gs1 / GS1_DigitalLink_Resolver_CE

The GS1 DigitalLink Resolver Community Edition
Apache License 2.0
42 stars 26 forks source link

[Snyk] Security upgrade mssql from 6.3.1 to 7.0.0 #35

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 711/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.8
Command Injection
SNYK-JS-AZUREMSRESTNODEAUTH-1245464
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: mssql The new version differs by 119 commits.
  • 4863573 7.0.0
  • 0b29b48 Update changelog
  • 0504313 Merge pull request #1218 from dhensby/pulls/7/prep
  • 2b30610 FIX Handle new way tedious throws errors for validation
  • a49d945 Bump tedious version
  • 7dd4a18 Merge pull request #1222 from dhensby/pulls/v8-utc
  • 54751bb NEW Add useUTC support to msnodesqlv8 driver
  • 43e44d1 7.0.0-beta.5
  • 6bf055f Update changelog
  • 59c05e2 Merge pull request #1217 from dhensby/pulls/clone-config
  • ef817ed Fix deep cloning of config fixes #1177
  • d2e7182 Merge pull request #1192 from dhensby/pulls/validate-reqs
  • 8a43595 Merge pull request #1211 from TomV/patch-2
  • 23a8875 Make connection vaidation optional
  • 5852b35 Simplify example
  • 273b1b2 Update README.md
  • 9af05e5 NEW Validate msnodesqlv8 requests are healthy by making a request
  • 80ff783 NEW Validate tedious requests are healthy by making a request
  • 9d0105e Merge pull request #1212 from mtriff/6
  • 72bb33e Merge pull request #1213 from mtriff/stream-rows-affected
  • e52dc91 Merge branch 'master' into 6
  • e32a770 Rebase to master
  • 767738b Add detailed error support for msnodesqlv8
  • 85bbb03 Merge branch 'master' into stream-rows-affected
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic