javascript-grapqhl-simple icon indicating copy to clipboard operation
javascript-grapqhl-simple copied to clipboard

[Snyk] Upgrade: apollo-server-express, apollo-server

Open jeresoftx opened this issue 9 months ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together. :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
Name Versions Released on
apollo-server-expressfrom 3.12.0 to 3.12.1 1 version ahead of your current version 21 days agoon 2023-08-30
apollo-serverfrom 3.12.0 to 3.12.1 1 version ahead of your current version 21 days agoon 2023-08-30

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Information Exposure
SNYK-JS-APOLLOSERVERCORE-5876618
256/1000
Why? Recently disclosed, CVSS 3.7
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: apollo-server-express from apollo-server-express GitHub release notes
Package name: apollo-server from apollo-server GitHub release notes
Commit messages
Package name: apollo-server-express
  • ea2e2c3 Release
  • 1dd45b8 get CI passing
  • d38b43b Merge pull request from GHSA-j5g3-5c8r-7qfx
  • 590ca13 Update v3 docs with new EOL
  • 71b2c8a Apollo Server 3 docs typo: ctx.connectionParams not just connectionParams (#7503)

Compare

Package name: apollo-server
  • ea2e2c3 Release
  • 1dd45b8 get CI passing
  • d38b43b Merge pull request from GHSA-j5g3-5c8r-7qfx
  • 590ca13 Update v3 docs with new EOL
  • 71b2c8a Apollo Server 3 docs typo: ctx.connectionParams not just connectionParams (#7503)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

jeresoftx avatar Sep 21 '23 02:09 jeresoftx