Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade: , node-fetch, , , argon2, big-integer, bootstrap, braintree-web-drop-in, bufferutil, core-js, koa, oidc-client-ts, tldts, utf-8-validate, zone.js #82

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

TheAutisticTechie
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@koa/router
from 12.0.0 to 12.0.1 | 1 version ahead of your current version | a year ago
on 2023-10-12
node-fetch
from 2.6.12 to 2.7.0 | 2 versions ahead of your current version | a year ago
on 2023-08-23
@microsoft/signalr
from 6.0.21 to 6.0.25 | 3 versions ahead of your current version | 10 months ago
on 2023-11-14
@microsoft/signalr-protocol-msgpack
from 6.0.21 to 6.0.25 | 3 versions ahead of your current version | 10 months ago
on 2023-11-14
argon2
from 0.31.0 to 0.40.3 | 8 versions ahead of your current version | 3 months ago
on 2024-05-25
big-integer
from 1.6.51 to 1.6.52 | 1 version ahead of your current version | 10 months ago
on 2023-11-21
bootstrap
from 4.6.0 to 4.6.2 | 2 versions ahead of your current version | 2 years ago
on 2022-07-19
braintree-web-drop-in
from 1.40.0 to 1.43.0 | 5 versions ahead of your current version | 2 months ago
on 2024-07-12
bufferutil
from 4.0.7 to 4.0.8 | 1 version ahead of your current version | a year ago
on 2023-10-15
core-js
from 3.32.0 to 3.38.0 | 14 versions ahead of your current version | a month ago
on 2024-08-04
koa
from 2.14.2 to 2.15.2 | 3 versions ahead of your current version | 6 months ago
on 2024-03-21
oidc-client-ts
from 2.3.0 to 2.4.0 | 1 version ahead of your current version | 10 months ago
on 2023-10-27
tldts
from 6.1.0 to 6.1.39 | 39 versions ahead of your current version | a month ago
on 2024-08-10
utf-8-validate
from 6.0.3 to 6.0.4 | 1 version ahead of your current version | 4 months ago
on 2024-05-10
zone.js
from 0.12.0 to 0.14.10 | 14 versions ahead of your current version | a month ago
on 2024-08-05

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
696 Proof of Concept
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
696 Proof of Concept
Release notes
Package name: @koa/router from @koa/router GitHub release notes
Package name: node-fetch from node-fetch GitHub release notes
Package name: @microsoft/signalr from @microsoft/signalr GitHub release notes
Package name: @microsoft/signalr-protocol-msgpack from @microsoft/signalr-protocol-msgpack GitHub release notes
Package name: argon2
  • 0.40.3 - 2024-05-25
  • 0.40.2 - 2024-05-25

    Fix issue with publishing tags starting with v

  • 0.40.1 - 2024-02-22
  • 0.40.0-alpha.3 - 2024-01-10
  • 0.40.0-alpha.2 - 2023-12-30
  • 0.40.0-alpha.1 - 2023-12-20
  • 0.31.2 - 2023-11-04

    Note: this is the last version that will support Node 16 since it's support has ended on 2023-09-11. Please upgrade to 18 or preferably 20 as soon as possible.

    What's Changed

    New Contributors

    Full Changelog: v0.31.1...v0.31.2

  • 0.31.1 - 2023-09-01

    Maintenance release intended to fix missing prebuilts due to failure when building v0.31.0

    Note: v0.31.x will be the last version supporting Node v16. Please update to Node v18 or newer.

    Full Changelog: v0.31.0...v0.31.1

  • 0.31.0 - 2023-08-02

    What's Changed

    Please update to v0.31.0 as soon as possible.

    New Contributors

    Full Changelog: v0.30.3...v0.31.0

from argon2 GitHub release notes
Package name: big-integer from big-integer GitHub release notes
Package name: bootstrap

Snyk has created this PR to upgrade:
  - @koa/router from 12.0.0 to 12.0.1.
    See this package in npm: https://www.npmjs.com/package/@koa/router
  - node-fetch from 2.6.12 to 2.7.0.
    See this package in npm: https://www.npmjs.com/package/node-fetch
  - @microsoft/signalr from 6.0.21 to 6.0.25.
    See this package in npm: https://www.npmjs.com/package/@microsoft/signalr
  - @microsoft/signalr-protocol-msgpack from 6.0.21 to 6.0.25.
    See this package in npm: https://www.npmjs.com/package/@microsoft/signalr-protocol-msgpack
  - argon2 from 0.31.0 to 0.40.3.
    See this package in npm: https://www.npmjs.com/package/argon2
  - big-integer from 1.6.51 to 1.6.52.
    See this package in npm: https://www.npmjs.com/package/big-integer
  - bootstrap from 4.6.0 to 4.6.2.
    See this package in npm: https://www.npmjs.com/package/bootstrap
  - braintree-web-drop-in from 1.40.0 to 1.43.0.
    See this package in npm: https://www.npmjs.com/package/braintree-web-drop-in
  - bufferutil from 4.0.7 to 4.0.8.
    See this package in npm: https://www.npmjs.com/package/bufferutil
  - core-js from 3.32.0 to 3.38.0.
    See this package in npm: https://www.npmjs.com/package/core-js
  - koa from 2.14.2 to 2.15.2.
    See this package in npm: https://www.npmjs.com/package/koa
  - oidc-client-ts from 2.3.0 to 2.4.0.
    See this package in npm: https://www.npmjs.com/package/oidc-client-ts
  - tldts from 6.1.0 to 6.1.39.
    See this package in npm: https://www.npmjs.com/package/tldts
  - utf-8-validate from 6.0.3 to 6.0.4.
    See this package in npm: https://www.npmjs.com/package/utf-8-validate
  - zone.js from 0.12.0 to 0.14.10.
    See this package in npm: https://www.npmjs.com/package/zone.js

See this project in Snyk:
https://app.snyk.io/org/dltmurphy/project/458c83bb-c79a-4877-9c14-8fd700dc6dbd?utm_source=github&utm_medium=referral&page=upgrade-pr
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

"socket hang up" / ECONNRESET on consecutive requests with Node.js 19 and Node.js 20
2 participants