Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk-dev] Fix for 3 vulnerabilities #779

Closed
wants to merge 1 commit into from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
No No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:ms:20170412
Yes No Known Exploit
high severity Prototype Override Protection Bypass
npm:qs:20170213
No No Known Exploit
Commit messages
Package name: body-parser The new version differs by 221 commits.

See the full diff

Package name: express The new version differs by 250 commits.

See the full diff

Package name: mongoose The new version differs by 250 commits.
  • c86ef79 chore: release 4.11.14
  • 0165e5f chore: bump lockfile and add back nsp re: #5658
  • 07e62be fix(populate): automatically select() populated()-ed fields
  • cc6e489 test(populate): repro #5669
  • 4be7d79 chore: remove nsp for now
  • 5ab6726 chore: run nsp after test
  • 2b4435d Merge pull request #5679 from hairyhenderson/add-nsp-check-in-ci
  • bf6ef00 Merge pull request #5675 from jonathanprl/patch-1
  • 5332ab6 chore: use ~
  • 48ca046 Adding nsp check to the CI build
  • f9e0525 fix(connection): make force close work as expected
  • 0e5fc39 test(connection): repro #5664
  • e8f0055 Update mquery dependency
  • 4875dbe fix(model): make `init()` public and return a promise that resolves when indexes are done building
  • 3f17393 fix(document): treat $elemMatch as inclusive projection
  • a7a5621 test(document): repro #5661
  • c79d48e docs(model/query): clarify which functions fire which middleware
  • 635f07f chore: now working on 4.11.14
  • cc32e59 Merge branch 'master' of github.com:Automattic/mongoose
  • 96e06b7 chore: release 4.11.13
  • cc52ec0 Merge pull request #5665 from sime1/master
  • ab9ba7c test: add coverage for #5656
  • 52ed14f Merge pull request #5656 from zipp3r/master
  • a872591 fix(query): avoid throwing cast error for strict: throw with nested id in query

See the full diff

Package name: ms The new version differs by 19 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@FauxFaux FauxFaux closed this Aug 18, 2020
@SonyaMoisset SonyaMoisset deleted the snyk-fix-d9b844a2e3584a442d8b66df435dfa81 branch July 11, 2022 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants