flaviuse / mern-authentication

MERN stack authentication boilerplate: password reset, email verification, server sessions, redux, typescript, hooks and docker for dev and prod.
https://mern-auth-client.herokuapp.com/login
MIT License
439 stars 95 forks source link

[Snyk] Upgrade connect-mongo from 4.4.1 to 4.5.0 #89

Closed snyk-bot closed 2 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade connect-mongo from 4.4.1 to 4.5.0.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-1579269
554/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-MPATH-1577289
554/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: connect-mongo
  • 4.5.0 - 2021-08-17

    chore: bump version to 4.5.0 for release

  • 4.4.1 - 2021-03-23

    chore: bump version to 4.4.1

from connect-mongo GitHub release notes
Commit messages
Package name: connect-mongo
  • 3e27376 chore: bump version to 4.5.0 for release
  • fa8826d Merge pull request #430 from jdesboeufs/feat/upgrade-mongodb-depns
  • 472c003 test: ignore test file on code coverage
  • 83480c2 chore: drop node 10 support due to mongodb upgrade
  • 8bdc9e0 docs: update CHANGELOG
  • 788f603 fix: createIndex should have correct async dependency setup
  • ccd716a fix: upgrade mongodb driver to v4
  • cceec18 fix: move writeConcern option away from top-level to remove deprecation warning #422 (#424)
  • 03962f4 docs: Update MIGRATION_V4.md (#421)
  • 9c1d0b5 docs: add known issue
  • 5b1b965 docs: update MIGRATION_V4.md (#417)
  • 94b65f6 docs: add known issue on autoRemove native causing error on close
  • bbff285 docs: migration guide argument correction (#414)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs