Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYAPPLICATIONMANUAL

Renovatebot

Renovate CLI

Renovate CLI is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

Renovate CLI is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • User-facing application functions
  • Local or managed application deployment
  • Vendor-maintained feature and security updates

Typical use

Used by individuals or organizations for the product-specific tasks described by its publisher.

Deployment

Installed on supported endpoints or supplied through a vendor-managed service, depending on the edition.

Lifecycle records

No verified lifecycle boundary is currently published for this product family.

Official sources

EMPTY

Renovate CLI official lifecycle source

Checked automatically.

The official page was read, but no target-scoped lifecycle boundary was found.

Open publisher source

Package vulnerability advisories

Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file

Fixed: 40.33.0

Renovate vulnerable to arbitrary command injection via npm manager and malicious Renovate configuration

Fixed: 40.33.0

Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository

Fixed: 40.33.0

Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies

Fixed: 40.33.0

Child processes spawned by Renovate incorrectly have full access to environment variables

Fixed: 42.96.3, 43.4.4

Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file

Fixed: 40.33.0

Renovate vulnerable to arbitrary command injection via Gradle Wrapper and malicious `distributionUrl`

Fixed: 42.68.5

Renovate vulnerable to arbitrary command injection via helmv3 manager and registryAliases

Fixed: 37.199.0