cameri / nostream

A Nostr Relay written in TypeScript
MIT License
741 stars 190 forks source link

[Snyk] Upgrade helmet from 6.0.1 to 6.1.5 #297

Closed cameri closed 1 year ago

cameri commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade helmet from 6.0.1 to 6.1.5.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **6 versions** ahead of your current version. - The recommended version was released **21 days ago**, on 2023-04-11.
Release notes
Package name: helmet
  • 6.1.5 - 2023-04-11

    6.1.5

      </li>
      <li>
        <b>6.1.4</b> - <a href="https://snyk.io/redirect/github/helmetjs/helmet/releases/tag/v6.1.4">2023-04-10</a></br><p>6.1.4</p>
      </li>
      <li>
        <b>6.1.3</b> - <a href="https://snyk.io/redirect/github/helmetjs/helmet/releases/tag/v6.1.3">2023-04-10</a></br><p>6.1.3</p>
      </li>
      <li>
        <b>6.1.2</b> - <a href="https://snyk.io/redirect/github/helmetjs/helmet/releases/tag/v6.1.2">2023-04-09</a></br><p>6.1.2</p>
      </li>
      <li>
        <b>6.1.1</b> - <a href="https://snyk.io/redirect/github/helmetjs/helmet/releases/tag/v6.1.1">2023-04-08</a></br><p>6.1.1</p>
      </li>
      <li>
        <b>6.1.0</b> - <a href="https://snyk.io/redirect/github/helmetjs/helmet/releases/tag/v6.1.0">2023-04-08</a></br><p>6.1.0</p>
      </li>
      <li>
        <b>6.0.1</b> - <a href="https://snyk.io/redirect/github/helmetjs/helmet/releases/tag/v6.0.1">2022-11-29</a></br><p>v6.0.1</p>
      </li>
    </ul>
    from <a href="https://snyk.io/redirect/github/helmetjs/helmet/releases">helmet GitHub release notes</a>


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

socket-security[bot] commented 1 year ago

New dependency changes detected. Learn more about Socket for GitHub ↗︎


👍 No new dependency issues detected in pull request

Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

Pull request alert summary
Issue Status
Install scripts ✅ 0 issues
Native code ✅ 0 issues
Bin script shell injection ✅ 0 issues
Unresolved require ✅ 0 issues
Invalid package.json ✅ 0 issues
HTTP dependency ✅ 0 issues
Git dependency ✅ 0 issues
Potential typo squat ✅ 0 issues
Known Malware ✅ 0 issues
Telemetry ✅ 0 issues
Protestware/Troll package ✅ 0 issues

📊 Modified Dependency Overview:

⬆️ Updated Package Version Diff Added Capability Access +/- Transitive Count Publisher
helmet@6.1.5 6.0.1...6.1.5 None +0/-0 evanhahn
sonarcloud[bot] commented 1 year ago

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information