TreeGateway / tree-gateway

This is a full featured and free API Gateway
http://treegateway.com
MIT License
189 stars 42 forks source link

[Snyk] Security upgrade typescript-rest-swagger from 0.0.12 to 1.1.2 #190

Open thiagobustamante opened 3 years ago

thiagobustamante commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 758/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-MERGE-1042987
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: typescript-rest-swagger The new version differs by 141 commits.
  • 9444142 new version
  • 70f7968 Merge pull request #125 from thiagobustamante/dependabot/npm_and_yarn/lodash-4.17.19
  • 6cc5b44 Merge pull request #124 from alexandreMelloTW/updating-dependencies
  • 470115a Bump lodash from 4.17.15 to 4.17.19
  • ab66e5b Merge pull request #123 from TeselaGen/master
  • 89e360f updating minimist
  • 581f5cb updating ts-jest@26.1.0
  • 105ab09 updating swagger2openapi@6.0.3
  • 1ce12bf updating jest@26.0.1
  • 6b01c04 updating mocha@8.0.1
  • 7a24c24 updating mkdirp@1.0.4
  • 529e8b5 adding a more helpful error message when a type isn't found
  • 40cca2b Merge pull request #1 from thiagobustamante/master
  • 3a47f3c Merge pull request #108 from oranoran/fix/devDependencies
  • 83ff9e1 Moved all dependencies to devDependencies to avoid dependency creep
  • cc10432 fix travis
  • ce35c40 fix release
  • c591024 fix travis deploy
  • a956a13 Merge branch 'master' of https://github.com/thiagobustamante/typescript-rest-swagger
  • c2024a1 support union types
  • 5dc6731 Merge pull request #101 from thiagobustamante/dependabot/npm_and_yarn/handlebars-4.5.3
  • e474eeb Merge pull request #85 from thiagobustamante/dependabot/npm_and_yarn/diff-3.5.0
  • f3e513f Merge pull request #86 from JulienSergent/hotfix/keep-module-typescript-rest
  • 96b5fa9 Merge pull request #88 from Insalien/add-consumes-decorator
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic