AntiNuke
AntiNuke copied to clipboard
[Snyk] Upgrade booru from 2.6.3 to 2.6.6
Snyk has created this PR to upgrade booru from 2.6.3 to 2.6.6.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
-
The recommended version is 3 versions ahead of your current version.
-
The recommended version was released on 2 months ago.
Issues fixed by the recommended upgrade:
| Issue | Score | Exploit Maturity | |
|---|---|---|---|
| Regular Expression Denial of Service (ReDoS) SNYK-JS-UNDICI-3323845 |
432 | Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-FASTXMLPARSER-5668858 |
432 | No Known Exploit | |
| Prototype Pollution SNYK-JS-FASTXMLPARSER-3325616 |
432 | Proof of Concept | |
| CRLF Injection SNYK-JS-UNDICI-3323844 |
432 | Proof of Concept | |
| Information Exposure SNYK-JS-UNDICI-5962466 |
432 | No Known Exploit | |
| Permissive Cross-domain Policy with Untrusted Domains SNYK-JS-UNDICI-6252336 |
432 | No Known Exploit | |
| Improper Access Control SNYK-JS-UNDICI-6564963 |
432 | No Known Exploit | |
| Improper Authorization SNYK-JS-UNDICI-6564964 |
432 | No Known Exploit |
Release notes
Package name: booru
- 2.6.6 - 2024-06-12
- 2.6.5 - 2024-03-18
- 2.6.4 - 2023-08-07
- 2.6.3 - 2022-09-11
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- This PR was automatically created by Snyk using the credentials of a real user.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
- Snyk has automatically assigned this pull request, set who gets assigned.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: