[Snyk] Upgrade: concurrently, config, express-jwt, fs, mongoose, nodemon, pdfkit, validator #4
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
concurrently
from 6.3.0 to 6.5.1 | 3 versions ahead of your current version | 3 years ago
on 2021-12-19
config
from 3.3.6 to 3.3.12 | 6 versions ahead of your current version | 3 months ago
on 2024-06-25
express-jwt
from 6.1.0 to 6.1.2 | 2 versions ahead of your current version | 2 years ago
on 2022-04-20
fs
from 0.0.1-security to 0.0.2 | 1 version ahead of your current version | 10 years ago
on 2014-09-12
mongoose
from 6.0.10 to 6.13.0 | 99 versions ahead of your current version | 3 months ago
on 2024-06-06
nodemon
from 2.0.13 to 2.0.22 | 10 versions ahead of your current version | a year ago
on 2023-03-22
pdfkit
from 0.12.3 to 0.15.0 | 3 versions ahead of your current version | 6 months ago
on 2024-03-24
validator
from 13.6.0 to 13.12.0 | 4 versions ahead of your current version | 4 months ago
on 2024-05-09
Issues fixed by the recommended upgrade:
SNYK-JS-CRYPTOJS-6028119
SNYK-JS-LODASHSET-1320032
SNYK-JS-MONGOOSE-2961688
SNYK-JS-MONGOOSE-5777721
SNYK-JS-VALIDATOR-1090600
SNYK-JS-GOT-2932019
SNYK-JS-HTTPCACHESEMANTICS-3248783
SNYK-JS-JSON5-3182856
SNYK-JS-MINIMATCH-3050818
SNYK-JS-MONGODB-5871303
Release notes
Package name: concurrently
-
6.5.1 - 2021-12-19
- Fix command names when using npm wildcard (#148, #165, #211, #212)
-
6.5.0 - 2021-12-17
- Add support for configuring via environment variables that start with
- Add
-
6.4.0 - 2021-11-13
- Add
-
6.3.0 - 2021-10-02
- Distribute prefix colors correctly when using npm/yarn/pnpm script expansion (#186, #210, #234, #286)
- Add new option to programmatic API,
from concurrently GitHub release notesCONCURRENTLY_prefix (#289)--timingsflag to show when each process started and stopped, and how long they ran for (#291, #295)--hideflag to hide the output of specified commands (#138, #173)prefixColors, which serves as fallback for commands without aprefixColor(#286)Package name: config
-
3.3.12 - 2024-06-25
- Remove usage of deprecated utils to fix warnings in Node 22 by @ KidkArolis in #764
- @ KidkArolis made their first contribution in #764
-
3.3.11 - 2024-02-01
- fix: webpack bundling compatibility by @ cbazureau in #757
- @ cbazureau made their first contribution in #757
-
3.3.10 - 2024-01-09
- replace var to let and const by @ jamashita in #720
- refactor: 💡 xxx === undefined => typeof xxx === 'undefined' by @ jamashita in #729
- Fix source maps when using ts config files, improve performance loading ts config files by @ andrzej-woof in #721
- fix: lack of comments removal, invalid regexp by @ DeutscherDude in #745
- @ jamashita made their first contribution in #720
- @ andrzej-woof made their first contribution in #721
- @ DeutscherDude made their first contribution in #745
-
3.3.9 - 2023-01-17
- Support loading transpiled JS config files by @ Tomas2D in #692
- fix(vulnerability): upgrade json5 version from 2.2.1 to 2.2.2 by @ veekays in #713
- @ Tomas2D made their first contribution in #692
- @ veekays made their first contribution in #713
-
3.3.8 - 2022-09-09
- bump json5 dep to 2.2.1
- Cleanup of file scoped environment variables by @ jdmarshall in #667
- Allow multiple relative directory paths separated by path.delimiter to work by @ inside in #661
- Reentrancy bugs by @ jdmarshall in #668
- Fixed property mutation. Throw an exception on such an attempt. Updat… by @ fgheorghe in #516
- docs: update copyright & fix misspelling by @ DigitalGreyHat in #677
- @ jdmarshall made their first contribution in #667
- @ inside made their first contribution in #661
- @ DigitalGreyHat made their first contribution in #677
-
3.3.7 - 2022-01-11
- No code changes. Resolving versioning / release mix-up
-
3.3.6 - 2021-03-08
- Added publishConfig element to package.json to prevent publishing to the wrong repository - @ lorenwest
from config GitHub release notesWhat's Changed
New Contributors
Full Changelog: v3.3.11...v3.3.12
What's Changed
New Contributors
Full Changelog: v3.3.10...v3.3.11
What's Changed
New Contributors
Full Changelog: v3.3.9...v3.3.10
What's Changed
New Contributors
Full Changelog: v3.3.8...v3.3.9
What's Changed
New Contributors
Full Changelog: v3.3.7...v3.3.8
Package name: express-jwt
-
6.1.2 - 2022-04-20
-
6.1.1 - 2022-02-21
-
6.1.0 - 2021-08-11
from express-jwt GitHub release notes6.1.2
6.1.1
6.1.0
Package name: fs
-
0.0.2 - 2014-09-12
-
0.0.1-security - 2016-08-23
from fs GitHub release notesPackage name: mongoose
-
6.13.0 - 2024-06-06
-
6.12.9 - 2024-05-24
-
6.12.8 - 2024-04-10
-
6.12.7 - 2024-03-01
-
6.12.6 - 2024-01-22
-
6.12.5 - 2024-01-03
-
6.12.4 - 2023-12-27
-
6.12.3 - 2023-11-07
-
6.12.2 - 2023-10-25
-
6.12.1 - 2023-10-12
-
6.12.0 - 2023-08-24
-
6.11.6 - 2023-08-21
-
6.11.5 - 2023-08-01
-
6.11.4 - 2023-07-17
-
6.11.3 - 2023-07-11
-
6.11.2 - 2023-06-08
-
6.11.1 - 2023-05-08
-
6.11.0 - 2023-05-01
-
6.10.5 - 2023-04-06
-
6.10.4 - 2023-03-21
-
6.10.3 - 2023-03-13
-
6.10.2 - 2023-03-07
-
6.10.1 - 2023-03-03
-
6.10.0 - 2023-02-22
-
6.9.3 - 2023-02-22
-
6.9.2 - 2023-02-16
-
6.9.1 - 2023-02-06
-
6.9.0 - 2023-01-25
-
6.8.4 - 2023-01-17
-
6.8.3 - 2023-01-06
-
6.8.2 - 2022-12-28
-
6.8.1 - 2022-12-19
-
6.8.0 - 2022-12-05
-
6.7.5 - 2022-11-30
-
6.7.4 - 2022-11-28
-
6.7.3 - 2022-11-22
-
6.7.2 - 2022-11-07
-
6.7.1 - 2022-11-02
-
6.7.0 - 2022-10-24
-
6.6.7 - 2022-10-21
-
6.6.6 - 2022-10-20
-
6.6.5 - 2022-10-05
-
6.6.4 - 2022-10-03
-
6.6.3 - 2022-09-30
-
6.6.2 - 2022-09-26
-
6.6.1 - 2022-09-14
-
6.6.0 - 2022-09-08
-
6.5.5 - 2022-09-07
-
6.5.4 - 2022-08-30
-
6.5.3 - 2022-08-25
-
6.5.2 - 2022-08-10
-
6.5.1 - 2022-08-03
-
6.5.0 - 2022-07-26
-
6.4.7 - 2022-07-25
-
6.4.6 - 2022-07-20
-
6.4.5 - 2022-07-18
-
6.4.4 - 2022-07-08
-
6.4.3 - 2022-07-05
-
6.4.2 - 2022-07-01
-
6.4.1 - 2022-06-27
-
6.4.0 - 2022-06-17
-
6.3.9 - 2022-06-17
-
6.3.8 - 2022-06-13
-
6.3.7 - 2022-06-13
-
6.3.6 - 2022-06-07
-
6.3.5 - 2022-05-30
-
6.3.4 - 2022-05-19
-
6.3.3 - 2022-05-09
-
6.3.2 - 2022-05-02
-
6.3.1 - 2022-04-21
-
6.3.0 - 2022-04-14
-
6.2.11 - 2022-04-13
-
6.2.10 - 2022-04-04
-
6.2.9 - 2022-03-28
-
6.2.8 - 2022-03-23
-
6.2.7 - 2022-03-16
-
6.2.6 - 2022-03-11
-
6.2.5 - 2022-03-09
-
6.2.4 - 2022-02-28
-
6.2.3 - 2022-02-21
-
6.2.2 - 2022-02-16
-
6.2.1 - 2022-02-07
-
6.2.0 - 2022-02-02
-
6.1.10 - 2022-02-01
-
6.1.9 - 2022-01-31
-
6.1.8 - 2022-01-24
-
6.1.7 - 2022-01-17
-
6.1.6 - 2022-01-10
-
6.1.5 - 2022-01-04
-
6.1.4 - 2021-12-27
-
6.1.3 - 2021-12-21
-
6.1.2 - 2021-12-15
-
6.1.1 - 2021-12-09
-
6.1.0 - 2021-12-07
-
6.0.15 - 2021-12-06
-
6.0.14 - 2021-11-29
-
6.0.13 - 2021-11-15
-
6.0.12 - 2021-10-21
-
6.0.11 - 2021-10-14
-
6.0.10 - 2021-10-08
from mongoose GitHub release notesPackage name: nodemon
-
2.0.22 - 2023-03-22
- remove ts mapping if loader present (f7816e4), closes #2083
-
2.0.21 - 2023-03-02
- remove ts mapping if loader present (1468397), closes #2083
-
2.0.20 - 2022-09-16
- remove postinstall script (e099e91)
-
2.0.19 - 2022-07-05
- Replace update notifier with simplified deps (#2033) (176c4a6), closes #1961 #2028
-
2.0.18 - 2022-06-23
- revert update-notifier forcing esm (1b3bc8c)
-
2.0.17 - 2022-06-23
- bump update-notifier to v6.0.0 (#2029) (0144e4f)
- update packge-lock (27e91c3)
-
2.0.16 - 2022-04-29
- support windows by using path.delimiter (e26aaa9)
-
2.0.15 - 2021-11-09
- bump prod dep versions (54784ab)
-
2.0.14 - 2021-10-19
- add windows signals SIGUSR2 & SIGUSR1 to terminate the process (#1938) (61e7abd), closes #1903 #1915 #1936 #1937 #1882 #1893
-
2.0.14-alpha.1 - 2021-10-18
-
2.0.13 - 2021-09-23
- bump update-notifier (90e7a3e), closes #1919
- release process on main (9f82a48)
from nodemon GitHub release notes2.0.22 (2023-03-22)
Bug Fixes
2.0.21 (2023-03-02)
Bug Fixes
2.0.20 (2022-09-16)
Bug Fixes
2.0.19 (2022-07-05)
Bug Fixes
2.0.18 (2022-06-23)
Bug Fixes
2.0.17 (2022-06-23)
Bug Fixes
2.0.16 (2022-04-29)
Bug Fixes
2.0.15 (2021-11-09)
Bug Fixes
2.0.14 (2021-10-19)
Bug Fixes
2.0.13 (2021-09-23)
Bug Fixes
Package name: pdfkit
-
0.15.0 - 2024-03-24
- Add subset for PDF/UA
- Fix for line breaks in list items (#1486)
- Fix for soft hyphen not being replaced by visible hyphen if necessary (#457)
- Optimize output files by ignoring identity transforms
- Fix for Acroforms - setting an option to false will still apply the flag (#1495)
- Fix for text extraction in PDFium-based viewers due to invalid ToUnicodeMap (#1498)
- Remove deprecated
- Drop support for Node.js < 18 and for browsers released before 2020
-
0.14.0 - 2023-11-09
- Add support for PDF/A-1b, PDF/A-1a, PDF/A-2b, PDF/A-2a, PDF/A-3b, PDF/A-3a
- Update crypto-js to v4.2.0 (properly fix security issue)
-
0.13.0 - 2021-10-24
- Add tiling pattern support
-
0.12.3 - 2021-08-01
from pdfkit GitHub release noteswritemethodv0.12.3
Package name: validator
What's Changed
New Features / Validators
isAbaRouting@ songyuewFixes, New Locales and Enhancements
isLicensePlateadd Pakistanien-PKlocale @ anasshakilisPortfix invalid leading zeros @ anasshakilisTaxIDadded Argentinaes-ARlocale @ estefrareisDatetimezone offset fix @ tomaspanekisPassportNumberaddedZAlocale @ GMorris-professionalisMobilePhone:en-MWlocale @ SimranSiddiquiam-AMlocale @ AlexKrupkoisPostalAddressfixNLlocale @ RobinvanderVlietisISO4217addSLEcurrency @ urgisStrongPasswordfix symbolRegex to include\@ nandavikasisVATfixedKZlocale @ MatthieuLemoineisAlpha,isAlphanumericaddedeolocale @ RobinvanderVlietisIBANadd AlgeriaDZlocale @ thibault-lrisVATimproveAUlocale @ matthewberrymanisUUIDadd support for v7 @ rusconisTaxIDadd Ukraineuk-UAlocale @ arttigerisDatedisallow hiphen before year @ Sumit-tech-joshiNew Contributors