Ecosyste.ms: Packages

An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

Top 0.8% on npmjs.org
Top 0.4% downloads on npmjs.org
Top 0.3% dependent packages on npmjs.org
Top 1.0% dependent repos on npmjs.org
Top 0.9% forks on npmjs.org
Top 1.0% docker downloads on npmjs.org

npmjs.org : renovate

Automated dependency updates. Flexible so you don't need to be.

Registry - Source - Homepage - JSON
purl: pkg:npm/renovate
Keywords: automated, azure, bazel, bitbucket, buildkite, dependencies, dependency, docker, gitea, github, gitlab, management, meteor, node, npm, outdated, php, pnpm, python, update, yarn, azure-devops, dependencies-checking, dependency-manager, package-management
License: AGPL-3.0-only
Latest release: 3 months ago
First release: about 3 years ago
Dependent packages: 116
Dependent repositories: 308
Downloads: 555,227 last month
Stars: 14,948 on GitHub
Forks: 2,046 on GitHub
Docker dependents: 9
Docker downloads: 823
Total Commits: 15950
Committers: 1005
Average commits per author: 15.871
Development Distribution Score (DDS): 0.685
More commit stats: commits.ecosyste.ms
See more repository details: repos.ecosyste.ms
Last synced: 3 months ago

Moderate
GSA_kwCzR0hTQS1ycWd2LTI5MnYtNXFncs4AA7QK
Renovate vulnerable to arbitrary command injection via helmv3 manager and registryAliases
Ecosystems: npm
Packages: renovate
Source: github
Published: 23 days ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTM2cmgtZ2dwci1qM2dq
Renovate vulnerable to Azure DevOps token leakage in logs
Ecosystems: npm
Packages: renovate
Source: github
Published: over 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXY3eDMtN2h3Ny1wY2pn
Renovate vulnerable to leakage of temporary repository tokens into Pull Request comments
Ecosystems: npm
Packages: renovate
Source: github
Published: over 4 years ago