Skip to content

test(deps): bump dotenv from 17.4.2 to 18.0.3 - #131

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dotenv-18.0.3
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dotenv-18.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps dotenv from 17.4.2 to 18.0.3.

Changelog

Sourced from dotenv's changelog.

18.0.3 (2026-09-22)

Changed

  • Patch DOTENV_QUIET setting when inside .env file (#1059)

18.0.2 (2026-09-21)

Changed

  • Patch additional edge cases for the fast parser (#1056)

18.0.1 (2026-09-18)

Changed

  • Handle file urls in config logging (#1054)

18.0.0 (2026-09-17)

Added

  • NEW: Dotenv now has a CLI. (#1022)
$ dotenv run -- node index.js
◇ injected env (2) from .env
Hello Dotenv
  • NEW: Dotenv now has a fast parser thanks to @​homanp of superagent.sh. Pass config({ fast: true }), flag --fast, or set DOTENV_FAST=true to opt-in to ~2x faster character-scanner parser. (#1010)
$ dotenv run --fast -- node index.js
◇ injected env (2) from .env
Hello Dotenv

faster than Node native parseEnv!

Changed

  • Injecting message sent to stderr rather than stdout and tips removed (#1037)

Removed

  • Remove tips (#1031)
  • Remove skill files (#1032)
  • Remove Spanish README (#1034)

... (truncated)

Commits
  • f6390d1 18.0.3
  • 456da68 changelog
  • 12ea34b Merge pull request #1059 from motdotla/config-quiet
  • a654bc2 patch DOTENV_QUIET
  • a0ae3e0 Merge pull request #1058 from SulimanAbdulrazzaq/fix/fast-parser-lone-export-...
  • d6b3a1d demonstrate DOTENV_QUIET failing
  • d57e0bc fix: keep assignments after a bare export line in the fast parser
  • 5203712 perf: skip quoted text and short-circuit ASCII whitespace checks
  • c69ed11 chore: align package version with 18.0.2 changelog
  • 2db9acf fix: retain closing quote candidates in the fast scanner
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [dotenv](https://github.com/motdotla/dotenv) from 17.4.2 to 18.0.3.
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.4.2...v18.0.3)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 18.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

❌MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 24 0 0 0.41s
✅ ACTION zizmor 24 0 0 0 7.83s
✅ DOCKERFILE hadolint 3 0 0 1.33s
✅ JSON npm-package-json-lint yes no no 0.56s
✅ JSON prettier 22 3 0 0 0.64s
✅ JSON v8r 22 0 0 9.56s
✅ MARKDOWN markdownlint 12 0 0 0 1.21s
✅ MARKDOWN markdown-table-formatter 12 1 0 0 0.28s
✅ REPOSITORY betterleaks yes no no 1.3s
✅ REPOSITORY checkov yes no no 21.88s
✅ REPOSITORY git_diff yes no no 0.02s
❌ REPOSITORY grype yes 2 1 102.19s
❌ REPOSITORY osv-scanner yes 6 no 1.57s
✅ REPOSITORY secretlint yes no no 2.58s
✅ REPOSITORY syft yes no no 4.2s
❌ REPOSITORY trivy yes 2 1 11.54s
✅ REPOSITORY trivy-sbom yes no no 0.47s
✅ REPOSITORY trufflehog yes no no 5.1s
⚠️ SPELL lychee 86 1 0 10.46s
✅ YAML prettier 32 0 0 0 1.19s
✅ YAML v8r 32 0 0 10.9s
✅ YAML yamllint 32 0 0 1.4s

Detailed Issues

❌ REPOSITORY / grype - 2 errors
error: A high vulnerability in python package: urllib3, version 2.7.0 was found at: /.devcontainer/cpp/requirements.txt

error: A high vulnerability in python package: urllib3, version 2.7.0 was found at: /.devcontainer/cpp/requirements.txt

warning: A medium vulnerability in python package: urllib3, version 2.7.0 was found at: /.devcontainer/cpp/requirements.txt

warning: 1 warnings emitted
error: 2 errors emitted
❌ REPOSITORY / osv-scanner - 6 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned package-lock.json file and found 73 packages
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/cortex-mf/Cargo.lock file and found 30 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned test/rust/workspace/cortex-m/Cargo.lock file and found 30 packages
End status: 61 dirs visited, 220 inodes visited, 7 Extract calls, 23.063829ms elapsed, 23.06403ms wall time
Loaded filter from: test/rust/workspace/cortex-m/osv-scanner.toml
Loaded filter from: test/rust/workspace/cortex-mf/osv-scanner.toml
RUSTSEC-2026-0110 has been filtered out because: bare-metal is deprecated/unmaintained upstream with no fixed version; pulled in transitively by cortex-m in this test fixture crate
RUSTSEC-2026-0110 has been filtered out because: bare-metal is deprecated/unmaintained upstream with no fixed version; pulled in transitively by cortex-m in this test fixture crate
Filtered 2 vulnerabilities from output

Total 2 packages affected by 6 known vulnerabilities (0 Critical, 4 High, 2 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6 vulnerabilities can be fixed.

+-------------------------------------+------+-----------+-----------------------+---------+---------------+------------------------------------+
| OSV URL                             | CVSS | ECOSYSTEM | PACKAGE               | VERSION | FIXED VERSION | SOURCE                             |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+------------------------------------+
| https://osv.dev/PYSEC-2026-4175     | 7.6  | PyPI      | urllib3               | 2.7.0   | 2.8.0         | .devcontainer/cpp/requirements.txt |
| https://osv.dev/GHSA-8988-9cw3-xx77 |      |           |                       |         |               |                                    |
| https://osv.dev/PYSEC-2026-4176     | 6.9  | PyPI      | urllib3               | 2.7.0   | 2.8.0         | .devcontainer/cpp/requirements.txt |
| https://osv.dev/GHSA-gh4c-6fx4-qh6g |      |           |                       |         |               |                                    |
| https://osv.dev/PYSEC-2026-4177     | 8.9  | PyPI      | urllib3               | 2.7.0   | 2.8.0         | .devcontainer/cpp/requirements.txt |
| https://osv.dev/GHSA-vxq7-64xx-v4gw |      |           |                       |         |               |                                    |
| https://osv.dev/GHSA-6j4f-fj2g-mc7p | 7.5  | npm       | brace-expansion (dev) | 5.0.9   | 5.0.10        | package-lock.json                  |
| https://osv.dev/GHSA-q2hr-2g5m-vwhr | 5.3  | npm       | brace-expansion (dev) | 5.0.9   | 5.0.12        | package-lock.json                  |
| https://osv.dev/GHSA-qhr7-859c-m2p7 | 7.5  | npm       | brace-expansion (dev) | 5.0.9   | 5.0.11        | package-lock.json                  |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+------------------------------------+
❌ REPOSITORY / trivy - 2 errors
error: Package: urllib3
Installed Version: 2.7.0
Vulnerability CVE-2026-97687
Severity: HIGH
Fixed Version: 2.8.0
Link: [CVE-2026-97687](https://avd.aquasec.com/nvd/cve-2026-97687)
    ┌─ .devcontainer/cpp/requirements.txt:518:1
    │
518 │ urllib3==2.7.0 \
    │ ^
    │
    = urllib3: urllib3: Traffic interception via HTTPS proxy TLS configuration override
    = urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.

error: Package: urllib3
Installed Version: 2.7.0
Vulnerability CVE-2026-97689
Severity: HIGH
Fixed Version: 2.8.0
Link: [CVE-2026-97689](https://avd.aquasec.com/nvd/cve-2026-97689)
    ┌─ .devcontainer/cpp/requirements.txt:518:1
    │
518 │ urllib3==2.7.0 \
    │ ^
    │
    = urllib3: urllib3: Denial of Service via unbounded memory allocation in chunk parser
    = urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.

warning: Package: urllib3
Installed Version: 2.7.0
Vulnerability CVE-2026-97688
Severity: MEDIUM
Fixed Version: 2.8.0
Link: [CVE-2026-97688](https://avd.aquasec.com/nvd/cve-2026-97688)
    ┌─ .devcontainer/cpp/requirements.txt:518:1
    │
518 │ urllib3==2.7.0 \
    │ ^
    │
    = urllib3: urllib3: Denial of Service via infinite loop during chunked Deflate decoding
    = urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.

warning: 1 warnings emitted
error: 2 errors emitted
⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........133
🔗 Unique.........112
✅ Successful.....127
⏳ Timeouts.........0
🔀 Redirected......13
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 30:7) | Rejected status code: 403 Forbidden

Hint: Followed 13 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants