes a security fix.
Vulnerabilities fixed
Sourced from The GitHub Security Advisory Database.
Command injection in nodemailer This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
Affected versions: < 6.4.16
Changelog
Sourced from nodemailer's changelog.
6.4.16 2020-11-12
- Applied updated prettier formating rules
6.4.15 2020-11-06
- Minor changes in header key casing
6.4.14 2020-10-14
- Disabled postinstall script
6.4.13 2020-10-02
- Fix normalizeHeaderKey method for single node messages
6.4.12 2020-09-30
- Better handling of attachment filenames that include quote symbols
- Includes all information from the oath2 error response in the error message (Normal Gaussian) [1787f227]
6.4.11 2020-07-29
- Fixed escape sequence handling in address parsing
6.4.10 2020-06-17
- Fixed RFC822 output for MailComposer when using invalid content-type value. Mostly relevant if message attachments have stragne content-type values set.
6.4.7 2020-05-28
- Always set charset=utf-8 for Content-Type headers
- Catch error whn using invalid crypto.sign input
6.4.6 2020-03-20
- fix:
requeueAttempts=n
should requeuen
times (Patrick Malouin) [a27ed2f7]6.4.4 2020-03-01
- Add
options.forceAuth
for SMTP (Patrick Malouin) [a27ed2f7]6.4.3 2020-02-22
- Added an option to specify max number of requeues when connection closes unexpectedly (Igor Sechyn) [8a927f5a]
6.4.2 2019-12-11
- Fixed bug where array item was used with a potentially empty array
... (truncated)
Commits
-
ba31c64
v6.4.16 -
7e7b2b2
v6.4.15 -
fca2041
Update CHANGELOG.md -
b4ccfa3
Oups -
24b93bf
Add ethereal.email to well-known/services.json -
0f132fa
doc: make the code a little more accessible with some code comments. -
1815bad
v6.4.14 -
dd26ddd
v6.4.13 -
455cfbe
v6.4.12 -
1787f22
Includes all information from the oath2 error response in the error message (... - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language -
@dependabot badge me
will comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot dashboard:
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)