Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade: , nock, node-fetch, promise.allsettled, redis #23

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

p4xx07
Copy link
Owner

@p4xx07 p4xx07 commented Sep 11, 2024

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@eyevinn/hls-truncate
from 0.2.0 to 0.3.0 | 1 version ahead of your current version | a year ago
on 2023-08-08
nock
from 13.3.1 to 13.5.5 | 14 versions ahead of your current version | 22 days ago
on 2024-08-20
node-fetch
from 2.6.9 to 2.7.0 | 5 versions ahead of your current version | a year ago
on 2023-08-23
promise.allsettled
from 1.0.6 to 1.0.7 | 1 version ahead of your current version | a year ago
on 2023-09-03
redis
from 3.1.0 to 3.1.2 | 2 versions ahead of your current version | 3 years ago
on 2021-04-20

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-REDIS-1255645
479 No Known Exploit
Release notes
Package name: @eyevinn/hls-truncate from @eyevinn/hls-truncate GitHub release notes
Package name: nock
  • 13.5.5 - 2024-08-20

    13.5.5 (2024-08-20)

    Bug Fixes

    • backport: memory leaks due to timer references outliving the timers (#2773) (#2773) (66eb7f4)
  • 13.5.4 - 2024-02-26

    13.5.4 (2024-02-26)

    Bug Fixes

  • 13.5.3 - 2024-02-17
  • 13.5.2 - 2024-02-17
  • 13.5.1 - 2024-01-28
  • 13.5.0 - 2024-01-14
  • 13.4.0 - 2023-11-27
  • 13.3.8 - 2023-11-03
  • 13.3.7 - 2023-10-30
  • 13.3.6 - 2023-10-19
  • 13.3.5 - 2023-10-19
  • 13.3.4 - 2023-10-10
  • 13.3.3 - 2023-08-16
  • 13.3.2 - 2023-07-13
  • 13.3.1 - 2023-04-27
from nock GitHub release notes
Package name: node-fetch from node-fetch GitHub release notes
Package name: promise.allsettled from promise.allsettled GitHub release notes
Package name: redis
  • 3.1.2 - 2021-04-20

    Fixes

    Exclude unnecessary files from tarball (#1600)

  • 3.1.1 - 2021-04-13

    Enhancements

    • Upgrade node and dependencies (#1578)

    Fixes

    • Fix a potential exponential regex in monitor mode (#1595)
  • 3.1.0 - 2021-03-31

    Enhancements

    • Upgrade node and dependencies and redis-commands to support Redis 6 (#1578)
    • Add support for Redis 6 auth pass [user] (#1508)
from redis GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade:
  - @eyevinn/hls-truncate from 0.2.0 to 0.3.0.
    See this package in npm: https://www.npmjs.com/package/@eyevinn/hls-truncate
  - nock from 13.3.1 to 13.5.5.
    See this package in npm: https://www.npmjs.com/package/nock
  - node-fetch from 2.6.9 to 2.7.0.
    See this package in npm: https://www.npmjs.com/package/node-fetch
  - promise.allsettled from 1.0.6 to 1.0.7.
    See this package in npm: https://www.npmjs.com/package/promise.allsettled
  - redis from 3.1.0 to 3.1.2.
    See this package in npm: https://www.npmjs.com/package/redis

See this project in Snyk:
https://app.snyk.io/org/paxx-rnd/project/7993dbe6-2724-4eae-9826-96c4852f2538?utm_source=github&utm_medium=referral&page=upgrade-pr
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

"socket hang up" / ECONNRESET on consecutive requests with Node.js 19 and Node.js 20
2 participants