Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , dotenv, express, firebase-admin, nodemon, query-string #717

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

davidhin
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@google-cloud/storage
from 5.7.2 to 5.20.5 | 50 versions ahead of your current version | 2 years ago
on 2022-05-19
dotenv
from 8.2.0 to 8.6.0 | 5 versions ahead of your current version | 3 years ago
on 2021-05-05
express
from 4.17.1 to 4.19.2 | 9 versions ahead of your current version | 6 months ago
on 2024-03-25
firebase-admin
from 9.4.2 to 9.12.0 | 9 versions ahead of your current version | 3 years ago
on 2021-09-28
nodemon
from 2.0.7 to 2.0.22 | 25 versions ahead of your current version | a year ago
on 2023-03-22
query-string
from 6.13.8 to 6.14.1 | 2 versions ahead of your current version | 4 years ago
on 2021-02-26

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
696 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
696 Proof of Concept
high severity Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
696 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NORMALIZEURL-1296539
696 No Known Exploit
high severity Prototype Poisoning
SNYK-JS-QS-3153490
696 Proof of Concept
medium severity Open Redirect
SNYK-JS-GOT-2932019
696 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
696 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
696 No Known Exploit
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
696 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
696 Proof of Concept
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
696 Proof of Concept
Release notes
Package name: @google-cloud/storage
  • 5.20.5 - 2022-05-19

    5.20.5 (2022-05-19)

    Bug Fixes

    • chore: move uuid package to dependencies (#1952) (0ff5aa3)
  • 5.20.4 - 2022-05-18

    5.20.4 (2022-05-18)

    Bug Fixes

    • revert native typescript mocha tests (#1947) (1d0ea7d)
    • support empty object uploads for resumable upload (#1949) (da6016e)
  • 5.20.3 - 2022-05-17

    5.20.3 (2022-05-17)

    Bug Fixes

    • move retrieval of package.json to utility function (#1941) (ac5cbdf)
  • 5.20.2 - 2022-05-17

    5.20.2 (2022-05-17)

    Bug Fixes

    • use path.join and __dirname for require package.json (#1936) (b868762)
  • 5.20.1 - 2022-05-16

    5.20.1 (2022-05-16)

    Bug Fixes

  • 5.20.0 - 2022-05-16

    5.20.0 (2022-05-16)

    Features

    • add x-goog-api-client headers for retry metrics (#1920) (0c7e4f6)
  • 5.19.4 - 2022-04-28

    5.19.4 (2022-04-28)

    Bug Fixes

  • 5.19.3 - 2022-04-20

    5.19.3 (2022-04-20)

    Bug Fixes

    • export idempotencystrategy and preconditionoptions from index (#1880) (8aafe04)
  • 5.19.2 - 2022-04-14

    5.19.2 (2022-04-14)

    Bug Fixes

    • deleting, getting, and getting metadata for notifications (#1872) (451570e)
  • 5.19.1 - 2022-04-11

    5.19.1 (2022-04-08)

    Bug Fixes

  • 5.19.0 - 2022-04-06
  • 5.18.3 - 2022-03-28
  • 5.18.2 - 2022-02-16
  • 5.18.1 - 2022-01-26
  • 5.18.0 - 2022-01-19
  • 5.17.0 - 2022-01-10
  • 5.16.1 - 2021-12-01
  • 5.16.0 - 2021-11-09
  • 5.15.6 - 2021-11-08
  • 5.15.5 - 2021-11-03
  • 5.15.4 - 2021-11-01
  • 5.15.3 - 2021-10-14
  • 5.15.2 - 2021-10-13
  • 5.15.1 - 2021-10-12
  • 5.15.0 - 2021-10-07
  • 5.14.8 - 2021-10-06
  • 5.14.7 - 2021-10-06
  • 5.14.6 - 2021-10-06
  • 5.14.5 - 2021-10-04
  • 5.14.4 - 2021-09-27
  • 5.14.3 - 2021-09-22
  • 5.14.2 - 2021-09-13
  • 5.14.1 - 2021-09-08
  • 5.14.0 - 2021-08-26
  • 5.13.2 - 2021-08-26
  • 5.13.1 - 2021-08-18
  • 5.13.0 - 2021-08-09
  • 5.12.0 - 2021-08-03
  • 5.11.1 - 2021-08-02
  • 5.11.0 - 2021-07-26
  • 5.10.0 - 2021-07-22
  • 5.9.0 - 2021-07-21
  • 5.8.5 - 2021-05-04
  • 5.8.4 - 2021-04-19
  • 5.8.3 - 2021-03-29
  • 5.8.2 - 2021-03-23
  • 5.8.1 - 2021-03-03
  • 5.8.0 - 2021-02-18
  • 5.7.4 - 2021-02-01
  • 5.7.3 - 2021-01-25
  • 5.7.2 - 2021-01-11
from @google-cloud/storage GitHub release notes
Package name: dotenv from dotenv GitHub release notes
Package name: express from express GitHub release notes
Package name: firebase-admin
  • 9.12.0 - 2021-09-28

    New Features

    • feat(rc): Add Remote Config Parameter Value Type Support (#1424)

    Bug Fixes

    • fix(fac): Verify Token: Change the jwks cache duration from 1 day to 6 hours (#1439)
    • fix(rtdb): Changed admin.database to use database-compat package (#1437)

    Miscellaneous

    • [chore] Release 9.12.0 (#1442)
    • Pin @ types/jsonwebtoken to 8.5.1 (#1438)
    • build(deps): bump tar from 6.1.3 to 6.1.11 (#1430)
    • build(deps-dev): bump @ types/lodash from 4.14.171 to 4.14.173 (#1435)
    • build(deps-dev): bump @ microsoft/api-extractor from 7.18.4 to 7.18.7 (#1423)
    • fix typo (#1420)
  • 9.11.1 - 2021-08-19

    Bug Fixes

    • fix: Update comments in index files (#1414)
    • fix: Throw error on user disabled and check revoked set true (#1401)

    Miscellaneous

    • [chore] Release 9.11.1 (#1415)
    • build(deps): bump path-parse from 1.0.6 to 1.0.7 (#1413)
    • build(deps-dev): bump yargs from 17.0.1 to 17.1.1 (#1412)
    • chore: Add emulator tests to nightlies (#1409)
    • build(deps-dev): bump ts-node from 9.0.0 to 10.2.0 (#1402)
    • build(deps): bump tar from 6.1.0 to 6.1.3 (#1399)
    • build(deps-dev): bump @ microsoft/api-extractor from 7.15.2 to 7.18.4 (#1379)
    • build(deps): bump jwks-rsa from 2.0.3 to 2.0.4 (#1393)
    • build(deps-dev): bump @ types/minimist from 1.2.1 to 1.2.2 (#1388)
    • build(deps-dev): bump @ types/request from 2.48.5 to 2.48.6 (#1387)
    • build(deps-dev): bump @ types/lodash from 4.14.157 to 4.14.171 (#1386)
    • build(deps): bump @ firebase/database from 0.10.6 to 0.10.7 (#1385)
    • build(deps-dev): bump @ types/bcrypt from 2.0.0 to 5.0.0 (#1384)
    • build(deps-dev): bump nock from 13.1.0 to 13.1.1 (#1370)
  • 9.11.0 - 2021-07-15

    New Features

    • feat(fac): Add custom TTL options for App Check (#1363)

    Miscellaneous

    • [chore] Release 9.11.0 (#1376)
    • Fix typo and formatting in docs (#1378)
    • Add AppCheckTokenOptions type to ToC (#1375)
    • Reduce App Check custom token exp to 5 mins (#1372)
    • build(deps): bump @ google-cloud/firestore from 4.12.2 to 4.13.1 (#1369)
    • Update index.ts (#1367)
    • build(deps-dev): bump @ types/chai from 4.2.11 to 4.2.21 (#1365)
    • build(deps-dev): bump yargs from 16.1.0 to 17.0.1 (#1357)
    • build(deps): bump jwks-rsa from 2.0.2 to 2.0.3 (#1361)
    • build(deps): bump @ firebase/database from 0.10.5 to 0.10.6 (#1356)
    • build(deps-dev): bump @ types/sinon from 9.0.4 to 10.0.2 (#1326)
    • build(deps-dev): bump @ types/nock from 9.3.1 to 11.1.0 (#1351)
    • build(deps): bump @ firebase/database from 0.10.4 to 0.10.5 (#1350)
    • build(deps-dev): bump @ types/request-promise from 4.1.46 to 4.1.47 (#1338)
  • 9.10.0 - 2021-06-24

    New Features

    • feat(fis): Adding the admin.installations() API for deleting Firebase installation IDs (#1187)

    Bug Fixes

    • fix: Updated TOC for new Auth type aliases (#1342)
    • fix(docs): replace all global.html -> admin.html (#1341)
    • fix(auth): Better type hierarchies for Auth API (#1294)

    Miscellaneous

    • [chore] Release 9.10.0 (#1345)
    • build(deps-dev): bump @ types/minimist from 1.2.0 to 1.2.1 (#1336)
    • build(deps-dev): bump gulp-filter from 6.0.0 to 7.0.0 (#1334)
    • build(deps-dev): bump request-promise from 4.2.5 to 4.2.6 (

Snyk has created this PR to upgrade:
  - @google-cloud/storage from 5.7.2 to 5.20.5.
    See this package in npm: https://www.npmjs.com/package/@google-cloud/storage
  - dotenv from 8.2.0 to 8.6.0.
    See this package in npm: https://www.npmjs.com/package/dotenv
  - express from 4.17.1 to 4.19.2.
    See this package in npm: https://www.npmjs.com/package/express
  - firebase-admin from 9.4.2 to 9.12.0.
    See this package in npm: https://www.npmjs.com/package/firebase-admin
  - nodemon from 2.0.7 to 2.0.22.
    See this package in npm: https://www.npmjs.com/package/nodemon
  - query-string from 6.13.8 to 6.14.1.
    See this package in npm: https://www.npmjs.com/package/query-string

See this project in Snyk:
https://app.snyk.io/org/davidhin/project/841c5671-e275-457f-90b0-2f0dac39b3e5?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants