BlueWallet / LndHub

Wrapper for Lightning Network Daemon. It provides separate accounts for end-users
http://LndHub.io
MIT License
776 stars 196 forks source link

[Snyk] Upgrade @grpc/proto-loader from 0.6.5 to 0.6.11 #449

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade @grpc/proto-loader from 0.6.5 to 0.6.11.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-PROTOBUFJS-2441248
589/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 8.2
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @grpc/proto-loader
  • 0.6.11 - 2022-05-03
    • Broaden dependency on long to 4.x or 5.x (#2112)
  • 0.6.10 - 2022-05-02
    • Update the dependency on the long library to version 5 to fix some TypeScript type compatibility issues (#2110)
  • 0.6.9 - 2022-01-05
  • 0.6.8 - 2022-01-04
  • 0.6.7 - 2021-11-16
  • 0.6.6 - 2021-10-18
  • 0.6.5 - 2021-09-13
from @grpc/proto-loader GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs