[Snyk] Fix for 1 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
:sparkles: Snyk has automatically assigned this pull request, set who gets assigned.
As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 823/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.6 |
Server-side Request Forgery (SSRF) SNYK-JS-IP-6240864 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: mongodb
The new version differs by 67 commits.- e57b738 chore(main): release 6.0.0 [skip-ci] (#3762)
- e70826a docs: generate docs from latest main [skip-ci] (#3744)
- df1b4f2 docs(NODE-5560): add v6 upgrade guide (#3844)
- 7bef363 feat(NODE-5584)!: adopt bson v6 and mongodb-client-encryption v6 (#3845)
- 05d2725 fix(NODE-5592): withTransaction return type (#3846)
- 91152b9 chore(NODE-5581): pull in bson alpha.1 and mongodb-legacy main (#3843)
- ecb2e20 chore: fix alpha version guard
- ea2d60a refactor(NODE-5514): make FLE logic use async-await (#3830)
- a17b0af feat(NODE-5484)!: mark MongoError for internal use and remove Node14 cause assignment logic (#3800)
- 33c86c9 feat(NODE-5566): add ability to provide CRL file via tlsCRLFile (#3834)
- 2323ca8 ci(NODE-5125): fix flaky case 14 prose test (#3833)
- a0955bd fix(NODE-5548): ensure that tlsCertificateKeyFile maps to cert and key (#3819)
- bf00e32 docs(no-story): generate api docs for 5.8 release (#3832)
- 11682d0 docs(NODE-5532): fix docs for `types` and regenerate 5.7 docs (#3822)
- a7ffdf5 ci(NODE-5446): revert bump dev dependencies (#3801) (#3829)
- 46e15e7 docs: fix cutoff sentence on CommandStartedEvent (#3827)
- 1c05b38 docs: generate 4.17.0 documentation (#3826)
- 45f8fb9 chore(NODE-5544): fix duplicate PR highlights (#3816)
- bd031fc feat(NODE-5396): add `mongodb-js/saslprep` as a required dependency (#3815)
- fd9a467 chore(NODE-5446): bump dev dependencies (#3801)
- 6483276 docs(NODE-5540): Fix MDB University links in GH pages (#3814)
- 7955610 fix(NODE-4788)!: use implementer Writable methods for GridFSBucketWriteStream (#3808)
- 2fbb715 docs(NODE-5523): add component support matrix to readme (#3806)
- af47529 docs(NODE-5535): fix link to Transactions quickstart (#3811)
Package name: mongoose
The new version differs by 250 commits.- 5821568 chore: release 8.0.0
- 3f850ce docs: add version support notes for Mongoose 8, including EOL date for Mongoose 6
- db92dd9 Merge pull request #14004 from hasezoey/fixwebsite
- 68166bf chore(scripts/website): fix script to correctly parse "-rc" like versions
- c28cffe chore: release 8.0.0-rc0
- 4280457 Merge pull request #13937 from Automattic/8.0
- 502ec4b Merge pull request #13990 from Automattic/vkarpov15/gh-13897
- 572e018 chore: add 8.0.0-rc0 changelog
- b567ec6 feat: upgrade to MongoDB driver 6.2.0
- 9e9ad37 Merge branch 'master' into 8.0
- d3d2ec4 docs(migrating_to_8): add note about #13897 to migration guide
- 8d61a7d Merge branch '8.0' into vkarpov15/gh-13897
- f923f6c Merge pull request #13989 from Automattic/vkarpov15/gh-13578
- 30888e3 test: fix typescript tests
- ce66e23 fix lint
- 8fe5c36 docs: fix lint
- c7f110e docs(migrating_to_8): add note about `overwrite` to migration guide
- d6cd1db test: fix a couple of failing tests
- 84ac690 Merge branch '8.0' into vkarpov15/gh-13578
- c5b16fe test: add additional assert re: code review comment
- 7efa151 Merge pull request #13992 from suzuki/fix/doc-typescript-query-helper
- b630afb docs(migrating_to_8): add missing issues to migration guide
- eefe935 Merge branch 'master' into 8.0
- eacb5ab fix(document): fix missing import and change wrong variable name
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
👩💻 Set who automatically gets assigned
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: