typescript-api
typescript-api copied to clipboard
[Snyk] Security upgrade bcrypt from 1.0.3 to 2.0.0
trafficstars
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 711/1000 Why? Recently disclosed, Has a fix available, CVSS 8.5 |
Arbitrary File Write SNYK-JS-TAR-1579147 |
Yes | No Known Exploit | |
| 711/1000 Why? Recently disclosed, Has a fix available, CVSS 8.5 |
Arbitrary File Write SNYK-JS-TAR-1579152 |
Yes | No Known Exploit | |
| 711/1000 Why? Recently disclosed, Has a fix available, CVSS 8.5 |
Arbitrary File Write SNYK-JS-TAR-1579155 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: bcrypt
The new version differs by 26 commits.- ab026b2 v2.0.0
- f00d4b8 Merge pull request #589 from agathver/libc-aware
- dab435e install and use any-promise (#504)
- 9a9ab45 Make binaries libc aware
- aac593c Merge pull request #587 from agathver/hash-version-support
- 2d45be1 Allow to choose bcrypt minor version
- 0ea1b36 Merge pull request #549 from agathver/2b-hashes
- 4c44f20 Add support for $2b$ hashes
- e8cde51 Merge pull request #583 from ofrobots/async-resource
- 6a79eaf fix: propagate async context
- 88590ea Merge pull request #584 from kelektiv/snyk-fix-bc668290
- 1da0f44 fix: package.json to reduce vulnerabilities
- 43734e3 Merge pull request #564 from david-a-wheeler/readme-timing
- f2bec20 README: comparisons resist timing attacks
- 096a34f Merge pull request #554 from agathver/node-9
- d1cb91d Bump deps
- 7b928fb Add NodeJS 9 to CI matrix
- 90d438b Merge pull request #550 from agathver/drop-old-node
- 9540ed0 Remove support for NodeJS < 4
- 99e2a09 Merge pull request #539 from tonylukasavage/issue-538
- 7914916 Merge pull request #545 from agathver/test-improvements
- f3a34bd Add additional testcases for testing bcrypt implementation
- ebb7417 preserve stack traces on async error callbacks
- 6746a04 Use strict equality comparison in tests
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report