Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade express-fileupload from 0.0.5 to 1.1.8 #4

Closed
wants to merge 1 commit into from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-EXPRESSFILEUPLOAD-595969
Yes Proof of Concept
Commit messages
Package name: express-fileupload The new version differs by 250 commits.
  • 829f395 version bump
  • db49535 Merge pull request #237 from richardgirges/fix-236-proto-pollution
  • d81bee9 Upgrade latest packages; run npm audit fix; add logic to prevent prototype pollution in parseNested
  • e9848fc Update package-lock.json
  • d536cfb Update package.json
  • c7a6b9c Merge pull request #233 from RomanBurunkov/master
  • a53b93f Update tests to support empty files
  • d8c00c5 Add empty files support for tempFileHandler
  • b24233d Comment extra condition in fileFactory(issue [Snyk-onprem] Fix for 4 vulnerabilities #1), add more logging
  • d57ee02 Formatting utilities
  • b6097df Merge pull request #232 from RomanBurunkov/master
  • 05004b7 Merge pull request #230 from Code42Cate/readme-timeout
  • 1afa527 Update dependencies
  • 880c2b7 Improve timeout option documentation
  • 3f130b0 Add timeout option to README.MD
  • d55fa83 Merge pull request #222 from wbt/patch-1
  • d61f02f Fix some small typos
  • f20389a Merge pull request #219 from wbt/patch-1
  • b95d3c7 Small typo fix usefull => useful
  • 0f1ff52 Merge pull request #214 from RomanBurunkov/master
  • 2257106 Update package.json
  • 62e3419 Merge pull request #213 from RomanBurunkov/master
  • 055ceac Destroy file stream in case of upload timeout.
  • 5fb6150 Add debug loggin for temp file cleaning up insted throwing error

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@FauxFaux FauxFaux closed this Oct 4, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants