egg-boilerplate-d-ts icon indicating copy to clipboard operation
egg-boilerplate-d-ts copied to clipboard

[Snyk] Security upgrade egg from 2.37.0 to 3.2.0

Open whxaxes opened this issue 1 year ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 761/1000
Why? Mature exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JS-DICER-2311764
Yes Mature

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: egg The new version differs by 8 commits.
  • 6a24fd8 Release 3.2.0
  • 733d669 feat: update egg-multipart 2.x -> 3.x (#5023)
  • 4857813 docs: update the version of the required Node (#5021)
  • bbd0e43 chore: change the templates of bug/suggestion report (#5019)
  • 64dd9fe Release 3.1.0 (#5003)
  • 2c5ba48 🐛 FIX: Add config.httpclient.useHttpClientNext defined (#5001)
  • 2ffb37a feat: Support urllib@3 (#5000)
  • ff1850f Release 3.0.0 (#4999)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Denial of Service (DoS)

whxaxes avatar Nov 27 '23 14:11 whxaxes