cameri / nostream

A Nostr Relay written in TypeScript
MIT License
715 stars 185 forks source link

[Snyk] Upgrade joi from 17.7.0 to 17.9.1 #288

Closed snyk-bot closed 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to upgrade joi from 17.7.0 to 17.9.1.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


Release notes
Package name: joi from joi GitHub release notes
Commit messages
Package name: joi
  • cc11f8d 17.9.1
  • 99cf8eb Merge pull request #2932 from hapijs/fix/warnings-externals-mismatches
  • e64375a fix: do not trigger warnings and externals on arrays and alternatives mismatches
  • 0fdab3a 17.9.0
  • 7b24729 Merge pull request #2931 from hapijs/feat/external-helpers
  • e52a362 feat: improve external helpers
  • c191b99 17.8.4
  • ab91092 Merge pull request #2928 from hapijs/fix/validation-warning-types
  • 6b530c8 fix: validation warning types
  • 227e761 Merge pull request #2923 from hapijs/chore/docs
  • b0d8df8 chore: fix wrong usage of Joi.expression
  • ff3e5fc 17.8.3
  • ade2748 Merge pull request #2919 from hapijs/chore/revert-17.8
  • 09cbaaa chore: revert 17.8.x line
  • 04751f1 17.8.2
  • d49e029 Merge pull request #2916 from hapijs/fix/email-options
  • 245e0c9 fix: properly transform domain
  • cc88b68 17.8.1
  • 67b0923 Merge pull request #2910 from hapijs/fix/optional-chaining
  • 5036947 fix: transpile optional chaining
  • 79a2af4 17.8.0
  • 2998d86 Merge pull request #2909 from hapijs/chore/bump-address
  • 286dc6d chore: use latest address module
  • f8fab8c Merge pull request #2908 from madhavappaneni/patch-1
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

socket-security[bot] commented 1 year ago

New dependency changes detected. Learn more about Socket for GitHub ↗︎


👍 No new dependency issues detected in pull request

Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

Pull request alert summary
Issue Status
Install scripts ✅ 0 issues
Native code ✅ 0 issues
Bin script shell injection ✅ 0 issues
Unresolved require ✅ 0 issues
Invalid package.json ✅ 0 issues
HTTP dependency ✅ 0 issues
Git dependency ✅ 0 issues
Potential typo squat ✅ 0 issues
Known Malware ✅ 0 issues
Telemetry ✅ 0 issues
Protestware/Troll package ✅ 0 issues

📊 Modified Dependency Overview:

⬆️ Updated Package Version Diff Added Capability Access +/- Transitive Count Publisher
joi@17.9.1 17.7.0...17.9.1 None +0/-0 marsup
coveralls commented 1 year ago

Pull Request Test Coverage Report for Build 4770413726


Files with Coverage Reduction New Missed Lines %
src/adapters/web-socket-adapter.ts 2 53.76%
src/adapters/web-socket-server-adapter.ts 4 67.16%
<!-- Total: 6 -->
Totals Coverage Status
Change from base Build 4769551383: -0.2%
Covered Lines: 1212
Relevant Lines: 2136

💛 - Coveralls
sonarcloud[bot] commented 1 year ago

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information