AlaSQL / node-red-contrib-alasql

A Node-RED node wrapping AlaSQL for fast SQL based in-memory data processing for BI and ERP applications.
MIT License
8 stars 11 forks source link

[Snyk] Upgrade alasql from 0.6.3 to 0.6.4 #37

Closed snyk-bot closed 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to upgrade alasql from 0.6.3 to 0.6.4.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-LODASH-590103
490/1000
Why? CVSS 9.8
No Known Exploit
Prototype Pollution
SNYK-JS-AJV-584908
490/1000
Why? CVSS 9.8
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: alasql
  • 0.6.4 - 2020-09-24
    • Add: String and Number objects supported as values
    • Add: JOIN USING now supports String and Number objects
    • Fix: File naming when exporting to Exel
  • 0.6.3 - 2020-07-20
from alasql GitHub release notes
Commit messages
Package name: alasql
  • 2311b55 Bump deps
  • 658cae4 Bump xlsx from 0.16.6 to 0.16.7 (#1226)
  • b34aa92 Devops: remove dist/ from repo
  • f33dd98 devops: format all
  • 44723c6 Create dependabot.yml
  • 4fb1808 JOIN USING compatibility with String and Number objects (#1225)
  • a38759c String/Number object support (#1219)
  • 3e3284d devops: format all
  • e15135a Fix #919
  • 1023123 Update README.md
  • 945ae68 Updated version in files to 0.6.3
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs