Skip to content
This repository has been archived by the owner on Feb 15, 2021. It is now read-only.

[Snyk] Security upgrade mongoose from 5.0.1 to 5.2.12 #8

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-MPATH-72672
No No Known Exploit
Commit messages
Package name: mongoose The new version differs by 250 commits.
  • 36850b6 chore: release 5.2.12
  • 29fefa9 Merge branch '4.x'
  • 4545d44 chore: release 4.13.17
  • fb8b644 fix(document): disallow setting constructor and prototype if strict mode false
  • 73399e9 chore: release 5.2.11
  • 346d1f5 chore: add cpc
  • a9962c7 style: fix lint
  • 8565d4d Merge branch '4.x'
  • b33d8c2 style: fix lint
  • efcce8f Merge branch '4.x'
  • df93f5b chore: release 4.13.16
  • a3b98f6 fix(document): disallow setting __proto__ if strict mode false
  • be72ee3 Merge pull request #6945 from Fonger/gh-6938-map-fix
  • 844dd7c Merge pull request #6943 from lineus/fix-6927
  • da856d3 Merge pull request #6942 from julescubtree/master
  • ffe607f test(model): fix flaky test for #6937
  • 1634c5f test(connection): increase delay in connection test
  • 0749d47 fix(map): reduce Map sub docs to make hooks work
  • edac58e test(map): repro #6938
  • ab6fff4 making number.castForQuery return a CastError
  • 643706b update documentation for model.save()
  • c59cecc update documentation for document.save()
  • 62f9d6f Merge pull request #6939 from Fonger/gh-6937
  • 7b92e8d style: fix lint re: #6908

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant