Skip to content
This repository has been archived by the owner on May 7, 2024. It is now read-only.

[Snyk] Fix for 4 vulnerabilities #687

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090599
Yes No Known Exploit
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090600
Yes No Known Exploit
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090601
Yes No Known Exploit
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090602
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: sails-mongo The new version differs by 211 commits.
  • 18d0f31 1.0.0
  • 8d7a5a9 Merge pull request Use kong tags to configure tags for service object #465 from lusid/patch-1
  • 18b5494 Adding missing appname to config whitelist
  • a5bddd1 Add mongo back to Travis file
  • 91e3895 1.0.0-11
  • 8c21360 Solve 'TypeError: Cannot read property 'indexOf' of undefined', restoring old error message for when no 'url' is specified (https://snyk.io/redirect/github/balderdashy/sails-mongo/commit/e91c851d48c7a683fbcd507e45bcc6e9a63c21d1#commitcomment-24688823)
  • d5a5fcd Update boilerplate
  • 89109a4 1.0.0-10
  • 81f33c6 Run "unique" feature tests
  • a848a7c Transform MongoError instances into regular errors so that Waterline can understand them.
  • f19c1dc Merge branch 'Josebaseba-master'
  • 5ab4f71 Have `sum` and `avg` return zero if no records match criteria
  • f784149 Merge branch 'master' of https://github.com/Josebaseba/sails-mongo into Josebaseba-master
  • cd5354d Return null if there are no documents to sum
  • 3a0b5e8 Merge branch 'master' of https://github.com/Josebaseba/sails-mongo into Josebaseba-master
  • a3dbb81 Merge pull request Passive health checks got "expected an integer" #463 from balderdashy/fix-for-waterline-1405
  • c0832cb Skip running native `.sort()` if there's nothing to sort.
  • 3464162 Get a grip, eslint.
  • 33443de add note about url escaping
  • b609ecb Return 0 if there are no documents to sum
  • 00ec486 1.0.0-9
  • e91c851 Merge pull request [Snyk] Fix for 1 vulnerabilities #461 from balderdashy/allow-mongo-atlas-urls
  • fb3af37 Add tests for normalizeDatastoreConfig
  • fabcae5 Move check for Atlas URLs into `normalize-datastore-config`

See the full diff

Package name: validator The new version differs by 250 commits.
  • 24b3fd3 13.6.1
  • b986f3d fix: ReDOS in isEmail and isHSL (#1651)
  • 2a3a1c3 13.6.0
  • 1fa0959 chore: add typeof utility (#1648)
  • cf403d0 fix(isMobilePhone): add Sierra Leone phone and fix Sri Lanka phone (#1558)
  • 3f70b8e feat(isPassportNumber, isIBAN, isMobilePhone): add Mozambique locale (#1604)
  • 05ceb18 isURL(): Allow URLs to have only a username in the userinfo subcomponent (#1644)
  • 9ee1b6b fix(isMobilePhone): update china zh-CN locale (#1642)
  • b82f4f2 fix(docs): typo in README.md (#1640)
  • 615547f feat(isMobilePhone): add Latvia lv-LV locale (#1638)
  • d006e08 fix(isMobilePhone): add support for new networks codes in GH (#1635)
  • c33fca6 fix(isISIN): optimization (#1633)
  • 2ef84e4 fix(isIP): validator patterns for IPv4 and IPv6 RegExp formats (#1632)
  • 67a200d feat(isPostalCode): add KR locale (#1628)
  • b65ddc5 fix: fix A-z ranges (#1625)
  • 39830a9 feat: IR passport and identityCard, respect .gitignore files (#1595)
  • 5d6db63 feat(isIPRange): add support for IP version 4 or 6 (#1594)
  • a31c116 fix: update isMobilePhone validation for en-SG (#1573)
  • 63b6162 chore: add gitter chatroom badge (#1592)
  • bb0dba6 feat(isPassportNumber): add MY locale (#1574)
  • 7989e5b feat(isLicensePlate): add support for pt-BR locale (#1588)
  • 3c771e8 feat(pt-BR): tax id, passport and license plates (#1613)
  • 418df05 fix(isMobilePhone): prevent allowing landline numbers in es-CO (#1623)
  • 6262f62 chore: improving code coverage to 100% branches (#1624)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant