LeoDBMX / goof

Super vulnerable todo list application
Apache License 2.0
0 stars 0 forks source link

[Snyk] Upgrade typeorm from 0.2.24 to 0.2.37 #1

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade typeorm from 0.2.24 to 0.2.37.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-TYPEORM-590152
801/1000
Why? Mature exploit, Has a fix available, CVSS 8.3
Mature
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HIGHLIGHTJS-1048676
801/1000
Why? Mature exploit, Has a fix available, CVSS 8.3
No Known Exploit
Prototype Pollution
SNYK-JS-HIGHLIGHTJS-1045326
801/1000
Why? Mature exploit, Has a fix available, CVSS 8.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: typeorm
  • 0.2.37 - 2021-08-13

    Bug Fixes

    • allow periods in parameter identifiers (#8022) (4201938)
    • ConnectionManager connections property should include list of Connections (#8004) (2344db6)
    • entity value for date columns that are related (#8027) (5a3767f)
    • handle brackets when only one condition is passed (#8048) (ab39066)
    • handle enums with multiple apostrophes in MySQL (#8013) (37c40a6), closes #8011
    • include all drivers in driverfactory error message (#8061) (fbd1ef7)
    • resolve not returning soft deleted relations with withDeleted find option (#8017) (65cbcc7)
    • SAP HANA inserts used incorrect value for returning query (#8072) (36398db)
    • some drivers set the wrong database name when defined from url (#8058) (a3a3284)
    • throw error when not connected in drivers (#7995) (cd71f62)

    Features

  • 0.2.37-dev.fe78bee - 2021-08-08
  • 0.2.37-dev.fbd1ef7 - 2021-08-11
  • 0.2.37-dev.fbbac93 - 2021-08-03
  • 0.2.37-dev.f7eb46d - 2021-07-31
  • 0.2.37-dev.f0e40f6 - 2021-08-06
  • 0.2.37-dev.cd71f62 - 2021-07-31
  • 0.2.37-dev.ca26297 - 2021-08-04
  • 0.2.37-dev.ba366f2 - 2021-08-08
  • 0.2.37-dev.ab39066 - 2021-08-06
  • 0.2.37-dev.a5e4ce7 - 2021-08-05
  • 0.2.37-dev.a3a3284 - 2021-08-10
  • 0.2.37-dev.91d5b2f - 2021-07-31
  • 0.2.37-dev.80cdf8f - 2021-08-11
  • 0.2.37-dev.768b4fe - 2021-08-05
  • 0.2.37-dev.69fabaf - 2021-07-31
  • 0.2.37-dev.65cbcc7 - 2021-08-10
  • 0.2.37-dev.5a3767f - 2021-08-08
  • 0.2.37-dev.5714e8d - 2021-08-11
  • 0.2.37-dev.37c40a6 - 2021-08-11
  • 0.2.37-dev.37bd012 - 2021-08-04
  • 0.2.37-dev.36398db - 2021-08-12
  • 0.2.37-dev.2344db6 - 2021-08-04
  • 0.2.37-dev.01a038c - 2021-08-13
  • 0.2.37-dev.4201938 - 2021-08-05
  • 0.2.36 - 2021-07-31

    Bug Fixes

    • add deprecated WhereExpression alias for WhereExpressionBuilder (#7980) (76e7ed9)
    • always generate migrations with template string literals (#7971) (e9c2af6)
    • use js rather than ts in all browser package manifests (#7982) (0d90bcd)
    • use nvarchar/ntext during transit for SQLServer queries (#7933) (62d7976)

    Features

    • add postgres connection option applicationName (#7989) (d365acc)
  • 0.2.36-dev.d365acc - 2021-07-30
  • 0.2.36-dev.b797781 - 2021-07-30
  • 0.2.36-dev.76e7ed94 - 2021-07-30
  • 0.2.36-dev.62d7976 - 2021-07-31
  • 0.2.36-dev.0d90bcd - 2021-07-30
  • 0.2.35 - 2021-07-29
    Read more
  • 0.2.35-rc.0 - 2021-07-28
  • 0.2.34 - 2021-06-03

    version bump

  • 0.2.33 - 2021-06-01

    version bump

  • 0.2.32 - 2021-03-30

    version bump

  • 0.2.31 - 2021-02-08

    version bump

  • 0.2.30 - 2021-01-12

    version bump

  • 0.2.29 - 2020-11-02

    version bump

  • 0.2.28 - 2020-09-30

    version bump

  • 0.2.27 - 2020-09-29
  • 0.2.26 - 2020-09-10
  • 0.2.25 - 2020-05-19
  • 0.2.24 - 2020-02-28
from typeorm GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs