Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 4 vulnerabilities #47

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

veksen
Copy link
Owner

@veksen veksen commented Dec 20, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-JS-MOMENT-2440688
No No Known Exploit
low severity 506/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
npm:bson:20180225
Yes Proof of Concept
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Prototype Pollution
npm:hoek:20180212
Yes Proof of Concept
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
npm:moment:20170905
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: express-jwt The new version differs by 2 commits.
  • 5766a24 Merge pull request #186 from auth0/jwt_update
  • 11f3ac4 Update jsonwebtoken dependency to 8.1.0

See the full diff

Package name: joi The new version differs by 250 commits.
  • b3833c4 17.1.1
  • ed5990a Fix domain validation in relative uri. Closes #2316
  • 1d1fd3f Merge pull request #2314 from jsoref/api-schema-object-foo-number-min-error
  • c4d072b Update API.md - correct sample - fails because is gone
  • b0ab57c Merge pull request #2305 from cbebry/patch-1
  • d9738fb Update API.md - valid() no longer takes arrays
  • 6ec7131 Merge pull request #2293 from hapijs/consider-changeless-forks
  • e9f1865 Fix error on changeless forks. Fixes #2292.
  • a9b5c3c Merge pull request #2281 from moonthug/patch-1
  • 17118ce Fix example joi extension
  • 48a3006 17.1.0
  • 2417a42 Better annotate handling. isError. Closes #2279. Closes #2280
  • 26206ed Merge pull request #2278 from Bjorn248/master
  • 9768802 fix typo in LICENSE
  • 8d72fac 17.0.2
  • 038854b Consistent keys term. Closes #2269
  • a7102c6 17.0.1
  • 90a2b19 Move flag back to proto. Closes #2268
  • 86636f3 17.0.0
  • 9acff1d Update deps. Closes #2263
  • 3bcab3a Move annotate() our of browser. Closes #2261
  • c75a8f0 Merge branch 'master' of github.com:hapijs/joi
  • 057248b Clarify rename(). For #2216
  • fa9dd37 Merge pull request #2259 from nwhitmont/master

See the full diff

Package name: mongoose The new version differs by 250 commits.
  • 76fae6d chore: release 5.3.9
  • 40d4177 Merge pull request #7213 from NewEraCracker/master
  • 751397c fix(document): run setter only once when doing `.set()` underneath a single nested subdoc
  • 10837d4 test(document): repro #7196
  • 10a63a9 Bump version of bson dependency to match mongodb-core
  • d10274e docs(transactions): add example of aborting a transaction
  • d245847 Merge branch 'master' of github.com:Automattic/mongoose
  • 551a75b chore: add cpc to some pages that were missing it
  • 1ca3514 Merge pull request #7210 from gfranco93/patch-1
  • c1606b6 Merge pull request #7207 from lineus/fix-7098
  • e9d538e Merge pull request #7203 from lineus/fix-7202
  • 8f16b67 fix(document): surface errors in subdoc pre validate
  • 87005a1 test(document): repro #7187
  • 5b1d81c Documentation fix: fixed anchor link
  • eebfb36 docs(query): add note re: cursor()
  • c1e2617 docs(query): improve find() docs re: #7188
  • 526f82d fix(query): run default functions after hydrating the loaded document
  • 320d5f8 test(query): repro #7182
  • 64c6d15 if our update schema path is a nested array do not skip query casting.
  • 5d122e8 test for #7098
  • 5ba13a7 refactor(test): move strictQuery tests to query.test.js since they do not use findOneAndUpdate()
  • 4121629 chore: refer to correct issue #7178
  • 22ed5d2 fix(query): handle strictQuery: 'throw' with nested path correctly
  • 8c16354 test(query): repro #7152

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
馃 View latest project report

馃洜 Adjust project settings

馃摎 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

馃 Regular Expression Denial of Service (ReDoS)
馃 Directory Traversal
馃 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants