TreeGateway / tree-gateway

This is a full featured and free API Gateway
http://treegateway.com
MIT License
189 stars 42 forks source link

[Snyk] Fix for 1 vulnerabilities #203

Open thiagobustamante opened 9 months ago

thiagobustamante commented 9 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Missing Release of Resource after Effective Lifetime
[SNYK-JS-INFLIGHT-6095116](https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: fs-extra-promise The new version differs by 8 commits.
  • 3653162 v1.0.0
  • 680a61e Fix: Do not promisify `createWriteStream` method
  • fd7a138 Refactor to ES6 + code style
  • c9603ea Update license
  • 1b81b6b Drop support for Node versions before 4.0
  • 40c01a8 Update `bluebird` dependency to v3.5.0
  • ca0be2b Update `fs-extra` dependency to v2.1.2
  • 52cca00 Skip Travis CI runs on release tags
See the full diff
Package name: typescript-ioc The new version differs by 25 commits.
See the full diff
Package name: typescript-rest The new version differs by 136 commits.
  • 398e159 fix pipeline
  • 3fa54c9 remove travis
  • 076195b update CI/CD tool
  • d93081f updating dependencies
  • 70a2716 Merge pull request #144 from mr-short/patch-1
  • af159a1 update dependencies
  • 6e6e09c Merge pull request #148 from mr-short/multiple-security-decorators
  • 1dbae06 Multiple security decorators
  • 78b8c48 ServiceAuthenticator getRoles: add response param
  • 7215bff Authenticator getRoles: add response param
  • bc1491d new version
  • fbc53ae new version
  • fc22a52 Merge pull request #141 from abhisekp/fix-null-return
  • c3a14b9 Merge pull request #143 from thiagobustamante/snyk-fix-ffa9b8c068604dd0964148211857f5df
  • 3a7812a Merge pull request #142 from msieurtoph/patch-1
  • 4f48f43 fix: package.json & package-lock.json to reduce vulnerabilities
  • 70582d7 Wait for the reponse from async methods before executing postProcessors
  • f6284c7 fix(service): Fix service invoker null return
  • b976126 readme file
  • 247edc8 Fix serviceFactory
  • 3bddb02 remove tyoescript-ioc dependency
  • e3b45df allow access the server router
  • 6d43e26 add new immutable method
  • 976bd27 fix travis deploy
See the full diff
Package name: typescript-rest-swagger The new version differs by 141 commits.
  • 9444142 new version
  • 70f7968 Merge pull request #125 from thiagobustamante/dependabot/npm_and_yarn/lodash-4.17.19
  • 6cc5b44 Merge pull request #124 from alexandreMelloTW/updating-dependencies
  • 470115a Bump lodash from 4.17.15 to 4.17.19
  • ab66e5b Merge pull request #123 from TeselaGen/master
  • 89e360f updating minimist
  • 581f5cb updating ts-jest@26.1.0
  • 105ab09 updating swagger2openapi@6.0.3
  • 1ce12bf updating jest@26.0.1
  • 6b01c04 updating mocha@8.0.1
  • 7a24c24 updating mkdirp@1.0.4
  • 529e8b5 adding a more helpful error message when a type isn't found
  • 40cca2b Merge pull request #1 from thiagobustamante/master
  • 3a47f3c Merge pull request #108 from oranoran/fix/devDependencies
  • 83ff9e1 Moved all dependencies to devDependencies to avoid dependency creep
  • cc10432 fix travis
  • ce35c40 fix release
  • c591024 fix travis deploy
  • a956a13 Merge branch 'master' of https://github.com/thiagobustamante/typescript-rest-swagger
  • c2024a1 support union types
  • 5dc6731 Merge pull request #101 from thiagobustamante/dependabot/npm_and_yarn/handlebars-4.5.3
  • e474eeb Merge pull request #85 from thiagobustamante/dependabot/npm_and_yarn/diff-3.5.0
  • f3e513f Merge pull request #86 from JulienSergent/hotfix/keep-module-typescript-rest
  • 96b5fa9 Merge pull request #88 from Insalien/add-consumes-decorator
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/thiagobustamante/project/e3c97800-99d3-48c9-ac62-e736db808b2a?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/thiagobustamante/project/e3c97800-99d3-48c9-ac62-e736db808b2a?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"0c53a2db-d46f-4318-bfa8-3638f736774e","prPublicId":"0c53a2db-d46f-4318-bfa8-3638f736774e","dependencies":[{"name":"fs-extra-promise","from":"0.4.1","to":"1.0.0"},{"name":"typescript-ioc","from":"1.2.6","to":"3.0.0"},{"name":"typescript-rest","from":"1.8.1","to":"3.0.3"},{"name":"typescript-rest-swagger","from":"0.0.12","to":"1.1.2"}],"packageManager":"npm","projectPublicId":"e3c97800-99d3-48c9-ac62-e736db808b2a","projectUrl":"https://app.snyk.io/org/thiagobustamante/project/e3c97800-99d3-48c9-ac62-e736db808b2a?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-INFLIGHT-6095116"],"upgrade":["SNYK-JS-INFLIGHT-6095116"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[661],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc=fix-pr)