derhuerst / vbb-rest

An HTTP API for Berlin & Brandenburg public transport.
https://v6.vbb.transport.rest/
ISC License
130 stars 12 forks source link

[Snyk] Security upgrade hafas-rest-api from 3.7.0 to 4.0.0 #49

Closed snyk-bot closed 1 year ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKDOWNIT-2331914
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: hafas-rest-api The new version differs by 4 commits.
  • 4b65116 tests: use app's user-agent āœ…; 4.0.0
  • ce266cf /stops/nearby -> /locations/nearby šŸ’„āœ…
  • 4e5907e VBB example: add caching via cached-hafas-client šŸ“
  • d517887 upgrade deps & dev deps; Node 16+ šŸ’„
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: šŸ§ View latest project report

šŸ›  Adjust project settings

šŸ“š Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

šŸ¦‰ Learn about vulnerability in an interactive lesson of Snyk Learn.

derhuerst commented 1 year ago

Fixed as of ebb6125c2da424aba43d09c54fe60b8832930af4.