Skip to content
This repository has been archived by the owner on Jul 22, 2024. It is now read-only.

[Snyk] Security upgrade parse-server from 2.8.1 to 5.0.0 #49

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

madztheo
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 823/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.6
Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: parse-server The new version differs by 250 commits.
  • 46c9a91 chore(release): 5.0.0 [skip ci]
  • 33dcf6d build: release 5.0
  • b2a2a7e Merge branch 'release' into build-release
  • 50072bd ci: add branch name change (#7853)
  • f5ef2e9 chore(release): 5.0.0-beta.9 [skip ci]
  • 23a3488 feat: bump required node engine to >=12.22.10 (#7848)
  • d35cd47 chore(release): 5.0.0-beta.8 [skip ci]
  • 971adb5 fix: security vulnerability that allows remote code execution (GHSA-p6h4-93qp-jhcm) (#7843)
  • a48015c chore(release): 5.0.0-beta.7 [skip ci]
  • 7029b27 fix: security upgrade follow-redirects from 1.14.7 to 1.14.8 (#7802)
  • be37266 chore(release): 5.0.0-beta.6 [skip ci]
  • 4bd34b1 fix: security upgrade follow-redirects from 1.14.2 to 1.14.7 (#7772)
  • f90461e chore(release): 5.0.0-beta.5 [skip ci]
  • 3b92fa1 fix: schema cache not cleared in some cases (#7771)
  • 66347dc chore(release): 5.0.0-beta.4 [skip ci]
  • 8ee0445 fix: unable to use objectId size higher than 19 on GraphQL API (#7722)
  • 2923833 chore(release): 5.0.0-beta.3 [skip ci]
  • 6a54dac fix: node engine range has no upper limit to exclude incompatible node versions (#7693)
  • 32b7194 chore(release): 5.0.0-beta.2 [skip ci]
  • 200d4ba revert: refactor: allow ES import for cloud string if package type is module (#7691)
  • 6962bfa docs: enable npm beta badge on README
  • e91e388 docs: fix changelog which was expectedly incorrect on first beta release
  • 4f11406 chore(release): 5.0.0-beta.1 [skip ci]
  • e94a08f build: release beta

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Server-side Request Forgery (SSRF)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants