Skip to content

Conversation

@anukulSingh
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

config
from 3.3.2 to 3.3.12 | 9 versions ahead of your current version | 3 months ago
on 2024-06-25
express
from 4.17.1 to 4.19.2 | 9 versions ahead of your current version | 6 months ago
on 2024-03-25
express-validator
from 6.6.1 to 6.15.0 | 20 versions ahead of your current version | 2 years ago
on 2023-02-16
gravatar
from 1.8.1 to 1.8.2 | 1 version ahead of your current version | 3 years ago
on 2021-08-16
mongoose
from 5.10.14 to 5.13.22 | 65 versions ahead of your current version | 8 months ago
on 2024-01-02

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Code Injection
SNYK-JS-LODASH-1040724
681 Proof of Concept
high severity Prototype Pollution
SNYK-JS-MONGOOSE-2961688
681 Proof of Concept
high severity Prototype Pollution
SNYK-JS-MONGOOSE-5777721
681 Proof of Concept
high severity Prototype Pollution
SNYK-JS-MQUERY-1050858
681 Proof of Concept
high severity Prototype Pollution
SNYK-JS-MQUERY-1089718
681 Proof of Concept
medium severity Information Exposure
SNYK-JS-MONGODB-5871303
681 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-MONGOOSE-1086688
681 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-MPATH-1577289
681 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090602
681 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090599
681 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090600
681 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090601
681 Proof of Concept
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
681 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
681 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
681 Proof of Concept
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
681 Proof of Concept
Release notes
Package name: config from config GitHub release notes
Package name: express from express GitHub release notes
Package name: express-validator

Snyk has created this PR to upgrade:
  - config from 3.3.2 to 3.3.12.
    See this package in npm: https://www.npmjs.com/package/config
  - express from 4.17.1 to 4.19.2.
    See this package in npm: https://www.npmjs.com/package/express
  - express-validator from 6.6.1 to 6.15.0.
    See this package in npm: https://www.npmjs.com/package/express-validator
  - gravatar from 1.8.1 to 1.8.2.
    See this package in npm: https://www.npmjs.com/package/gravatar
  - mongoose from 5.10.14 to 5.13.22.
    See this package in npm: https://www.npmjs.com/package/mongoose

See this project in Snyk:
https://app.snyk.io/org/anukulsingh/project/c43b2822-620a-44a5-80b0-6f81c1451cee?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants