Nano-SQL icon indicating copy to clipboard operation
Nano-SQL copied to clipboard

[Snyk] Security upgrade better-sqlite3 from 5.4.2 to 7.5.3

Open only-cliches opened this issue 6 months ago • 0 comments

snyk-top-banner

Snyk has created this PR to fix 8 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • packages/Adapter-SQLite3/package.json
  • packages/Adapter-SQLite3/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Arbitrary File Write
SNYK-JS-TAR-1579147
  639  
high severity Arbitrary File Write
SNYK-JS-TAR-1579152
  639  
high severity Arbitrary File Write
SNYK-JS-TAR-1579155
  639  
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536528
  624  
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536531
  624  
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
  601  
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
  506  
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
  410  

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report 📜 Customise PR templates 🛠 Adjust project settings 📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution 🦉 Arbitrary File Overwrite 🦉 Regular Expression Denial of Service (ReDoS)

only-cliches avatar Aug 16 '24 10:08 only-cliches