MateMalice / mail-listener2

Mail listener library for node.js. Get notification when new email arrived.
Other
9 stars 7 forks source link

[Snyk] Upgrade mailparser from 2.4.3 to 2.7.7 #15

Closed snyk-bot closed 3 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to upgrade mailparser from 2.4.3 to 2.7.7.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue Exploit Maturity
Prototype Pollution
SNYK-JS-MINIMIST-559764
Proof of Concept
Release notes
Package name: mailparser from mailparser GitHub release notes
Commit messages
Package name: mailparser
  • 6bfb93e v2.7.7
  • a8222e2 Reimplemented #231
  • 9eecb85 Remove double decoding of header value via libmime, add test for colons in From header.
  • 81c1e35 Create FUNDING.yml
  • 9636083 Charset to lowercase before comparing
  • 3edfefe v2.7.6
  • 2154921 v2.7.5
  • 876d9c3 v2.7.4
  • b91e70d Use encoding-japanese for iso-2022-jp by default
  • f15c301 v2.7.3
  • 053d961 v2.7.2
  • 5b1595e fixed issue with non-ending callbacks
  • 08f1739 use Buffer.from(input, 'binary')
  • 633e436 fix(simple-parser): Buffer.from(string) default encode is utf-8,when input string‘s encode is gbk,result has some garbled
  • ceba79f remove space-only name test and patch assumption about flowed module
  • c56a38c Support encoded address lists.
  • 89572e0 fix: error on ks_c_5601-1987
  • faf9fc5 fix: handle simpleParser input stream error
  • 9463fe8 Add option to skip html to text conversion
  • 0d12690 v2.7.1
  • 7cba5bc v2.7.0
  • 4e367f7 fix: capture decoder end event to use on cleanup
  • c4b4d7d Move eslint into devDependencies
  • 403176f fixed invalid license file
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs