mongoose-validator icon indicating copy to clipboard operation
mongoose-validator copied to clipboard

Security Update : Bump Validator Version to 13.6.0

Open sanknmFinicity opened this issue 3 years ago • 7 comments

PRISMA Cloud Reported Vulnerability :

PRISMA-2021-0063

sanknmFinicity avatar Nov 23 '21 17:11 sanknmFinicity

Just need a merge on https://github.com/leepowelldev/mongoose-validator/pull/52

Prepaid2Coin-Cory avatar Mar 27 '22 18:03 Prepaid2Coin-Cory

@leepowelldev Could you merge the above Pull Request? If not could you give a maintainer write permissions such as myself.

Prepaid2Coin-Cory avatar Mar 27 '22 18:03 Prepaid2Coin-Cory

Happy to merge, but I wonder if this jump should bump this package to a new major version - as I’m unsure if there’s any breaking changes between 10 and 13. An alternative is to move validator package to a peer dependency?

On 27 Mar 2022, at 19:53, Cory Bethrant @.***> wrote:

 @leepowelldev Could you merge the above Pull Request? If not could you give a maintainer write permissions such as myself.

— Reply to this email directly, view it on GitHub, or unsubscribe. You are receiving this because you were mentioned.

leepowelldev avatar Mar 27 '22 19:03 leepowelldev

@leepowelldev Yes it should be a major version. I updated the Pull Request to make the change from dependencies to peerDependencies.

Prepaid2Coin-Cory avatar Mar 27 '22 21:03 Prepaid2Coin-Cory

Updates in master - will aim to release this evening

leepowelldev avatar Mar 28 '22 13:03 leepowelldev

@leepowelldev Thank you good sir!

Prepaid2Coin-Cory avatar Mar 28 '22 13:03 Prepaid2Coin-Cory

Feel free to close this whenever

Prepaid2Coin-Cory avatar Mar 28 '22 13:03 Prepaid2Coin-Cory