ecronix / react-most-wanted

React starter kit with "Most Wanted" application features
https://www.react-most-wanted.com/
MIT License
2.43k stars 459 forks source link

[Snyk] Upgrade firebase-admin from 10.0.0 to 10.3.0 #411

Closed TarikHuber closed 2 years ago

TarikHuber commented 2 years ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade firebase-admin from 10.0.0 to 10.3.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **5 versions** ahead of your current version. - The recommended version was released **3 months ago**, on 2022-06-09. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Denial of Service (DoS)
[SNYK-JS-DICER-2311764](https://snyk.io/vuln/SNYK-JS-DICER-2311764) | **546/1000**
**Why?** Mature exploit, CVSS 7.5 | Mature (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: firebase-admin
  • 10.3.0 - 2022-06-09

    Bug Fixes

    • fix: Add type declarations to exports fields (#1758)
    • fix: Switch to @ fastify/busboy (#1757)

    Miscellaneous

    • [chore] Release 10.3.0 (#1759)
    • build(deps): bump jwks-rsa from 2.1.0 to 2.1.4 (#1747)
    • build(deps-dev): bump @ microsoft/api-extractor from 7.24.2 to 7.25.0 (#1750)
    • build(deps-dev): bump @ firebase/app-compat from 0.1.25 to 0.1.26 (#1746)
    • build(deps-dev): bump @ typescript-eslint/parser from 5.25.0 to 5.27.1 (#1751)
    • build(deps-dev): bump ts-node from 10.8.0 to 10.8.1 (#1749)
    • build(deps): bump @ types/node from 17.0.38 to 17.0.41 (#1748)
    • build(deps-dev): bump eslint from 8.16.0 to 8.17.0 (#1745)
    • build(deps-dev): bump nock from 13.2.4 to 13.2.6 (#1744)
    • build(deps-dev): bump @ typescript-eslint/eslint-plugin (#1743)
    • build(deps-dev): bump @ firebase/auth-compat from 0.2.14 to 0.2.15 (#1735)
    • build(deps-dev): bump ts-node from 10.7.0 to 10.8.0 (#1737)
    • build(deps): bump @ types/node from 17.0.35 to 17.0.38 (#1736)
    • build(deps-dev): bump @ microsoft/api-extractor from 7.24.1 to 7.24.2 (#1734)
    • build(deps-dev): bump @ types/lodash from 4.14.178 to 4.14.182 (#1731)
    • build(deps-dev): bump del from 6.1.0 to 6.1.1 (#1725)
    • build(deps): bump @ types/node from 17.0.34 to 17.0.35 (#1720)
    • build(deps-dev): bump @ microsoft/api-extractor from 7.24.0 to 7.24.1 (#1721)
    • build(deps-dev): bump eslint from 8.15.0 to 8.16.0 (#1722)
    • build(deps-dev): bump @ typescript-eslint/eslint-plugin (#1719)
    • chore: Run nightly builds on Node 14 (#1717)
    • build(deps): bump @ types/node from 17.0.33 to 17.0.34 (#1716)
    • build(deps-dev): bump @ typescript-eslint/eslint-plugin (#1715)
    • build(deps-dev): bump @ microsoft/api-extractor from 7.23.2 to 7.24.0 (#1714)
    • build(deps-dev): bump yargs from 17.3.1 to 17.5.1 (#1711)
    • build(deps-dev): bump @ typescript-eslint/parser from 5.23.0 to 5.25.0 (#1713)
    • build(deps-dev): bump @ firebase/app-compat from 0.1.19 to 0.1.25 (#1709)
    • build(deps-dev): bump del from 6.0.0 to 6.1.0 (#1708)
    • build(deps): bump @ firebase/database-compat from 0.1.8 to 0.2.0 (#1706)
    • build(deps-dev): bump eslint from 8.14.0 to 8.15.0 (#1702)
    • build(deps-dev): bump @ firebase/auth-compat from 0.2.8 to 0.2.14 (#1701)
    • build(deps): bump @ types/node from 17.0.10 to 17.0.33 (#1700)
    • build(deps): bump @ firebase/database-types from 0.9.7 to 0.9.8 (#1699)
    • build(deps-dev): bump @ typescript-eslint/eslint-plugin (#1705)
    • build(deps-dev): bump @ microsoft/api-extractor from 7.19.4 to 7.23.2 (#1698)
    • build(deps-dev): bump @ types/chai-as-promised from 7.1.4 to 7.1.5 (#1697)
    • build(deps-dev): bump @ typescript-eslint/eslint-plugin (#1696)
    • build(deps-dev): bump @ typescript-eslint/parser from 5.12.0 to 5.23.0 (#1695)
    • build(deps-dev): bump sinon from 13.0.2 to 14.0.0 (#1692)
    • build(deps-dev): bump nock from 13.2.2 to 13.2.4 (#1691)
    • build(deps-dev): bump ts-node from 10.5.0 to 10.7.0 (#1690)
    • build(deps-dev): bump chai from 4.3.4 to 4.3.6 (#1689)
  • 10.2.0 - 2022-05-05
    Read more
  • 10.1.0 - 2022-04-21
    Read more
  • 10.0.2 - 2022-01-21
    Read more
  • 10.0.1 - 2021-12-15

    Bug Fixes

    • fix(firestore): Expose more types from gcp firestore
    • fix(auth): Add user disabled error code. (#1506)
    • fix(auth): Remove request body for deleteTenant (#1461)

    Miscellaneous

    • [chore] Release 10.0.1 (#1520)
    • Add new Firestore types exposed from the admin firestore module (#1519)
    • Update base-auth.ts (#1501)
    • Update multi-tenancy integration tests to run against auth emulator (#1453)
    • build(deps-dev): bump mocha from 8.4.0 to 9.1.2 (#1440)
    • build(deps): bump @ types/node from 16.10.2 to 16.11.0 (#1464)
    • build(deps-dev): bump @ types/mocha from 8.2.2 to 9.0.0 (#1397)
  • 10.0.0 - 2021-10-14
    Read more
from firebase-admin GitHub release notes

**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/tarikhuber/project/dc918ec1-2ad3-4c22-8030-ca28137b7d3c?utm_source=github&utm_medium=referral&page=upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/tarikhuber/project/dc918ec1-2ad3-4c22-8030-ca28137b7d3c/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/tarikhuber/project/dc918ec1-2ad3-4c22-8030-ca28137b7d3c/settings/integration?pkg=firebase-admin&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)