Skip to content

[Snyk] Fix for 1 vulnerabilities#31

Open
snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-9cf06fab074a4de6eba7a4574c61c441
Open

[Snyk] Fix for 1 vulnerabilities#31
snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-9cf06fab074a4de6eba7a4574c61c441

Conversation

@snyk-bot

Copy link
Copy Markdown

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: bookshelf The new version differs by 250 commits.
  • bad8157 Fix wrong model being saved in PostgreSQL test
  • f0d7d63 Fix empty previousAttributes in collection models
  • ebe3c5c Reword some test cases
  • 00b0f93 Add tests for previousAttributes in collections
  • 3cdfa6e Add event related tests for previousAttributes()
  • 54554b7 Create previous attributes using deepClone
  • aef8244 Merge branch 'master' into rg-previous-attributes
  • 75492e7 Add new events guide
  • fc66733 Rename test case to make it more obvious
  • 32add1b Merge pull request #1876 from okuyiga/feature/fix-nested-json-bug
  • 8259d71 Create CNAME
  • 5b5b7f9 Merge pull request #1909 from bookshelf/rg-new-docs
  • 7b33289 Remove link from project title
  • e5fb28e Replace gh-pages with docs directory in master
  • 6551c02 Update plugin doc
  • 2694023 Update the structure of tutorials and add index
  • a9c41fc Update jsdoc theme package version
  • 7d91423 Refactor changelog format so it's more consistent
  • 55d0c30 Merge pull request #1903 from bookshelf/greenkeeper/lint-staged-8.0.0
  • 85e831a Merge pull request #1907 from chentsulin/husky-v1
  • 7831afb Merge pull request #1900 from chentsulin/patch-2
  • 7b61c04 upgrade husky to v1
  • dabce4e refactor: model.save using computed property name
  • 12bff36 Merge pull request #1904 from travnels/Turbocolor-to-Colorette

See the full diff

Package name: knex The new version differs by 250 commits.
  • eb136f1 Merge branch 'master' of https://github.com/tgriesser/knex
  • 2072163 Update version in changelog (#3138)
  • f28ae7a Merge branch 'master' of https://github.com/tgriesser/knex
  • f757e36 Bump version to 0.16.4 (#3137)
  • 18532b2 Bump version to 0.16.4
  • 286d84b Prepare for 0.16.4-next3 release (#3136)
  • 1948c3d Add boolean as a column name in join (#3121)
  • fe6083e Support nullable timestamps on MySQL (#3100)
  • b15ee3d make unionAll()'s call signature match union() (#3055)
  • e7ed005 Fix queryContext not being passed to raw queries (#3111)
  • 11fdc0c Add missing clearOrder & clearCounters types (#3109)
  • 7ecbcd5 Update changelog and version number (#3108)
  • 5fea86e Update dependencies (#3107)
  • 19926d8 [#3033] fix: sqlite3 drop/renameColumn() breaks with postProcessResponse (#3040)
  • 24fcf27 Fix transaction support for migrations (#3084)
  • de1c934 Include 'string' as accepted Knex constructor type definition (#3105)
  • 0aacab5 Fix for #2998 - Migrator & TypeScript (#3041)
  • fcd21d9 Add command for executing tests on SQLite (#3101)
  • 1da56a3 Update mssql dev dep to v5 stable (#3096)
  • b9a648c Format code (#3088)
  • 0db7859 add test that clearing offset (#2954)
  • f3f0750 Make TS stubs modern (#3080)
  • 68723e0 Update changelog (#3086)
  • 1b39d67 Tests for drop-and-recreate with async/await (#3083)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant