chore(deps): update dependency storybook to v7.6.21 [security] - #123
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency storybook to v7.6.21 [security]#123renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
from
December 31, 2025 17:04
ccc99ab to
c6a1f22
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
from
January 8, 2026 19:16
c6a1f22 to
0bd3485
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
2 times, most recently
from
January 24, 2026 04:11
ea041eb to
32510f0
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
from
February 2, 2026 21:05
32510f0 to
56ed13b
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
2 times, most recently
from
February 17, 2026 21:49
90017c4 to
3bfcdf3
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
from
March 5, 2026 20:15
3bfcdf3 to
7a6110a
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
from
March 13, 2026 10:59
7a6110a to
c809d32
Compare
auto-merge was automatically disabled
March 29, 2026 04:54
Pull request was closed
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
3 times, most recently
from
April 1, 2026 20:41
febff30 to
253e2cb
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
from
April 8, 2026 19:05
253e2cb to
5678081
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
from
April 29, 2026 14:14
5678081 to
99e6122
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
2 times, most recently
from
May 18, 2026 12:40
b60650d to
44ee3de
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
2 times, most recently
from
June 1, 2026 20:56
9f17bc5 to
d5221e3
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
from
June 11, 2026 14:58
d5221e3 to
3ce1262
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
2 times, most recently
from
July 16, 2026 20:56
26e349e to
df5bc4e
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
2 times, most recently
from
July 24, 2026 17:09
46a5bf3 to
1d02dc5
Compare
renovate
Bot
force-pushed
the
renovate/npm-storybook-vulnerability
branch
from
July 30, 2026 20:40
1d02dc5 to
ea0dd18
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
7.6.10→7.6.21Storybook manager bundle may expose environment variables during build
CVE-2025-68429 / GHSA-8452-54wp-rmv6
More information
Details
On December 11th, the Storybook team received a responsible disclosure alerting them to a potential vulnerability in certain built and published Storybooks.
The vulnerability is a bug in how Storybook handles environment variables defined in a
.envfile, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by thestorybook buildcommand. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. If those variables contained secrets, they should be considered compromised.Who is impacted?
For a project to be vulnerable to this issue, it must:
storybook builddirectly or indirectly) in a directory that contains a.envfile (including variants like.env.local).envfile contains sensitive secrets7.0.0or aboveStorybooks built without a
.envfile at build time are not affected, including common CI-based builds where secrets are provided via platform environment variables rather than.envfiles.Users' Storybook runtime environments (i.e.
storybook dev) are not affected. Deployed applications that share a repo with a project's Storybook are not affected.Storybook 6 and below are not affected.
Recommended actions
First, Storybook recommends that everyone audit for any sensitive secrets provided via
.envfiles and rotate those keys.Second, Storybook has released patched versions of all affected major Storybook versions that no longer have this vulnerability. Projects should upgrade their Storybook—on both local machines and CI environments—to one of these versions before publishing again.
10.1.10+9.1.17+8.6.15+7.6.21+Finally, some projects may have been relying on the undocumented behavior at the heart of this issue and will need to change how they reference environment variables after this update. If a project can no longer read necessary environmental variable values, it can either prefix the variables with
STORYBOOK_or use theenvproperty in Storybook’s configuration to manually specify values. In either case, do not include sensitive secrets as they will be included in the built bundle.Further information
Details of the vulnerability can be found on the Storybook announcement.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Storybook manager bundle may expose environment variables during build
CVE-2025-68429 / GHSA-8452-54wp-rmv6
More information
Details
On December 11th, the Storybook team received a responsible disclosure alerting them to a potential vulnerability in certain built and published Storybooks.
The vulnerability is a bug in how Storybook handles environment variables defined in a
.envfile, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by thestorybook buildcommand. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. If those variables contained secrets, they should be considered compromised.Who is impacted?
For a project to be vulnerable to this issue, it must:
storybook builddirectly or indirectly) in a directory that contains a.envfile (including variants like.env.local).envfile contains sensitive secrets7.0.0or aboveStorybooks built without a
.envfile at build time are not affected, including common CI-based builds where secrets are provided via platform environment variables rather than.envfiles.Users' Storybook runtime environments (i.e.
storybook dev) are not affected. Deployed applications that share a repo with a project's Storybook are not affected.Storybook 6 and below are not affected.
Recommended actions
First, Storybook recommends that everyone audit for any sensitive secrets provided via
.envfiles and rotate those keys.Second, Storybook has released patched versions of all affected major Storybook versions that no longer have this vulnerability. Projects should upgrade their Storybook—on both local machines and CI environments—to one of these versions before publishing again.
10.1.10+9.1.17+8.6.15+7.6.21+Finally, some projects may have been relying on the undocumented behavior at the heart of this issue and will need to change how they reference environment variables after this update. If a project can no longer read necessary environmental variable values, it can either prefix the variables with
STORYBOOK_or use theenvproperty in Storybook’s configuration to manually specify values. In either case, do not include sensitive secrets as they will be included in the built bundle.Further information
Details of the vulnerability can be found on the Storybook announcement.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
storybookjs/storybook (storybook)
v7.6.21Compare Source
7.6.21
v7.6.20Compare Source
v7.6.19Compare Source
7.6.19
7.6.18containing wrong dependency identifiers, thanks @jreinhold!v7.6.18Compare Source
7.6.18
v7.6.17Compare Source
v7.6.16Compare Source
v7.6.15Compare Source
This release accidentally didn't contain anything.
v7.6.14Compare Source
trueargs in URL getting ignored - #25950, thanks @JReinhold!v7.6.13Compare Source
v7.6.12Compare Source
upgradedetecting the wrong version of existing Storybooks - #25752, thanks @JReinhold!v7.6.11Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.