codingfriend1 / Feathers-Vue

A boiler plate template using Feathers with Email Verification, Vue 2 with Server Side Rendering, stylus, scss, jade, babel, webpack, ES 6-8, login form, user authorization, and SEO
MIT License
197 stars 48 forks source link

[Snyk] Security upgrade feathers-hooks-common from 3.10.0 to 4.8.0 #24

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-AJV-584908
Yes No Known Exploit
Commit messages
Package name: feathers-hooks-common The new version differs by 138 commits.
  • 398eb77 4.8.0
  • 205dfb5 Renamed act-on.js to act-on-dispatch.js so docs work better.
  • cbc07be Merge branch 'master' of https://github.com/feathers-plus/feathers-hooks-common
  • 90b54c2 Added skipRemainingHook, actOnDispatch, actOnDefault
  • 06e52f8 Merge pull request #363 from beeplin/patch-2
  • 904d6fe allow mongoKeys running for all methods
  • 63c912d Updated depenendencies
  • b8fb47e Merge pull request #362 from beeplin/patch-1
  • 9c3be6d Allow `mongoKeys` for update/patch/remove
  • 8744d42 Updating changelog
  • 63a30bc 4.7.0
  • 157ab4e 4.6.0
  • 7895aed Merge pull request #357 from feathers-plus/license
  • eb12c7b Changed license to MIT
  • 3267b8e Updating changelog
  • 3fb69bf 4.5.6
  • 5f1509a Merge pull request #356 from feathers-plus/mongoKeys-02
  • f0a6957 Fixed issue with mongoKeys and .
  • 24a9538 Updating changelog
  • 7bf5342 4.5.5
  • 697ed4f Merge pull request #354 from feathers-plus/alter-items-03
  • 78916d9 Refactored alterItems to remove unneeded code.
  • 0939580 Updating changelog
  • 503bd05 4.5.4
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic