Rubix982 / Reflex

An MVP-ish LMS for Attendance Systems.
https://bit.ly/3xoEx92
Apache License 2.0
1 stars 0 forks source link

Bump mongoose from 5.12.12 to 5.13.15 in /server #71

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps mongoose from 5.12.12 to 5.13.15.

Changelog

Sourced from mongoose's changelog.

5.13.15 / 2022-08-22

6.5.2 / 2022-08-09

  • fix(aggregate): avoid throwing error when disconnecting with change stream open #12201 ramos-ph
  • fix(query): overwrite top-level key if using Query.prototype.set() to set to undefined #12155
  • fix(query): shallow clone options before modifying #12176
  • fix(types): auto schema type inference on Connection.prototype.model() #12240 hasezoey
  • fix(types): better typescript support for schema plugins #12139 emiljanitzek
  • fix(types): make bulkWrite() type param optional #12221 #12212
  • docs: misc cleanup #12199 hasezoey
  • docs: highlight current top-most visible header in navbar #12222 hasezoey
  • docs(populate): improve examples for Document.prototype.populate() #12111
  • docs(middleware): clarify document vs model in middleware docs #12113

6.5.1 / 2022-08-03

  • fix(timestamps): set timestamps on child schema when child schema has timestamps: true but parent schema does not #12119
  • fix(schema+timestamps): handle insertMany() with timestamps and discriminators #12150
  • fix(model+query): handle populate with lean transform that deletes _id #12143
  • fix(types): allow $pull with _id #12142
  • fix(types): add schema plugin option inference #12196 hasezoey
  • fix(types): pass type to mongodb bulk write operation #12167 emiljanitzek
  • fix(types): map correct generics from model to schema #12125 emiljanitzek
  • fix(types): avoid baffling circular reference when using PopulatedDoc with a bidirectional reference #12136
  • fix(types): allow using path with $count #12149
  • docs(compatibility): change to use a table #12200 hasezoey
  • docs(api_split.pug): add "code" to sidebar entries #12153 hasezoey
  • docs: add "code" to Headers (and index list) #12152 hasezoey

6.5.0 / 2022-07-26

  • perf(document): avoid creating unnecessary empty objects when creating a state machine #11988
  • feat: upgrade mongodb driver -> 4.8.1 #12103 AbdelrahmanHafez
  • feat(model): allow passing timestamps option to Model.bulkSave(...) #12082 AbdelrahmanHafez
  • feat(model): add castObject() function that casts a POJO to the model's schema #11945
  • feat(document): add $inc() helper that increments numeric paths #12115
  • feat(schema): add schema level lean option IslandRhythms
  • feat(schema): add global id option to disable id on schemas #12067 IslandRhythms
  • fix(connection): re-run Model.init() if re-connecting after explicitly closing a connection #12130
  • feat(model): add applyDefaults() helper that allows applying defaults to document or POJO #11945
  • feat(model): allow calling hydrate() with { setters: true } #11653
  • feat(model): add hydrate option to Model.watch() to automatically hydrate fullDocument #12121
  • feat(types): add support for automatically typed virtuals in schemas #11908 mohammad0-0ahmad

6.4.7 / 2022-07-25

... (truncated)

Commits
  • ca7996b chore: release 5.13.15
  • e75732a Merge pull request #12307 from Automattic/vkarpov15/fix-5x-build
  • a1144dc test: run node 7 tests with upgraded npm re: #12297
  • dfc4ad7 test: try upgrading npm for node v4 tests re: #12297
  • b9e985c test: more strict @​types/node version
  • 4d813fa test: fix @​types/node version in tests re: #12297
  • 99b4189 Merge pull request #12297 from shubanker/issue/prototype-pollution-5.x-patch
  • 5eb11dd made function non async
  • 6a19731 fix(schema): disallow setting proto when creating schema with dotted prop...
  • a2ec28d Merge pull request #11366 from laissonsilveira/5.x
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Rubix982/Reflex/network/alerts).
guardrails[bot] commented 1 year ago

:warning: We detected 16 security issues in this pull request:

Vulnerable Libraries (16)
Severity | Details ----- | -------- High | [pkg:npm/minimatch@3.0.4@3.0.4](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) upgrade to: *3.0.5* High | [pkg:npm/tar@6.1.0@6.1.0](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) upgrade to: *4.4.18,5.0.10,6.1.9* High | [pkg:npm/ansi-regex@5.0.0@5.0.0](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) upgrade to: *6.0.1,5.0.1,4.1.1,3.0.1* Medium | [pkg:npm/mysql2@2.2.5@2.2.5](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) - **no patch available** Low | [pkg:npm/node-fetch@2.6.1@2.6.1](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) - **no patch available** Critical | [pkg:npm/mongoose@5.13.15@5.13.15](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) - **no patch available** N/A | [pkg:npm/node-forge@0.10.0@0.10.0](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) upgrade to: *1.0.0* High | [pkg:npm/ansi-regex@4.1.0@4.1.0](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) upgrade to: *6.0.1,5.0.1,4.1.1,3.0.1* Medium | [pkg:npm/got@9.6.0@9.6.0](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) - **no patch available** Critical | [pkg:npm/jsonwebtoken@8.5.1@8.5.1](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) - **no patch available** Critical | [pkg:npm/qs@6.7.0@6.7.0](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) - **no patch available** Low | [pkg:npm/bcrypt@5.0.1@5.0.1](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) - **no patch available** Critical | [pkg:npm/minimist@1.2.5@1.2.5](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) upgrade to: *1.2.6* Critical | [pkg:npm/nodemon@2.0.7@2.0.7](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) - **no patch available** N/A | [pkg:npm/debug@2.6.9@2.6.9](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) upgrade to: *3.1.0* Critical | [pkg:npm/express@4.17.1@4.17.1](https://github.com/Rubix982/Reflex/blob/e3fa71eb473ee69eed0120e93447e7dc7f981328/server/package-lock.json) (t) - **no patch available** More info on how to fix Vulnerable Libraries in [JavaScript](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/using_vulnerable_libraries.html?utm_source=ghpr#).

👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.