Skip to content

deps: Update dependency matrix-js-sdk to v38 [SECURITY] - #3185

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-matrix-js-sdk-vulnerability
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-matrix-js-sdk-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 29, 2022 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
matrix-js-sdk ^19.5.0 → ^38.0.0 age confidence

Improper beacon events in matrix-js-sdk can result in availability issues

CVE-2022-39236 / GHSA-hvv8-5v86-r45x

More information

Details

Impact

Improperly formed beacon events (from MSC3488) can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer.

Patches

This is patched in matrix-js-sdk v19.7.0

Workarounds

Redacting applicable events, waiting for the sync processor to store data, and restarting the client can often fix it. Alternatively, redacting the applicable events and clearing all storage will fix the further perceived issues.

Downgrading to an unaffected version, noting that such a version may be subject to other vulnerabilities, will additionally resolve the issue.

References

N/A - This was a logic error in the SDK.

For more information

If you have any questions or comments about this advisory please email us at security at matrix.org.

Severity

  • CVSS Score: 4.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


matrix-js-sdk subject to impersonated messages due to permissive key forwarding

CVE-2022-39249 / GHSA-6263-x97c-c4gg

More information

Details

Impact

An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.

This attack is possible due to the matrix-js-sdk implementing a too permissive key forwarding strategy on the receiving end.

Key forwarding is a mechanism allowing clients to recover from “unable to decrypt” messages when they missed the initial key distribution, at the time the message was originally sent. Examples include accessing message history before they joined the room but also when some network/federation errors have occurred.

Patches

The default policy for accepting key forwards has been made more strict in the matrix-js-sdk. matrix-js-sdk will now only accept forwarded keys in response to previously issued requests and only from own, verified devices.

A unique exception to this rule is with the experimental MSC3061, that is forwarding room keys for past messages when invited in a room configured with the proper history visibility setting. Such key forwards are parked upon receipt and are only accepted if the SDK receives an invitation for that room from the inviter in a limited time window.

The SDK now sets a trusted flag on the decrypted message upon decryption, based on whether the key used to decrypt the message was received from a trusted source. Clients need to ensure that messages decrypted with a key with trusted = false are decorated appropriately (for example, by showing a warning for such messages).

Workarounds

As this attack requires coordination between a malicious homeserver and an attacker, if you trust your homeserver, no particular workaround is needed.

References

Blog post: https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clients

For more information

If you have any questions or comments about this advisory, e-mail us at security@matrix.org.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion

CVE-2022-39251 / GHSA-r48r-j8fx-mq2c

More information

Details

Impact

An attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield.

Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver.

These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm.

Patches

matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages.

Out of caution, several other checks have been audited or added:

  • Cleartext m.room_key, m.forwarded_room_key and m.secret.send to_device messages are discarded.
  • Secrets received from untrusted devices are discarded.
  • Key backups are only usable if they have a valid signature from a trusted device (no more local trust, or trust-on-decrypt).
  • The origin of a to-device message should only be determined by observing the Olm session which managed to decrypt the message, and not by using claimed sender_key, user_id, or any other fields controllable by the homeserver.
Workarounds

As this attack requires coordination between a malicious home server and an attacker, if you trust your home server no particular workaround is needed. Notice that the backup spoofing attack is a particularly sophisticated targeted attack.

We are not aware of this attack being used in the wild, though specifying a false positive-free way of noticing malicious key backups key is challenging.

As an abundance of caution, to avoid malicious backup attacks, you should not verify your new logins using emoji/QR verifications methods until patched. Prefer verifying with your security passphrase instead.

References

Blog post: https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clients

For more information

If you have any questions or comments about this advisory, e-mail us at security@matrix.org.

Severity

  • CVSS Score: 8.6 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


matrix-js-sdk subject to user impersonation due to key/device identifier confusion in SAS verification

CVE-2022-39250 / GHSA-5w8r-8pgj-5jmf

More information

Details

Impact

An attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’ identities, leading to the other device trusting/verifying the user identity under the control of the homeserver instead of the intended one.

The vulnerability is a bug in the matrix-js-sdk, caused by checking and signing user identities and devices in two separate steps, and inadequately fixing the keys to be signed between those steps.

Even though the attack is partly made possible due to the design decision of treating cross-signing user identities as Matrix devices on the server side (with their device ID set to the public part of the user identity key), no other examined implementations were vulnerable.

Patches

The matrix-js-sdk has been modified to double check that the key signed is the one that was verified instead of just referencing the key by ID. An additional check has been made to report an error when one of the device ID matches a cross-signing key.

Workarounds

As this attack requires coordination between a malicious homeserver and an attacker -- if you trust your homeserver no particular workaround is needed.

As a potential way of detecting compromise, it’s possible to review your device list or the device list of other users for devices with IDs in the form of a base64 cross-signing key (5XaczGNlfz0bl8R1IX5qn+tBoue2tWJqLMh+SDUuvCk) instead of classical device ID (SEHACYDHMG).

References

Blog post: https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clients

For more information

If you have any questions or comments about this advisory, e-mail us at security@matrix.org

Severity

  • CVSS Score: 8.6 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Prototype pollution in matrix-js-sdk (part 2)

CVE-2023-28427 / GHSA-mwq8-fjpf-c2gr

More information

Details

Impact

In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the Object.prototype, disrupting matrix-js-sdk functionality, causing denial of service and potentially affecting program logic.

(This is part 2, where CVE-2022-36059 / GHSA-rfv9-x7hh-xc32 is part 1. Part 2 covers remaining vectors not covered by part 1, found in a codebase audit scheduled after part 1.)

Patches

The issue has been patched in matrix-js-sdk 24.0.0.

Workarounds

None.

References
  • Release blog post
  • The advisory GHSA-rfv9-x7hh-xc32 (CVE-2022-36059) refers to an initial set of vulnerable locations discovered and patched in matrix-js-sdk 19.4.0. We opted not to disclose that advisory while we performed an audit of the codebase and are now disclosing it jointly with this one.
For more information

If you have any questions or comments about this advisory please email us at security at matrix.org.

Severity

  • CVSS Score: 8.2 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


matrix-js-sdk vulnerable to invisible eavesdropping in group calls

CVE-2023-29529 / GHSA-6g67-q39g-r79q

More information

Details

Impact

An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be participating in the call.

This attack is possible because matrix-js-sdk's group call implementation accepts incoming direct calls from other users, even if they have not yet declared intent to participate in the group call, as a means of resolving a race condition in call setup. Affected versions do not restrict access to the user's outbound media in this case.

Legacy 1:1 calls are unaffected.

Workarounds

Users may hold group calls in private rooms where only the exact users who are expected to participate in the call are present.

Severity

  • CVSS Score: 5.0 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


matrix-js-sdk will freeze when a user sets a room with itself as a its predecessor

CVE-2024-42369 / GHSA-vhr5-g3pm-49fm

More information

Details

Impact

A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but also called by the 'leaveRoomChain()' method, so leaving a room will also trigger the bug.

Even if the CVSS score would be 4.1 (AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:L) we classify this as High severity issue.

Patches

This was patched in matrix-js-sdk 34.3.1.

Workarounds

Sanity check rooms before passing them to the matrix-js-sdk or avoid calling either getRoomUpgradeHistory or leaveRoomChain.

References

N/A.

Severity

  • CVSS Score: 5.1 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Matrix JavaScript SDK's key history sharing could share keys to malicious devices

CVE-2024-47080 / GHSA-4jf8-g8wp-cx7c

More information

Details

Impact

In matrix-js-sdk versions 9.11.0 through 34.7.0, the method MatrixClient.sendSharedHistoryKeys is vulnerable to interception by malicious homeservers. The method implements functionality proposed in MSC3061 and can be used by clients to share historical message keys with newly invited users, granting them access to past messages in the room.

However, it unconditionally sends these "shared" keys to all of the invited user's devices, regardless of whether the user's cryptographic identity is verified or whether the user's devices are signed by that identity. This allows the attacker to potentially inject its own devices to receive sensitive historical keys without proper security checks.

Note that this only affects clients running the SDK with the legacy crypto stack. Clients using the new Rust cryptography stack (i.e. those that call MatrixClient.initRustCrypto() instead of MatrixClient.initCrypto()) are unaffected by this vulnerability, because MatrixClient.sendSharedHistoryKeys() raises an exception in such environments.

Patches

Fixed in matrix-js-sdk 34.8.0 by removing the vulnerable functionality.

Workarounds

Remove use of affected functionality from clients.

References
For more information

If you have any questions or comments about this advisory, please email us at security at matrix.org.

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal

CVE-2024-50336 / GHSA-xvg8-m4x3-w6xr

More information

Details

Summary

matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver.

Details

The Matrix specification demands homeservers to perform validation of the server-name and media-id components of MXC URIs with the intent to prevent path traversal. However, it is not mentioned that a similar check must also be performed on the client to prevent client-side path traversal. matrix-js-sdk fails to perform this validation.

Patches

Fixed in matrix-js-sdk 34.11.1.

Workarounds

None.

References

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


matrix-js-sdk has insufficient validation when considering a room to be upgraded by another

CVE-2025-59160 / GHSA-mp7c-m3rh-r56v

More information

Details

Impact

matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room.

Patches

The issue has been patched and users should upgrade to 38.2.0.

Workarounds

Avoid using MatrixClient::getJoinedRooms in favour of getRooms() and filtering upgraded rooms separately.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

matrix-org/matrix-js-sdk (matrix-js-sdk)

v38.2.0

Compare Source

==================================================================================================
Fix CVE-2025-59160 / GHSA-mp7c-m3rh-r56v

v38.1.0

Compare Source

==================================================================================================

✨ Features

  • Remove custom org.matrix.msc4075.rtc.notification.parent relation type (#​4979). Contributed by @​toger5.
  • MatrixRTC: Add RTC decline event (#​4978). Contributed by @​toger5.
  • Make a MatrixRTCSession emit once the RTCNotification is sent (#​4976). Contributed by @​toger5.
  • Use hydra semantics for unknown room versions (#​4957). Contributed by @​dbkr.
  • Expose the StatusChanged event through the RTCSession (#​4974). Contributed by @​toger5.
  • Add probablyLeft event to the MatrixRTCSession (#​4962). Contributed by @​toger5.

🐛 Bug Fixes

v38.0.0

Compare Source

==================================================================================================

🚨 BREAKING CHANGES

  • Release tranche of breaking changes (#​4975).
  • Remove support for FetchHttpApi onlyData = false
  • Remove deprecated IJoinRoomOpts.syncRoom
  • Remove deprecated methods which are unsupported in rust crypto
  • Remove deprecated getAuthIssuer method
  • Remove deprecated beginKeyVerification method
  • Remove deprecated isEncryptedDisabledForUnverifiedDevices getter
  • Remove deprecated UndecryptableToDeviceEvent MatrixClient emit
  • Remove deprecated defer utility method
  • Remove deprecated UIAResponse dummy type
  • Remove deprecated MatrixRTCSession MembershipConfig fields
  • Remove deprecated findVerificationRequestDMInProgress and storeSessionBackupPrivateKey methods in favour of overloads

✨ Features

  • Allow multiple rtc sessions per room (with different sessionDescriptions) (#​4945). Contributed by @​toger5.
  • Add support for login_hint in authorization url generation (#​4943). Contributed by @​odelcroi.
  • Only process MatrixRTC sessions associated with calls for callMembershipsForRoom (#​4960). Contributed by @​fkwp.

v37.13.0

Compare Source

====================================================================================================
This release supports new v12 Matrix rooms and consequently has a breaking change, removing powerLevelNorm from the RoomMember object as this can't be supported with infinite power levels. Apps should use the non-normalised powerLevel instead.

🚨 BREAKING CHANGES

✨ Features

  • [Backport staging] Support v12 rooms in maySendEvent (#​4956). Contributed by @​RiotRobot.
  • [Backport staging] Support for creator power level (#​4954). Contributed by @​RiotRobot.
  • Experimental support for sharing encrypted history on invite (#​4920). Contributed by @​richvdh.
  • Use the logger associated with MatrixClient in rust sdk (#​4918). Contributed by @​richvdh.
  • Update to matrix-sdk-crypto-wasm 15.1.0, and add new ShieldStateCode.MismatchedSender (#​4916). Contributed by @​richvdh.

🐛 Bug Fixes

  • Fix unknown/broken state in the RTC Membership Manager causing unnecassary error logging. (#​4944). Contributed by @​toger5.

v37.12.0

Compare Source

====================================================================================================

🦖 Deprecations

✨ Features

  • Custom abort timeout logic for restarting delayed events that is compatible with the widget api (#​4927). Contributed by @​toger5.
  • Allow sending notification events when starting a call (#​4826). Contributed by @​robintown.

🐛 Bug Fixes

v37.11.0

Compare Source

====================================================================================================

✨ Features

v37.10.0

Compare Source

====================================================================================================

✨ Features

v37.9.0

Compare Source

==================================================================================================

🐛 Bug Fixes

  • Ensure we send spec-compliant filter strings by stripping out null values (#​4865). Contributed by @​t3chguy.
  • Fix MatrixRTC membership manager failing to rejoin in a race condition (sync vs not found response) (#​4861). Contributed by @​toger5.
  • Include extraParams in all HTTP requests (#​4860). Contributed by @​rsb-tbg.

v37.8.0

Compare Source

==================================================================================================

🐛 Bug Fixes

v37.7.0

Compare Source

==================================================================================================

🦖 Deprecations

✨ Features

  • Allow the embedded client to work without update_state support (#​4849). Contributed by @​robintown.
  • Check for unknown variant on to-device sending and fall back to room event encryption. (#​4847). Contributed by @​toger5.
  • Reapply "Distinguish room state and timeline events in embedded clients" (#​4790). Contributed by @​robintown.

v37.6.0

Compare Source

==================================================================================================

🦖 Deprecations

  • Deprecate utils function defer in favour of Promise.withResolvers (#​4829). Contributed by @​t3chguy.

✨ Features

🐛 Bug Fixes

v37.5.0

Compare Source

==================================================================================================

✨ Features

🐛 Bug Fixes

  • [Backport staging] Fix token refresh behaviour for non-expired tokens (#​4827). Contributed by @​RiotRobot.
  • Refactor how token refreshing works to be more resilient (#​4819). Contributed by @​t3chguy.

v37.4.0

Compare Source

==================================================================================================

✨ Features

🐛 Bug Fixes

v37.3.0

Compare Source

==================================================================================================

✨ Features

  • MatrixRTC MembershipManger: remove redundant sendDelayedEventAction and expose status (#​4747). Contributed by @​toger5.
  • Abstract logout-causing error type from tokenRefreshFunction calls (#​4765). Contributed by @​t3chguy.
  • Improve PushProcessor::getPushRuleGlobRegex (#​4764). Contributed by @​t3chguy.
  • Export push processor & method for converting matrix glob to regexp (#​4763). Contributed by @​t3chguy.
  • Add authenticated media parameter to getMediaConfig (#​4762). Contributed by @​m004.
  • Rust crypto: set a timeout on outgoing HTTP requests (#​4761). Contributed by @​richvdh.
  • Switch sliding sync support to simplified sliding sync (#​4400). Contributed by @​dbkr.

v37.2.0

Compare Source

==================================================================================================

✨ Features

🐛 Bug Fixes

  • Allow port differing in OIDC dynamic registration URIs (#​4749). Contributed by @​t3chguy.
  • OIDC: only pass logo_uri, policy_uri, tos_uri if they conform to "common base" (#​4748). Contributed by @​t3chguy.

v37.1.0

Compare Source

==================================================================================================

🦖 Deprecations

  • MatrixRTC: MembershipManager test cases and deprecation of MatrixRTCSession.room (#​4713). Contributed by @​toger5.

✨ Features

🐛 Bug Fixes

v37.0.0

Compare Source

==================================================================================================

🚨 BREAKING CHANGES

🦖 Deprecations

✨ Features

🐛 Bug Fixes

v36.2.0

Compare Source

==================================================================================================

🦖 Deprecations

  • [Backport staging] Deprecate parameter and functions using legacy crypto in models/event.ts (#​4700). Contributed by @​RiotRobot.

✨ Features

🐛 Bug Fixes

[v36.1.0](https://redirect.github.com/matrix-org/matrix-js-sdk/blob/HEAD/CHANGELOG.md#Chang

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 29, 2022
@renovate renovate Bot changed the title deps: Update dependency matrix-js-sdk to v19.7.0 [SECURITY] deps: Update dependency matrix-js-sdk to v24 [SECURITY] Mar 30, 2023
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from ab1c10c to 6475787 Compare March 30, 2023 20:47
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from 6475787 to 6790ae5 Compare August 21, 2024 23:38
@renovate renovate Bot changed the title deps: Update dependency matrix-js-sdk to v24 [SECURITY] deps: Update dependency matrix-js-sdk to v34 [SECURITY] Aug 21, 2024
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from 6790ae5 to 1b920bf Compare August 10, 2025 13:47
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from 1b920bf to df1dfa8 Compare September 16, 2025 21:28
@renovate renovate Bot changed the title deps: Update dependency matrix-js-sdk to v34 [SECURITY] deps: Update dependency matrix-js-sdk to v38 [SECURITY] Sep 16, 2025
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from df1dfa8 to 2c1c047 Compare September 25, 2025 19:48
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from 2c1c047 to e4484f9 Compare October 16, 2025 00:38
@renovate renovate Bot changed the title deps: Update dependency matrix-js-sdk to v38 [SECURITY] deps: Update dependency matrix-js-sdk to v34 [SECURITY] Oct 16, 2025
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from e4484f9 to 57e8aae Compare November 10, 2025 16:11
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from 57e8aae to 3d6f295 Compare November 18, 2025 22:41
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from 3d6f295 to c58697b Compare January 19, 2026 18:11
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from c58697b to c6bb7ea Compare February 2, 2026 16:51
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from c6bb7ea to afdfd57 Compare March 13, 2026 18:51
@renovate renovate Bot changed the title deps: Update dependency matrix-js-sdk to v34 [SECURITY] deps: Update dependency matrix-js-sdk to v34 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate
renovate Bot deleted the renovate/npm-matrix-js-sdk-vulnerability branch March 27, 2026 01:21
@renovate renovate Bot changed the title deps: Update dependency matrix-js-sdk to v34 [SECURITY] - autoclosed deps: Update dependency matrix-js-sdk to v34 [SECURITY] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from afdfd57 to 1b57452 Compare March 30, 2026 20:37
@renovate renovate Bot changed the title deps: Update dependency matrix-js-sdk to v34 [SECURITY] deps: Update dependency matrix-js-sdk to v34 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title deps: Update dependency matrix-js-sdk to v34 [SECURITY] - autoclosed deps: Update dependency matrix-js-sdk to v34 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch 2 times, most recently from 1b57452 to 27164bf Compare April 27, 2026 23:47
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from 27164bf to 3e7591d Compare May 12, 2026 10:39
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from 3e7591d to e47e862 Compare July 30, 2026 16:32
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from e47e862 to b5c6fe9 Compare August 26, 2026 19:59
@renovate renovate Bot changed the title deps: Update dependency matrix-js-sdk to v34 [SECURITY] deps: Update dependency matrix-js-sdk to v38 [SECURITY] Aug 26, 2026
@renovate
renovate Bot force-pushed the renovate/npm-matrix-js-sdk-vulnerability branch from b5c6fe9 to f1205a9 Compare October 5, 2026 18:48

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants