practica
practica copied to clipboard
[Snyk] Security upgrade sequelize from 6.19.0 to 6.28.1
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- src/code-templates/services/order-service/package.json
- src/code-templates/services/order-service/package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 551/1000 Why? Recently disclosed, Has a fix available, CVSS 5.3 |
Information Exposure SNYK-JS-SEQUELIZE-3324089 |
No | No Known Exploit | |
| 601/1000 Why? Recently disclosed, Has a fix available, CVSS 6.3 |
Access of Resource Using Incompatible Type ('Type Confusion') SNYK-JS-SEQUELIZE-3324090 |
No | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: sequelize
The new version differs by 42 commits.- d9e0728 fix: throw if where receives an invalid value (#15699)
- 48d6193 fix: update moment-timezone version (#15685)
- fd4afa6 feat(types): use retry-as-promised types for retry options to match documentation (#15484)
- 1247c01 feat: add support for bigints (backport of #14485) (#15413)
- 94beace feat(postgres): add support for lock_timeout [#15345] (#15355)
- 7885000 fix(oracle): remove hardcoded maxRows value (#15323)
- bc39fd6 fix: fix parameters not being replaced when after $$ strings (#15307)
- a205765 fix(postgres): invalidate connection after client-side timeout (#15283)
- 67e69cd fix: remove options.model overwrite on bulkUpdate (#15252)
- 00c6da3 fix(types): add instance.dataValues property to model.d.ts (#15240)
- bf98d7c meta: swap Slack links (#15159)
- 7990095 fix: don't treat \ as escape in standard strings, support E-strings, support vars after ->> operator, treat lowercase e as valid e-string prefix (#15139)
- 851daaf fix(types): fix TS 4.9 excessive depth error on `InferAttributes` (v6) (#15135)
- 9dd93b8 fix(types): expose legacy "types" folder in export alias ( #15123)
- 06ad05d feat(oracle): add support for `dialectOptions.connectString` (#15042)
- a44772e feat(snowflake): Add support for `QueryGenerator#tableExistsQuery` (#15087)
- 55051d0 docs: add missing ssl options for sequelize instance (v6) (#15049)
- 5c88734 docs(model): Added paranoid option for Model.BelongsToMany.through (#15065)
- 7203b66 fix(postgres): add custom order direction to subQuery ordering with minified alias (#15056)
- 5f621d7 fix(oracle): add support for Oracle DB 18c CI (#15016)
- 3468378 feat(types): add typescript 4.8 compatibility (#14990)
- 1da6657 fix(types): missing type for oracle dialect in v6 (#14992)
- c230d80 feat(oracle): add oracle dialect support (#14638)
- 33d94b2 fix(types): backport #14704 for v6 (#14964)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.
Codecov Report
Patch and project coverage have no change.
Comparison is base (
e0fbcfe) 90.92% compared to head (0c5ea7f) 90.92%.
Additional details and impacted files
@@ Coverage Diff @@
## main #264 +/- ##
=======================================
Coverage 90.92% 90.92%
=======================================
Files 16 16
Lines 595 595
Branches 43 43
=======================================
Hits 541 541
Misses 53 53
Partials 1 1
| Flag | Coverage Δ | |
|---|---|---|
| app | 91.97% <ø> (ø) |
|
| generator | 63.63% <ø> (ø) |
Flags with carried forward coverage won't be shown. Click here to find out more.
Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.
:umbrella: View full report at Codecov.
:loudspeaker: Do you have feedback about the report comment? Let us know in this issue.