practica
practica copied to clipboard
[Snyk] Security upgrade sequelize from 6.19.0 to 6.29.0
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- src/code-templates/services/order-service/package.json
- src/code-templates/services/order-service/package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
701/1000 Why? Recently disclosed, Has a fix available, CVSS 8.3 |
Improper Filtering of Special Elements SNYK-JS-SEQUELIZE-3324088 |
No | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: sequelize
The new version differs by 45 commits.- d3f5b5a feat: throw an error if attribute includes parentheses (fixes CVE-2023-22578) (#15710)
- 53bd9b7 meta: fix null test getWhereConditions (#15705)
- 13f2e89 fix: accept undefined in where (#15703)
- d9e0728 fix: throw if where receives an invalid value (#15699)
- 48d6193 fix: update moment-timezone version (#15685)
- fd4afa6 feat(types): use retry-as-promised types for retry options to match documentation (#15484)
- 1247c01 feat: add support for bigints (backport of #14485) (#15413)
- 94beace feat(postgres): add support for lock_timeout [#15345] (#15355)
- 7885000 fix(oracle): remove hardcoded maxRows value (#15323)
- bc39fd6 fix: fix parameters not being replaced when after $$ strings (#15307)
- a205765 fix(postgres): invalidate connection after client-side timeout (#15283)
- 67e69cd fix: remove options.model overwrite on bulkUpdate (#15252)
- 00c6da3 fix(types): add instance.dataValues property to model.d.ts (#15240)
- bf98d7c meta: swap Slack links (#15159)
- 7990095 fix: don't treat \ as escape in standard strings, support E-strings, support vars after ->> operator, treat lowercase e as valid e-string prefix (#15139)
- 851daaf fix(types): fix TS 4.9 excessive depth error on `InferAttributes` (v6) (#15135)
- 9dd93b8 fix(types): expose legacy "types" folder in export alias ( #15123)
- 06ad05d feat(oracle): add support for `dialectOptions.connectString` (#15042)
- a44772e feat(snowflake): Add support for `QueryGenerator#tableExistsQuery` (#15087)
- 55051d0 docs: add missing ssl options for sequelize instance (v6) (#15049)
- 5c88734 docs(model): Added paranoid option for Model.BelongsToMany.through (#15065)
- 7203b66 fix(postgres): add custom order direction to subQuery ordering with minified alias (#15056)
- 5f621d7 fix(oracle): add support for Oracle DB 18c CI (#15016)
- 3468378 feat(types): add typescript 4.8 compatibility (#14990)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.