beyerleinf / esbuild-azure-functions

A ✨blazingly fast✨ builder for Azure Functions powered by esbuild.
MIT License
12 stars 2 forks source link

[Snyk] Security upgrade zod from 3.20.2 to 3.22.3 #24

Open beyerleinf opened 1 year ago

beyerleinf commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **768/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-ZOD-5925617](https://snyk.io/vuln/SNYK-JS-ZOD-5925617) | No | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: zod The new version differs by 247 commits.
  • 1e61d76 3.22.3
  • 2ba00fe [2609] fix ReDoS vulnerability in email regex (#2824)
  • ae0f7a2 docs: update ref to discriminated-unions docs (#2485)
  • ad2ee9c 2718 Updated Custom Schemas documentation example to use type narrowing (#2778)
  • 28c1927 Update sponsors
  • 18115a8 Formatting
  • 64dcc8e Update sponsors
  • f59be09 clarify datetime ISO 8601 (#2673)
  • 9bd3879 docs: remove obsolete text about readonly types (#2676)
  • 1e23990 Commit
  • 792b3ef Fix superrefine types
  • 8e4af7b X to Zod: add app.quicktype.io (#2668)
  • 0d49f10 docs: add typeschema to ecosystem (#2626)
  • 13d9e6b Fix lint
  • 0a055e7 3.22.1
  • 932cc47 Initial prototype fix for issue #2651 (#2652)
  • fba438c 3.22.0
  • 981d4b5 Add ZodReadonly (#2634)
  • 1ecd624 Fix prettier
  • 78a4090 docs: update comparison with `runtypes` (#2536)
  • 81a89f5 Update nullish documentation to correct chaining order (#2457)
  • 6aab901 fix typo test name (#2542)
  • 8b8ab3e Update README.md (#2562)
  • 5adae24 docs: add conform form integration (#2577)
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/beyerleinf/project/b5213ce3-ebd8-468b-aa44-a9b582b03468?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/beyerleinf/project/b5213ce3-ebd8-468b-aa44-a9b582b03468?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"51276f3a-465a-43ef-a81f-774dd25ccf5f","prPublicId":"51276f3a-465a-43ef-a81f-774dd25ccf5f","dependencies":[{"name":"zod","from":"3.20.2","to":"3.22.3"}],"packageManager":"npm","projectPublicId":"b5213ce3-ebd8-468b-aa44-a9b582b03468","projectUrl":"https://app.snyk.io/org/beyerleinf/project/b5213ce3-ebd8-468b-aa44-a9b582b03468?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-ZOD-5925617"],"upgrade":["SNYK-JS-ZOD-5925617"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[768],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr)
codecov-commenter commented 1 year ago

Codecov Report

All modified lines are covered by tests :white_check_mark:

Comparison is base (19a8d76) 100.00% compared to head (1729339) 100.00%.

Additional details and impacted files ```diff @@ Coverage Diff @@ ## main #24 +/- ## ========================================= Coverage 100.00% 100.00% ========================================= Files 20 20 Lines 554 554 Branches 60 60 ========================================= Hits 554 554 ```

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.