Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , nock, node-fetch, promise.allsettled, redis #23

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

p4xx07
Copy link
Owner

@p4xx07 p4xx07 commented Sep 11, 2024

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@eyevinn/hls-truncate
from 0.2.0 to 0.3.0 | 1 version ahead of your current version | a year ago
on 2023-08-08
nock
from 13.3.1 to 13.5.5 | 14 versions ahead of your current version | 22 days ago
on 2024-08-20
node-fetch
from 2.6.9 to 2.7.0 | 5 versions ahead of your current version | a year ago
on 2023-08-23
promise.allsettled
from 1.0.6 to 1.0.7 | 1 version ahead of your current version | a year ago
on 2023-09-03
redis
from 3.1.0 to 3.1.2 | 2 versions ahead of your current version | 3 years ago
on 2021-04-20

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-REDIS-1255645
479 No Known Exploit
Release notes
Package name: @eyevinn/hls-truncate from @eyevinn/hls-truncate GitHub release notes
Package name: nock
  • 13.5.5 - 2024-08-20

    13.5.5 (2024-08-20)

    Bug Fixes

    • backport: memory leaks due to timer references outliving the timers (#2773) (#2773) (66eb7f4)
  • 13.5.4 - 2024-02-26

    13.5.4 (2024-02-26)

    Bug Fixes

  • 13.5.3 - 2024-02-17
  • 13.5.2 - 2024-02-17
  • 13.5.1 - 2024-01-28
  • 13.5.0 - 2024-01-14
  • 13.4.0 - 2023-11-27
  • 13.3.8 - 2023-11-03
  • 13.3.7 - 2023-10-30
  • 13.3.6 - 2023-10-19
  • 13.3.5 - 2023-10-19
  • 13.3.4 - 2023-10-10
  • 13.3.3 - 2023-08-16
  • 13.3.2 - 2023-07-13
  • 13.3.1 - 2023-04-27
from nock GitHub release notes
Package name: node-fetch from node-fetch GitHub release notes
Package name: promise.allsettled from promise.allsettled GitHub release notes
Package name: redis
  • 3.1.2 - 2021-04-20

    Fixes

    Exclude unnecessary files from tarball (#1600)

  • 3.1.1 - 2021-04-13

    Enhancements

    • Upgrade node and dependencies (#1578)

    Fixes

    • Fix a potential exponential regex in monitor mode (#1595)
  • 3.1.0 - 2021-03-31

    Enhancements

    • Upgrade node and dependencies and redis-commands to support Redis 6 (#1578)
    • Add support for Redis 6 auth pass [user] (#1508)
from redis GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade:
  - @eyevinn/hls-truncate from 0.2.0 to 0.3.0.
    See this package in npm: https://www.npmjs.com/package/@eyevinn/hls-truncate
  - nock from 13.3.1 to 13.5.5.
    See this package in npm: https://www.npmjs.com/package/nock
  - node-fetch from 2.6.9 to 2.7.0.
    See this package in npm: https://www.npmjs.com/package/node-fetch
  - promise.allsettled from 1.0.6 to 1.0.7.
    See this package in npm: https://www.npmjs.com/package/promise.allsettled
  - redis from 3.1.0 to 3.1.2.
    See this package in npm: https://www.npmjs.com/package/redis

See this project in Snyk:
https://app.snyk.io/org/paxx-rnd/project/7993dbe6-2724-4eae-9826-96c4852f2538?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

"socket hang up" / ECONNRESET on consecutive requests with Node.js 19 and Node.js 20
2 participants