LBH3 / lbh3.org

LBH3 website
https://www.lbh3.org
Other
0 stars 0 forks source link

[Snyk] Security upgrade @feathersjs/socketio from 3.2.9 to 4.5.18 #452

Open chasenlehara opened 1 year ago

chasenlehara commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Improper Check for Unusual or Exceptional Conditions
[SNYK-JS-FEATHERSJSSOCKETIO-5794666](https://snyk.io/vuln/SNYK-JS-FEATHERSJSSOCKETIO-5794666) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @feathersjs/socketio The new version differs by 250 commits.
  • 2d3671d chore(release): publish v4.5.18
  • caa11cf chore: Update package-lock.json
  • 0b9a6b1 fix(transport-commons): Handle invalid service paths on socket lookups (#3242)
  • 022a407 chore(release): publish v4.5.17
  • 7969334 fix(core): Ensure .service does not access Object properties (#3240)
  • 18872c0 chore(release): publish v4.5.16
  • 1936c64 fix(transport-commons): Crow - fix array dispatching (#3073)
  • f5f7fae chore: Update publishin dist tag
  • 70335c4 fix(dependencies): Update dependencies
  • 141ecac chore: Fix changelog name
  • e81cad0 chore: Get builds and installation working again
  • 1f7ee5c chore: Fix NPM page links an images (#2768)
  • 5fe9644 chore: Moving community from slack to discord (#2736)
  • 1774fe0 chore: Update changelog
  • d0e9600 chore(release): publish v4.5.15
  • 849180f chore: Update package-lock.json
  • 25b6fb5 chore(release): publish v4.5.14
  • 5ec2ec8 fix(transport-commons): Ensure socket queries are always plain objects (#2598)
  • 445e804 fix(rest-client): Import errors from @ feathers/errors (#2591)
  • b5e94c4 chore(release): publish v4.5.13
  • 32356a5 fix: Fix socket.io type dependency (#2526)
  • 7fd94ce chore: Fix changelog
  • 8697ecc chore(release): publish v4.5.12
  • 67a7e31 fix(authentication-oauth): OAuth redirect lost sometimes due to session store race (#2514) (#2515)
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/chasenlehara/project/cc7408d4-89bd-4d22-a48e-38923d9f711b?utm_source=github&utm_medium=referral&page=fix-pr) πŸ›  [Adjust project settings](https://app.snyk.io/org/chasenlehara/project/cc7408d4-89bd-4d22-a48e-38923d9f711b?utm_source=github&utm_medium=referral&page=fix-pr/settings) πŸ“š [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"bfde72d9-b8e8-4a9b-8163-00cc86269bc5","prPublicId":"bfde72d9-b8e8-4a9b-8163-00cc86269bc5","dependencies":[{"name":"@feathersjs/socketio","from":"3.2.9","to":"4.5.18"}],"packageManager":"npm","projectPublicId":"cc7408d4-89bd-4d22-a48e-38923d9f711b","projectUrl":"https://app.snyk.io/org/chasenlehara/project/cc7408d4-89bd-4d22-a48e-38923d9f711b?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-FEATHERSJSSOCKETIO-5794666"],"upgrade":["SNYK-JS-FEATHERSJSSOCKETIO-5794666"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[661],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** πŸ¦‰ [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc=fix-pr)