brunobotelhobr / My-Sample-API

This is an Node API application with several vulenrabilities.
Other
3 stars 18 forks source link

[Snyk] Upgrade swagger-ui-express from 4.1.4 to 4.6.0 #27

Closed brunobotelhobr closed 1 year ago

brunobotelhobr commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade swagger-ui-express from 4.1.4 to 4.6.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **7 versions** ahead of your current version. - The recommended version was released **2 months ago**, on 2022-11-07. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | User Interface (UI) Misrepresentation of Critical Information
[SNYK-JS-SWAGGERUIDIST-2314884](https://snyk.io/vuln/SNYK-JS-SWAGGERUIDIST-2314884) | **484/1000**
**Why?** Has a fix available, CVSS 5.4 | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: swagger-ui-express
  • 4.6.0 - 2022-11-07

    Accept array of external JS/CSS assets

      </li>
      <li>
        <b>4.5.0</b> - <a href="https://snyk.io/redirect/github/scottie1984/swagger-ui-express/releases/tag/4.5.0">2022-07-13</a></br>No content.
      </li>
      <li>
        <b>4.4.0</b> - <a href="https://snyk.io/redirect/github/scottie1984/swagger-ui-express/releases/tag/4.4.0">2022-05-13</a></br><p><a href="https://snyk.io/redirect/github/scottie1984/swagger-ui-express/releases/tag/4.4.0">4.4.0</a></p>
      </li>
      <li>
        <b>4.3.0</b> - <a href="https://snyk.io/redirect/github/scottie1984/swagger-ui-express/releases/tag/4.3.0">2021-12-16</a></br>No content.
      </li>
      <li>
        <b>4.2.0</b> - <a href="https://snyk.io/redirect/github/scottie1984/swagger-ui-express/releases/tag/4.2.0">2021-12-01</a></br>No content.
      </li>
      <li>
        <b>4.1.6</b> - <a href="https://snyk.io/redirect/github/scottie1984/swagger-ui-express/releases/tag/4.1.6">2020-12-22</a></br><p>Multiple version example</p>
      </li>
      <li>
        <b>4.1.5</b> - <a href="https://snyk.io/redirect/github/scottie1984/swagger-ui-express/releases/tag/4.1.5">2020-11-19</a></br><p>4.1.5</p>
      </li>
      <li>
        <b>4.1.4</b> - <a href="https://snyk.io/redirect/github/scottie1984/swagger-ui-express/releases/tag/4.1.4">2020-03-21</a></br><p>No longer leak package.json</p>
      </li>
    </ul>
    from <a href="https://snyk.io/redirect/github/scottie1984/swagger-ui-express/releases">swagger-ui-express GitHub release notes</a>

Commit messages
Package name: swagger-ui-express
  • 24381a0 Bump version
  • 53c0fb4 Merge pull request #319 from Luku1806/feature/multiple-script-imports
  • 79ee9c7 Allow multiple external and inline Javascript imports as well as multiple external CSS
  • add0b6b Bump version of package
  • cd3fda6 Merge pull request #298 from kleinod21/master
  • d3f182a Url checking improved
  • 6f4d460 Bump package version
  • ec32130 fix dynamic loading for serveFiles and added customJsStr
  • 8cc6416 Extra check of trim query
  • 002178a Merge pull request #280 from dukvanduken/bugfix/req-path-query-trim
  • 89904f7 Merge pull request #294 from Edalbrelord/master
  • abc34ea Update swagger-ui-dist version to fix issue with oAuthRedirectUrl
  • fbe5c6f Trim req.url from query params
  • 512970a bump version of swagger-ui-dist due to security update
  • aa3d56a Bumped version of swagger-ui-dist and moved js template usage
  • ff10df4 Update README.md
  • fe789d8 Update README.md
  • d07439b Merge pull request #270 from jdgarcia/security-update
  • 9011cdf Merge pull request #269 from artyhedgehog/patch-1
  • e09c35f update swagger-ui-dist dependency to fix security vulnerabilities
  • de8e7eb readme: fix broken link to swagger-jsdoc
  • 5824af0 Merge pull request #236 from H3nSte1n/feature/Add_converage_section_to_readme
  • da7b5ff feat: Remove Coverage headline from README
  • b46e892 feat: Add coverage section to README
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs