sendgrid-nodejs icon indicating copy to clipboard operation
sendgrid-nodejs copied to clipboard

Deps update - snyk risks

Open EctorCunha opened this issue 1 year ago • 4 comments

Updating dependencies due to security risks.

Updated dependencies:

  • Packages
  • /client
  • /contact-importer
  • /inbound-mail-parser
  • /subscription-widget

Updates:

  • /client:
  • "axios": "^1.6.0"
  • /contact-importer:
  • "axios": "^1.6.0",
  • inbound-mail-parser:
    • "html-to-text": "^6.0.0",
    • "mailparser": "^3.6.5",
    • "nodemailer": "^6.6.1"
  • subscription-widget:
  • "mailparser": "^3.3.0",
  • "nodemon": "^3.0.1",

Note1: It was not possible to update /mail ("@sendgrid/client": "^7.7.0"). Note2: The branch name is specific because the initial intention was to solve just one problem. Note3: Doesn't exist the Development branch.

====================================================================================

Fixes

A short description of what this PR does.

Checklist

  • [x] I acknowledge that all my contributions will be made under the project's license
  • [ ] I have made a material change to the repo (functionality, testing, spelling, grammar)
  • [x] I have read the Contribution Guidelines and my PR follows them
  • [x] I have titled the PR appropriately
  • [x] I have updated my branch with the main branch
  • [ ] I have added tests that prove my fix is effective or that my feature works
  • [ ] I have added the necessary documentation about the functionality in the appropriate .md file
  • [ ] I have added inline documentation to the code I modified

If you have questions, please file a support ticket.

EctorCunha avatar Nov 09 '23 18:11 EctorCunha

Hi Ector! Wondering when this PR will be merged? The sendgrid vulnerability is blocking some changes I am trying to make.

jared-tewodros avatar Nov 15 '23 21:11 jared-tewodros

Hi! We are working on these changes. The PR will be merged soon. Thanks!

tiwarishubham635 avatar Nov 17 '23 11:11 tiwarishubham635

This PR encompasses changes included in and would close #1387

saghaulor avatar Nov 21 '23 17:11 saghaulor

Hi @EctorCunha! The changes required here are included as a part of #1390 and it will be merged soon.

tiwarishubham635 avatar Nov 22 '23 17:11 tiwarishubham635