semantic-release@3.0.1 vulnerabilities

Automated semver compliant package publishing

Direct Vulnerabilities

Known vulnerabilities in the semantic-release package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Information Disclosure

semantic-release is an Automated semver compliant package publishing

Affected versions of this package are vulnerable to Information Disclosure. Secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that become encoded when included in a URL.

How to fix Information Disclosure?

Upgrade semantic-release to version 17.2.3 or higher.

<17.2.3