Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , argon2, config, dayjs, dotenv, express-fileupload, express-rate-limit, mongoose, nanoid, nodemailer, pino, zod #509

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

JonasLang-dev
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@typegoose/typegoose
from 9.10.1 to 9.13.2 | 12 versions ahead of your current version | 2 years ago
on 2022-12-01
argon2
from 0.28.7 to 0.41.1 | 16 versions ahead of your current version | 22 days ago
on 2024-08-31
config
from 3.3.7 to 3.3.12 | 5 versions ahead of your current version | 3 months ago
on 2024-06-25
dayjs
from 1.11.4 to 1.11.13 | 9 versions ahead of your current version | a month ago
on 2024-08-20
dotenv
from 16.0.1 to 16.4.5 | 19 versions ahead of your current version | 7 months ago
on 2024-02-20
express-fileupload
from 1.4.0 to 1.5.1 | 5 versions ahead of your current version | 2 months ago
on 2024-07-13
express-rate-limit
from 6.5.1 to 6.11.2 | 12 versions ahead of your current version | a year ago
on 2023-09-12
mongoose
from 6.4.6 to 6.13.0 | 54 versions ahead of your current version | 4 months ago
on 2024-06-06
nanoid
from 3.3.4 to 3.3.7 | 3 versions ahead of your current version | a year ago
on 2023-11-06
nodemailer
from 6.7.7 to 6.9.14 | 17 versions ahead of your current version | 3 months ago
on 2024-06-19
pino
from 8.3.0 to 8.21.0 | 35 versions ahead of your current version | 5 months ago
on 2024-04-24
zod
from 3.17.10 to 3.23.8 | 111 versions ahead of your current version | 4 months ago
on 2024-05-08

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ZOD-5925617
305 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
305 Proof of Concept
high severity Prototype Pollution
SNYK-JS-MONGOOSE-5777721
305 Proof of Concept
high severity Prototype Poisoning
SNYK-JS-QS-3153490
305 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
305 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
305 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
305 Proof of Concept
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
305 No Known Exploit
medium severity Cross-site Scripting
SNYK-JS-EXPRESS-7926867
305 No Known Exploit
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
305 Proof of Concept
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
305 Proof of Concept
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
305 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
305 Proof of Concept
medium severity Information Exposure
SNYK-JS-MONGODB-5871303
305 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NODEMAILER-6219989
305 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
305 Proof of Concept
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
305 No Known Exploit
Release notes
Package name: @typegoose/typegoose from @typegoose/typegoose GitHub release notes
Package name: argon2
  • 0.41.1 - 2024-08-31

    Finally fixed the bug with generated types specifying any instead of Buffer for byte inputs (closes #403)

    We also added provenance to the publishing, so you can track what commit was used to build each published version from now on.

    Full Changelog: v0.41.0...v0.41.1

  • 0.41.0 - 2024-08-25

    What's Changed

    New Contributors

    Full Changelog: v0.40.2...v0.41.0

  • 0.40.3 - 2024-05-25
  • 0.40.2 - 2024-05-25

    Fix issue with publishing tags starting with v

  • 0.40.1 - 2024-02-22
  • 0.40.0-alpha.3 - 2024-01-10
  • 0.40.0-alpha.2 - 2023-12-30
  • 0.40.0-alpha.1 - 2023-12-20
  • 0.31.2 - 2023-11-04

    Note: this is the last version that will support Node 16 since it's support has ended on 2023-09-11. Please upgrade to 18 or preferably 20 as soon as possible.

    What's Changed

    New Contributors

    Full Changelog: v0.31.1...v0.31.2

  • 0.31.1 - 2023-09-01

    Maintenance release intended to fix missing prebuilts due to failure when building v0.31.0

    Note: v0.31.x will be the last version supporting Node v16. Please update to Node v18 or newer.

    Full Changelog: v0.31.0...v0.31.1

  • 0.31.0 - 2023-08-02

    What's Changed

    Please update to v0.31.0 as soon as possible.

    New Contributors

    Full Changelog: v0.30.3...v0.31.0

  • 0.30.3 - 2023-01-05

    What's Changed

    • Change binding resolution to mitigate "Module parse failed" errors by @ Voltra in #366

    New Contributors

    Full Changelog: v0.30.2...v0.30.3

  • 0.30.2 - 2022-11-08

    Fixes #362

  • 0.30.1 - 2022-10-13

    Defaults have been updated to use RFC recommended values, see #360

  • 0.29.1 - 2022-08-23
  • 0.29.0 - 2022-08-22
  • 0.28.7 - 2022-07-03
from argon2 GitHub release notes
Package name: config from config GitHub release notes
Package name: dayjs

Snyk has created this PR to upgrade:
  - @typegoose/typegoose from 9.10.1 to 9.13.2.
    See this package in npm: https://www.npmjs.com/package/@typegoose/typegoose
  - argon2 from 0.28.7 to 0.41.1.
    See this package in npm: https://www.npmjs.com/package/argon2
  - config from 3.3.7 to 3.3.12.
    See this package in npm: https://www.npmjs.com/package/config
  - dayjs from 1.11.4 to 1.11.13.
    See this package in npm: https://www.npmjs.com/package/dayjs
  - dotenv from 16.0.1 to 16.4.5.
    See this package in npm: https://www.npmjs.com/package/dotenv
  - express-fileupload from 1.4.0 to 1.5.1.
    See this package in npm: https://www.npmjs.com/package/express-fileupload
  - express-rate-limit from 6.5.1 to 6.11.2.
    See this package in npm: https://www.npmjs.com/package/express-rate-limit
  - mongoose from 6.4.6 to 6.13.0.
    See this package in npm: https://www.npmjs.com/package/mongoose
  - nanoid from 3.3.4 to 3.3.7.
    See this package in npm: https://www.npmjs.com/package/nanoid
  - nodemailer from 6.7.7 to 6.9.14.
    See this package in npm: https://www.npmjs.com/package/nodemailer
  - pino from 8.3.0 to 8.21.0.
    See this package in npm: https://www.npmjs.com/package/pino
  - zod from 3.17.10 to 3.23.8.
    See this package in npm: https://www.npmjs.com/package/zod

See this project in Snyk:
https://app.snyk.io/org/supercutcat/project/08ca081a-fcbb-4842-9424-5da4c249c304?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment