Skip to content

build(deps): bump nodemailer from 8.0.4 to 8.0.5#3076

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/nodemailer-8.0.5
Open

build(deps): bump nodemailer from 8.0.4 to 8.0.5#3076
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/nodemailer-8.0.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 8, 2026

Bumps nodemailer from 8.0.4 to 8.0.5.

Release notes

Sourced from nodemailer's releases.

v8.0.5

8.0.5 (2026-04-07)

Bug Fixes

  • decode SMTP server responses as UTF-8 at line boundary (95876b1)
  • sanitize CRLF in transport name option to prevent SMTP command injection (GHSA-vvjj-xcjg-gr5g) (0a43876)
Changelog

Sourced from nodemailer's changelog.

8.0.5 (2026-04-07)

Bug Fixes

  • decode SMTP server responses as UTF-8 at line boundary (95876b1)
  • sanitize CRLF in transport name option to prevent SMTP command injection (GHSA-vvjj-xcjg-gr5g) (0a43876)
Commits
  • 202cfb3 chore(master): release 8.0.5 (#1809)
  • b634abf docs: add CLAUDE.md with project conventions and release process
  • 95876b1 fix: decode SMTP server responses as UTF-8 at line boundary
  • 0a43876 fix: sanitize CRLF in transport name option to prevent SMTP command injection...
  • 08e59e6 chore: update dev dependencies
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 8, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented Apr 8, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
agents-api Ready Ready Preview, Comment Apr 15, 2026 3:40pm
agents-docs Ready Ready Preview, Comment Apr 15, 2026 3:40pm
agents-manage-ui Ready Ready Preview, Comment Apr 15, 2026 3:40pm

Request Review

@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented Apr 8, 2026

⚠️ No Changeset found

Latest commit: a651472

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 8, 2026

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from b0ced4a to 303e12d Compare April 8, 2026 20:32
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from 303e12d to ee35eea Compare April 9, 2026 02:37
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from ee35eea to 988265c Compare April 9, 2026 19:49
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from 988265c to 0d1812e Compare April 10, 2026 15:01
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from 0d1812e to f1a319e Compare April 10, 2026 21:40
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 14, 2026

A matching internal PR is ready in inkeep/agents-private#96 for canonical review and merge.

  • Original author attribution is preserved as @dependabot[bot]
  • The internal PR is the authoritative merge surface
  • The public repo will pick up the merged change through the normal mirror sync

This comment will be updated as the bridge state changes.

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from f1a319e to 2073ec5 Compare April 14, 2026 18:15
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from 2073ec5 to 206c58c Compare April 15, 2026 00:54
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from 206c58c to 8e24017 Compare April 15, 2026 13:29
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from 8e24017 to 7bc0b98 Compare April 15, 2026 15:36
@dependabot dependabot Bot changed the title chore(deps): bump nodemailer from 8.0.4 to 8.0.5 build(deps): bump nodemailer from 8.0.4 to 8.0.5 Apr 16, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch 6 times, most recently from d2767b3 to 64ffb6d Compare April 22, 2026 23:16
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 22, 2026

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from 64ffb6d to dee8d44 Compare April 23, 2026 00:44
Bumps [nodemailer](https://github.com/nodemailer/nodemailer) from 8.0.4 to 8.0.5.
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v8.0.4...v8.0.5)

---
updated-dependencies:
- dependency-name: nodemailer
  dependency-version: 8.0.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/nodemailer-8.0.5 branch from dee8d44 to a651472 Compare April 25, 2026 02:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants