chore(deps): update dependency nvm-sh/nvm to v0.40.5#990
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.40.4→v0.40.5Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
nvm-sh/nvm (nvm-sh/nvm)
v0.40.5Compare Source
Security fix
Note this release addresses CVE-2026-10796.
New Stuff
nvm install --offline: install from cache without network accessBug Fixes
nvm_download_artifact: reject version strings with disallowed charactersnvm_get_checksum: pass the tarball name to awk as data, not program textnvm_download: avoidevalso mirror-supplied version strings can't inject commandsnvm_download: send a well-formed Authorization header on the wget pathnvm_normalize_lts: only reject uppercase for LTS names, not regular aliasesinstall.sh: checkmkdirreturn codesinstall.sh: fix POSIX compliance, printf format strings, and profile detectionnvm which: show alias name in infinite loop error messagenvm uninstall: fix alias cleanup glob expansionnvm debug: use default empty values for potentially unset variablesnvm_iojs_version_has_solaris_binary: fix comparison to detect non-iojs versionsnvm_download_artifact: fix error propagation from subshellsnvm_install_binary: return failure when binary download fails with-bnvm_get_arch: only apply musl suffix on x64 Alpinenvm_get_arch: addcommandprefix tounamecallnvm_resolve_local_alias: avoid using variable as printf format stringnvm_get_mirror: fix awk URL validation to actually reject invalid URLsnvm_ls_remote_combined: propagate iojs remote listing failuresnvm install: fixnvm errtypo tonvm_errfor-s/-bconflictnvm alias: fix colors not showing by defaultRefactors
nvm_rc_version: use fd 3 instead of exported env var for multiple returnDocs
--offlinehelp line alignmentMisc
Tests
install_nvm_from_git: stop git background gc/maintenance racing with cleanupinstall_nvm_from_git: fix malformed test command (missing space before])try/try_errhelpers; convert tests to use themnvm installworkflowConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.