Skip to content

Update dependency bcrypt to v5#16

Open
staging-whitesource-for-github-com[bot] wants to merge 1 commit intomasterfrom
whitesource-remediate/bcrypt-5.x
Open

Update dependency bcrypt to v5#16
staging-whitesource-for-github-com[bot] wants to merge 1 commit intomasterfrom
whitesource-remediate/bcrypt-5.x

Conversation

@staging-whitesource-for-github-com
Copy link
Copy Markdown

@staging-whitesource-for-github-com staging-whitesource-for-github-com bot commented Mar 29, 2025

This PR contains the following updates:

Package Type Update Change
bcrypt dependencies major ^1.0.3^5.0.1

By merging this PR, the issue #2 will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability
High High 8.7 CVE-2025-7783
High High 7.5 CVE-2026-26996
Medium Medium 5.9 CVE-2020-7689
Low Low 3.7 CVE-2026-2391

Release Notes

kelektiv/node.bcrypt.js (bcrypt)

v5.0.1

Compare Source

  • Update node-pre-gyp to 1.0.0

v5.0.0

Compare Source

  • Fix the bcrypt "wrap-around" bug. It affects passwords with lengths >= 255.
    It is uncommon but it's a bug nevertheless. Previous attempts to fix the bug
    was unsuccessful.
    • Experimental support for z/OS
    • Fix a bug related to NUL in password input
    • Update node-pre-gyp to 0.15.0

v4.0.1

Compare Source

  • Fix compilation errors in Alpine linux

v4.0.0

Compare Source

  • Switch to NAPI bcrypt
    • Drop support for NodeJS 8

v3.0.8

Compare Source

  • Update node-pre-gyp to 0.14
    • Pre-built binaries for NodeJS 13

v3.0.7

Compare Source

  • Update nan to 2.14.0
    • Update node-pre-gyp to 0.13

v3.0.6

Compare Source

  • Update nan to 2.13.2

v3.0.5

Compare Source

  • Update nan to 2.13.1
    • NodeJS 12 compatibility
    • Remove node-pre-gyp from bundled dependencies

v3.0.4

Compare Source

  • Sync N-API bcrypt with NAN bcrypt

v3.0.3

Compare Source

  • Update nan to 2.12.1

v3.0.2

Compare Source

  • Update nan to 2.11.1

v3.0.1

Compare Source

  • Update nan to 2.11.0

v3.0.0

Compare Source

  • Drop support for NodeJS <= 4

v2.0.1

Compare Source

  • Update node-pre-gyp to allow downloading prebuilt modules

v2.0.0

Compare Source

  • Make 2b the default bcrypt version

  • If you want to rebase/retry this PR, check this box

@staging-whitesource-for-github-com staging-whitesource-for-github-com bot added the security fix Security fix generated by Mend label Mar 29, 2025
@staging-whitesource-for-github-com staging-whitesource-for-github-com bot force-pushed the whitesource-remediate/bcrypt-5.x branch from 59bb518 to 2d40b95 Compare March 4, 2026 12:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants