Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies
Renovate vulnerable to Azure DevOps token leakage in logs
Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file
Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance
Child processes spawned by Renovate incorrectly have full access to environment variables
Renovate vulnerable to arbitrary command injection via npm manager and malicious Renovate configuration
Renovate vulnerable to arbitrary command injection via Gradle Wrapper and malicious `distributionUrl`
Renovate vulnerable to arbitrary command injection via helmv3 manager and registryAliases
Renovate vulnerable to leakage of temporary repository tokens into Pull Request comments
Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file
Other Developer Tools projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Renovate — without relying on volunteer maintainers.
Talk to an Expert →