Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade qs from 6.3.1 to 6.12.1 #1

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

hunorszegediblack
Copy link

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to upgrade qs from 6.3.1 to 6.12.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 37 versions ahead of your current version.

  • The recommended version was released on 3 months ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Override Protection Bypass
npm:qs:20170213
152 No Known Exploit
high severity Prototype Poisoning
SNYK-JS-QS-3153490
152 Proof of Concept
Release notes
Package name: qs
  • 6.12.1 - 2024-04-12

    v6.12.1

  • 6.12.0 - 2024-03-06

    v6.12.0

  • 6.11.2 - 2023-05-15

    v6.11.2

  • 6.11.1 - 2023-03-06

    v6.11.1

  • 6.11.0 - 2022-06-27

    v6.11.0

  • 6.10.5 - 2022-06-06

    v6.10.5

  • 6.10.4 - 2022-06-06

    v6.10.4

  • 6.10.3 - 2022-01-11
    • [Fix] parse: ignore __proto__ keys (#428)
    • [Robustness] stringify: avoid relying on a global undefined (#427)
    • [actions] reuse common workflows
    • [Dev Deps] update eslint, @ ljharb/eslint-config, object-inspect, tape
  • 6.10.2 - 2021-12-06
  • 6.10.1 - 2021-03-22
  • 6.10.0 - 2021-03-18
  • 6.9.7 - 2022-01-11
  • 6.9.6 - 2021-01-14
  • 6.9.5 - 2021-01-13
  • 6.9.4 - 2020-05-03
  • 6.9.3 - 2020-03-25
  • 6.9.2 - 2020-03-22
  • 6.9.1 - 2019-11-08
  • 6.9.0 - 2019-09-21
  • 6.8.3 - 2022-01-11
    • [Fix] parse: ignore __proto__ keys (#428)
    • [Robustness] stringify: avoid relying on a global undefined (#427)
    • [Fix] stringify: avoid encoding arrayformat comma when encodeValuesOnly = true (#424)
    • [readme] remove travis badge; add github actions/codecov badges; update URLs
    • [Tests] clean up stringify tests slightly
    • [Docs] add note and links for coercing primitive values (#408)
    • [meta] fix README.md (#399)
    • [actions] backport actions from main
    • [Dev Deps] backport updates from main
    • [Refactor] stringify: reduce branching
    • [meta] do not publish workflow files
  • 6.8.2 - 2020-03-25
  • 6.8.1 - 2020-03-24
  • 6.8.0 - 2019-08-17
  • 6.7.3 - 2022-01-11
  • 6.7.2 - 2020-03-25
  • 6.7.1 - 2020-03-24
  • 6.7.0 - 2019-03-22
  • 6.6.1 - 2022-01-11
  • 6.6.0 - 2018-11-25
  • 6.5.3 - 2022-01-11
  • 6.5.2 - 2018-05-04
  • 6.5.1 - 2017-09-09
  • 6.5.0 - 2017-06-28
  • 6.4.1 - 2022-01-11
  • 6.4.0 - 2017-03-06
  • 6.3.3 - 2022-01-11
  • 6.3.2 - 2017-03-06
  • 6.3.1 - 2017-02-16
from qs GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants