koajs / koala

[SEEKING MAINTAINER] An HTTP/2 and ES6 Module-ready Koa Suite
MIT License
320 stars 27 forks source link

[Snyk] Security upgrade koa-qs from 2.0.0 to 3.0.0 #74

Closed snyk-bot closed 3 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Override Protection Bypass
npm:qs:20170213
Yes No Known Exploit
Commit messages
Package name: koa-qs The new version differs by 18 commits.
  • 255df00 3.0.0
  • fdb0cf9 chore: fixpack
  • 8dc4c48 Merge pull request #27 from 3imed-jaberi/add-opts-support
  • 15d4042 update LICENSE ๐Ÿ— ..
  • 7550ca7 update pkg.json ๐ŸŽ— ..
  • 8bafa18 add test for opts support + koa 2 ๐Ÿ’‰ ..
  • 3b4c591 add opts support ๐Ÿง™โ€โ™‚๏ธ ..
  • 07c915b Merge pull request #26 from 3imed-jaberi/3imed-jaberi-update-pkg
  • e22ef88 update README.md --io ๐Ÿ“‹ ..
  • 44a5fa6 update pkg.json ๐ŸŽ— ..
  • 0b788e2 update README.md ๐Ÿ“‹ ..
  • 362b105 update the CI pipeline ๐ŸŽฒ ..
  • 25c767e better code ๐Ÿš€ ..
  • 974540f fix test --pass ๐Ÿงชโœ”๏ธ ..
  • 1b86ba9 add mocha config. โ˜•๏ธ ..
  • 8f7c5f1 avoid generating pkg-lock.json โ˜”๏ธ ..
  • 9195b9a update .gitignore file ๐Ÿž ..
  • bf1225e update travis (#17)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

๐Ÿง View latest project report

๐Ÿ›  Adjust project settings

๐Ÿ“š Read more about Snyk's upgrade and patch logic