Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: bcrypt, cloudinary, dotenv, express, moment, mongoose, nodemon, socket.io, socket.io-client, stripe, validator #1

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

KOTTAGENVH
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

bcrypt
from 5.0.1 to 5.1.1 | 2 versions ahead of your current version | a year ago
on 2023-08-16
cloudinary
from 1.31.0 to 1.41.3 | 20 versions ahead of your current version | 8 months ago
on 2024-01-18
dotenv
from 16.0.2 to 16.4.5 | 18 versions ahead of your current version | 7 months ago
on 2024-02-20
express
from 4.18.1 to 4.19.2 | 5 versions ahead of your current version | 6 months ago
on 2024-03-25
moment
from 2.29.4 to 2.30.1 | 2 versions ahead of your current version | 9 months ago
on 2023-12-27
mongoose
from 6.5.4 to 6.13.0 | 48 versions ahead of your current version | 3 months ago
on 2024-06-06
nodemon
from 2.0.19 to 2.0.22 | 3 versions ahead of your current version | a year ago
on 2023-03-22
socket.io
from 4.5.1 to 4.7.5 | 13 versions ahead of your current version | 6 months ago
on 2024-03-14
socket.io-client
from 4.5.3 to 4.7.5 | 12 versions ahead of your current version | 6 months ago
on 2024-03-14
stripe
from 10.7.0 to 10.17.0 | 14 versions ahead of your current version | 2 years ago
on 2022-11-08
validator
from 13.7.0 to 13.12.0 | 3 versions ahead of your current version | 4 months ago
on 2024-05-09

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-MONGOOSE-5777721
646 Proof of Concept
high severity Uncaught Exception
SNYK-JS-SOCKETIO-7278048
646 No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-SOCKETIOPARSER-5596892
646 No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
646 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-ENGINEIO-3136336
646 No Known Exploit
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
646 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
646 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-SOCKETIOPARSER-5596892
646 No Known Exploit
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
646 Proof of Concept
medium severity Information Exposure
SNYK-JS-MONGODB-5871303
646 No Known Exploit
critical severity Remote Code Execution (RCE)
SNYK-JS-VM2-5772825
646 Mature
high severity Uncaught Exception
SNYK-JS-ENGINEIO-5496331
646 No Known Exploit
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
646 No Known Exploit
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
646 Proof of Concept
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
646 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
646 Proof of Concept
critical severity Sandbox Escape
SNYK-JS-VM2-5415299
646 Proof of Concept
critical severity Sandbox Escape
SNYK-JS-VM2-5422057
646 Proof of Concept
critical severity Improper Handling of Exceptional Conditions
SNYK-JS-VM2-5426093
646 No Known Exploit
medium severity Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
SNYK-JS-VM2-5537079
646 Proof of Concept
critical severity Sandbox Bypass
SNYK-JS-VM2-5537100
646 Proof of Concept
critical severity Remote Code Execution (RCE)
SNYK-JS-VM2-5772823
646 Proof of Concept
Release notes
Package name: bcrypt from bcrypt GitHub release notes
Package name: cloudinary
  • 1.41.3 - 2024-01-18
  • 1.41.2 - 2024-01-08
  • 1.41.1 - 2023-12-18
  • 1.41.0 - 2023-09-26
  • 1.40.0 - 2023-07-31
  • 1.39.0 - 2023-07-24
  • 1.38.0 - 2023-07-20
  • 1.37.3 - 2023-06-26
  • 1.37.2 - 2023-06-19
  • 1.37.1 - 2023-06-09
  • 1.37.0 - 2023-05-16
  • 1.36.4 - 2023-05-02
  • 1.36.3 - 2023-05-02
  • 1.36.2 - 2023-04-24
  • 1.36.1 - 2023-04-13
  • 1.36.0 - 2023-04-13
  • 1.35.0 - 2023-03-03
  • 1.34.0 - 2023-02-13
  • 1.33.0 - 2022-12-15
  • 1.32.0 - 2022-09-14
  • 1.31.0 - 2022-08-28
from cloudinary GitHub release notes
Package name: dotenv from dotenv GitHub release notes
Package name: express from express GitHub release notes
Package name: moment from moment GitHub release notes
Package name: mongoose
  • 6.13.0 - 2024-06-06
  • 6.12.9 - 2024-05-24
  • 6.12.8 - 2024-04-10
  • 6.12.7 - 2024-03-01
  • 6.12.6 - 2024-01-22
  • 6.12.5 - 2024-01-03
  • 6.12.4 - 2023-12-27
  • 6.12.3 - 2023-11-07
  • 6.12.2 - 2023-10-25
  • 6.12.1 - 2023-10-12
  • 6.12.0 - 2023-08-24
  • 6.11.6 - 2023-08-21
  • 6.11.5 - 2023-08-01
  • 6.11.4 - 2023-07-17
  • 6.11.3 - 2023-07-11
  • 6.11.2 - 2023-06-08
  • 6.11.1 - 2023-05-08
  • 6.11.0 - 2023-05-01
  • 6.10.5 - 2023-04-06
  • 6.10.4 - 2023-03-21
  • 6.10.3 - 2023-03-13
  • 6.10.2 - 2023-03-07
  • 6.10.1 - 2023-03-03
  • 6.10.0 - 2023-02-22
  • 6.9.3 - 2023-02-22
  • 6.9.2 - 2023-02-16
  • 6.9.1 - 2023-02-06
  • 6.9.0 - 2023-01-25
  • 6.8.4 - 2023-01-17
  • 6.8.3 - 2023-01-06
  • 6.8.2 - 2022-12-28
  • 6.8.1 - 2022-12-19
  • 6.8.0 - 2022-12-05
  • 6.7.5 - 2022-11-30
  • 6.7.4 - 2022-11-28
  • 6.7.3 - 2022-11-22
  • 6.7.2 - 2022-11-07
  • 6.7.1 - 2022-11-02
  • 6.7.0 - 2022-10-24
  • 6.6.7 - 2022-10-21
  • 6.6.6 - 2022-10-20
  • 6.6.5 - 2022-10-05
  • 6.6.4 - 2022-10-03
  • 6.6.3 - 2022-09-30
  • 6.6.2 - 2022-09-26
  • 6.6.1 - 2022-09-14
  • 6.6.0 - 2022-09-08
  • 6.5.5 - 2022-09-07
  • 6.5.4 - 2022-08-30
from mongoose GitHub release notes
Package name: nodemon from nodemon GitHub release notes
Package name: socket.io

Snyk has created this PR to upgrade:
  - bcrypt from 5.0.1 to 5.1.1.
    See this package in npm: https://www.npmjs.com/package/bcrypt
  - cloudinary from 1.31.0 to 1.41.3.
    See this package in npm: https://www.npmjs.com/package/cloudinary
  - dotenv from 16.0.2 to 16.4.5.
    See this package in npm: https://www.npmjs.com/package/dotenv
  - express from 4.18.1 to 4.19.2.
    See this package in npm: https://www.npmjs.com/package/express
  - moment from 2.29.4 to 2.30.1.
    See this package in npm: https://www.npmjs.com/package/moment
  - mongoose from 6.5.4 to 6.13.0.
    See this package in npm: https://www.npmjs.com/package/mongoose
  - nodemon from 2.0.19 to 2.0.22.
    See this package in npm: https://www.npmjs.com/package/nodemon
  - socket.io from 4.5.1 to 4.7.5.
    See this package in npm: https://www.npmjs.com/package/socket.io
  - socket.io-client from 4.5.3 to 4.7.5.
    See this package in npm: https://www.npmjs.com/package/socket.io-client
  - stripe from 10.7.0 to 10.17.0.
    See this package in npm: https://www.npmjs.com/package/stripe
  - validator from 13.7.0 to 13.12.0.
    See this package in npm: https://www.npmjs.com/package/validator

See this project in Snyk:
https://app.snyk.io/org/kottagenvh/project/1f6e4185-c6f7-40c8-9c37-6f6ec2310bdc?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

netlify bot commented Sep 15, 2024

Deploy Preview for polite-dragon-8754d9 failed.

Name Link
🔨 Latest commit d078b09
🔍 Latest deploy log https://app.netlify.com/sites/polite-dragon-8754d9/deploys/66e6b65b994b0a000895fe5a

Copy link

netlify bot commented Sep 15, 2024

Deploy Preview for lustrous-crepe-2ddaec failed.

Name Link
🔨 Latest commit d078b09
🔍 Latest deploy log https://app.netlify.com/sites/lustrous-crepe-2ddaec/deploys/66e6b65bfb67f90008a88c6b

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants