fix(deps): update dependency mongodb to v4.17.0 [security] - #494
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency mongodb to v4.17.0 [security]#494renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
April 3, 2024 17:20
30c2bed to
0c06011
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
April 13, 2024 22:45
0c06011 to
3a3dc4a
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
August 13, 2025 12:58
a8a2f8e to
9f04604
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
August 31, 2025 12:11
9f04604 to
33f0045
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
September 25, 2025 17:13
33f0045 to
b8c0417
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
October 21, 2025 19:55
b8c0417 to
3fa45ef
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
November 10, 2025 21:56
3fa45ef to
762c548
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
November 18, 2025 13:39
762c548 to
4f6bcc8
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
December 3, 2025 15:44
4f6bcc8 to
188a1d8
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
January 1, 2026 03:18
188a1d8 to
2d7f141
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
January 8, 2026 21:03
2d7f141 to
485b3f0
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
January 19, 2026 23:03
485b3f0 to
e3c46ff
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
February 2, 2026 15:56
e3c46ff to
185b052
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
February 17, 2026 18:04
351afc3 to
cf92997
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
March 5, 2026 16:46
cf92997 to
336f785
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
March 13, 2026 13:06
336f785 to
5797d04
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
April 8, 2026 15:49
02da7f2 to
dfb0470
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
3 times, most recently
from
April 29, 2026 17:04
697aff9 to
2ffa0a3
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
May 18, 2026 13:54
15cca07 to
4d32c2a
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
June 1, 2026 23:46
3ddd3b9 to
dc07076
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 11, 2026 09:17
dc07076 to
d96471b
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
July 21, 2026 00:12
56daa2d to
9db82c2
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
2 times, most recently
from
July 21, 2026 21:59
9db82c2 to
7bf58a3
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
July 24, 2026 22:51
7bf58a3 to
ce4dc82
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.2.1→4.17.0MongoDB Driver may publish events containing authentication-related data
CVE-2021-32050 / GHSA-vxvm-qww3-2fh7
More information
Details
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.
Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).
This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).
Severity
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
mongodb/node-mongodb-native (mongodb)
v4.17.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.17.0 of the
mongodbpackage!Release Notes
mongodb-js/saslprepis now installed by defaultUntil v6, the driver included the
saslpreppackage as an optional dependency for SCRAM-SHA-256 authentication.saslprepbreaks when bundled with webpack because it attempted to read a file relative to the package location and consequently the driver would throw errors when using SCRAM-SHA-256 if it were bundled.The driver now depends on
mongodb-js/saslprep, a fork ofsaslprepthat can be bundled with webpack because it includes the necessary saslprep data in memory upon loading. This will be installed by default but will only be used if SCRAM-SHA-256 authentication is used.Remove credential availability on
ConnectionPoolCreatedEventIn order to avoid mistakenly printing credentials the
ConnectionPoolCreatedEventwill replace the credentials option with an empty object. The credentials are still accessble via MongoClient options:client.options.credentials.Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.16.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.16.0 of the
mongodbpackage!Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.15.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.15.0 of the mongodb package!
Features
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.14.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.14.0 of the mongodb package!
Deprecations
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.13.0Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.12.1Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.12.0Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.11.0Compare Source
Features
Bug Fixes
v4.10.0Compare Source
Features
Bug Fixes
v4.9.1Compare Source
The MongoDB Node.js team is pleased to announce version 4.9.1 of the mongodb package!
Release Highlights
This is a bug fix release as noted below.
Bug Fixes
v4.9.0Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.8.1Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.8.0Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.7.0Compare Source
Features
Bug Fixes
v4.6.0Compare Source
Features
Bug Fixes
v4.5.0Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.4.1Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.4.0Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.3.1Compare Source
Features
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.