Mongoose-TypeScript-example
Mongoose-TypeScript-example copied to clipboard
[Snyk] Security upgrade mongoose from 5.9.29 to 5.12.2
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
673/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.6 |
Prototype Pollution SNYK-JS-MONGOOSE-1086688 |
No | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: mongoose
The new version differs by 250 commits.- 5549f26 chore: release 5.12.2
- 4b1aaac Merge pull request #10050 from SoftwareSing/fix-bulkwrite-with-timestamps-false
- 3759f34 chore: address CR comments
- 5ffbb8e fix(query): apply schema-level `select` option from array schematypes
- 7d19c9f test(query): repro #10029
- 4b0052e fix(schema): support setting `ref` as an option on an array SchemaType
- 171c31f test(schema): repro #10029
- 96f7905 fix(index.d.ts): make query methods return `QueryWithHelpers` so query helpers pass through chaining
- 04f880f fix(index.d.ts): add back `Aggregate#project()` types that were mistakenly removed in 5.12.0
- 9a3a7b4 style: fix lint
- 91f003a Merge pull request #10053 from 418sec/1-npm-mongoose
- 3ed44ff Merge pull request #1 from zpbrent/patch-2
- 00e059d fix(index.d.ts): add `upserted` array to `updateOne()`, `updateMany()`, `update()` result
- 003e477 add missing issue number
- 0101ab8 fix(bulkwrite): make bulkWrite can work with `timestamps: false`
- 9559c46 test(bulkwrite): repro #10048
- 1bb97ba chore: update opencollective sponsors
- 5888269 docs(mongoose+browser): fix broken links to info about `mongoose.Types`
- 43b0cfa Merge branch 'master' of github.com:Automattic/mongoose
- 03905c5 fix(index.d.ts): always allow setting `type` in Schema to a SchemaType class or a Schema instance
- 422620b Merge pull request #10015 from Automattic/gh-9982
- 7b14258 test(QueryCursor): fix tests from #10015
- f2651d7 docs(transactions): introduce `session.withTransaction()` before `session.startTransaction()` because `withTransaction()` is the recommended approach
- 61d313b chore: update opencollective sponsor logo
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report