advancing-safely-class-nodebr icon indicating copy to clipboard operation
advancing-safely-class-nodebr copied to clipboard

Code produced in a meetup where I taught about security in the development of APIs in Node.js by NodeBR.

Results 34 advancing-safely-class-nodebr issues
Sort by recently updated
recently updated
newest added

This PR was automatically created by Snyk using the credentials of a real user.Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of...

Bumps [minimist](https://github.com/substack/minimist) from 1.2.5 to 1.2.6. Commits 7efb22a 1.2.6 ef88b93 security notice for additional prototype pollution issue c2b9819 isConstructorOrProto adapted from PR bc8ecee test from prototype pollution PR See full...

dependencies

Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project. #### Changes included in this PR - Changes to the following...

Bumps [lodash-es](https://github.com/lodash/lodash) from 4.17.15 to 4.17.21. Commits f299b52 Bump to v4.17.21 c4847eb Improve performance of toNumber, trim and trimEnd on large input strings 3469357 Prevent command injection through _.template's variable...

dependencies

Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project. ![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=yarn&package_name=yup&from_version=0.29.1&to_version=0.30.0&pr_id=857be3e9-09c8-4bc7-8d35-b34c422ceece&visibility=true&has_feature_flag=false) #### Changes included in this PR - Changes to...

Bumps [ajv](https://github.com/ajv-validator/ajv) from 6.12.2 to 6.12.6. Release notes Sourced from ajv's releases. v6.12.6 Fix performance issue of "url" format. v6.12.5 Fix uri scheme validation (@​ChALkeR). Fix boolean schemas with strictKeywords...

dependencies

Bumps [tar](https://github.com/npm/node-tar) from 4.4.13 to 4.4.19. Commits 9a6faa0 4.4.19 70ef812 drop dirCache for symlink on all platforms 3e35515 4.4.18 52b09e3 fix: prevent path escape using drive-relative paths bb93ba2 fix: reserve...

dependencies

Snyk has created this PR to upgrade express-rate-limit from 5.2.3 to 5.3.0. ![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=yarn&package_name=express-rate-limit&from_version=5.2.3&to_version=5.3.0&pr_id=939aaa84-89bb-4dfe-baa4-bc4dab3fb0de&visibility=true&has_feature_flag=false) :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more...

Snyk has created this PR to upgrade dotenv from 8.2.0 to 8.6.0. ![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=yarn&package_name=dotenv&from_version=8.2.0&to_version=8.6.0&pr_id=fb15c3e1-57ec-49be-bc1f-7f2669acdc75&visibility=true&has_feature_flag=false) :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more...

Snyk has created this PR to upgrade knex from 0.21.2 to 0.95.8. ![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=yarn&package_name=knex&from_version=0.21.2&to_version=0.95.8&pr_id=6ab99ed6-683d-4618-851d-04fdc2b231f2&visibility=true&has_feature_flag=false) :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more...