cnpm / cnpmjs.org

‼️ ‼️ ‼️ ‼️ DEPRECATED, please use https://github.com/cnpm/cnpmcore ‼️ ‼️ ‼️ ‼️
https://npmmirror.com
Other
3.55k stars 748 forks source link

[Snyk] Security upgrade sequelize from 3.35.1 to 4.0.0 #1753

Closed snyk-bot closed 1 month ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-DOTTIE-3332763
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: sequelize The new version differs by 250 commits.
  • d960cf1 4.0.0
  • 8a4b529 docs: more resource link + fix incorrect changelog link
  • 411f89e New stable
  • a270d23 Docs: Added v3 to v4 migration guide (#7740)
  • fdf95dd fixed #7735, sqlite memory url no longer works (#7736)
  • b7ca3c4 docs: pretty color + reference theme
  • 2651f98 docs: update theme + changelog + logo
  • bfee712 fix: pooling fails to handle disconnection (#7698)
  • 41408df added: npm run sscce support
  • 567c3e5 Add relative and full path support for sqlite (#7700)
  • 6a84ba8 Amplify docs for "import" instruction (#7695)
  • 2934278 Closes #7709 [ci skip]
  • 4392201 #7184 Regression in affected rows reporting for updates (#7423)
  • 13a3f1e Fix documentation of include.paranoid (#7672)
  • b0bd5d0 [ci skip] git ignore package-lock.json
  • e2e0d82 Fix #7680 unreachable code in postgres query error handling (#7692)
  • 19e7659 Fix deadlock issue (#7659)
  • 5369231 fix: failing lint check
  • 787f3b3 Add `isSoftDeleted` helper method to model instances (#7531)
  • f7a6d3d Remove unused `err` variable on getting started (#7652)
  • 51c2509 Fix changelog [ci-skip]
  • fbe47d1 [MSSQL] Format isolation level as tedious isolation level (#7297)
  • 7ab3ba4 Update README.md link (#7642)
  • 02ea09c Add arrow-parens rule to ESLint (#7639)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

socket-security[bot] commented 1 year ago

New and updated dependency changes detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives^1 Size Publisher
sequelize ⬆️ 3.35.1...4.44.4 None +9/-6 5.38 MB sushantdhiman