lolo32 / fastify-sse

Provide Server-Sent Events to Fastify
20 stars 16 forks source link

[Snyk] Security upgrade fastify from 0.26.2 to 1.1.0 #16

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-FASTIFY-559018
Yes No Known Exploit
Commit messages
Package name: fastify The new version differs by 250 commits.
  • 6a7ceaf Bumped v1.1.0
  • bb2c1bc Store the 404 Context directly on the route Context (#837)
  • 31c5f7e Fix setting header multiple times and add utility methods (fix #834) (#836)
  • 5c29591 Bumped v1.0.0
  • cebe106 Updated benchmarks (#832)
  • 21c65a3 Use separate Fastify instances for route tests (#831)
  • 288903a fix responseTime regression (#827)
  • 88397a5 Update instances of "jsonBodyLimit" to "bodyLimit" (#828)
  • a7de0f9 Small doc fix in Getting-Started.md (#823)
  • f4cd1d2 Future-proof checking Node version (#822)
  • bebddc5 Remove fastify-register-timeout add fastify-elasticsearch (#821)
  • 3b4650f Update dependencies (fixes #789) (#820)
  • a1f5387 Bumped v1.0.0-rc.3
  • 746e307 Header name is case insensitive in the schema definition (#816)
  • 1b5e476 Fix linking to factory function options from Server Methods (#819)
  • f545acc Avoid to log if the log is not set (#776)
  • eb24aa7 Node 4 is no more. (#818)
  • 9cc9f35 Add FastifyInstance::after typescript definition (#814)
  • 93fcef0 Use writeHead instead of setHeader/getHeader. (#813)
  • dd585ba Update standard to the latest version šŸš€ (#796)
  • dab20bd Add support for per-parser body limits (#800)
  • b4db20a Fix FastifyInstance::ready type definition (#802)
  • d514d46 chore(package): update autocannon to version 2.0.0 (#803)
  • 639e01d ci: Improve format of output errors (#809)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

šŸ§ View latest project report

šŸ›  Adjust project settings

šŸ“š Read more about Snyk's upgrade and patch logic

coveralls commented 4 years ago

Coverage Status

Coverage remained the same at 100.0% when pulling 98f3285b89d6b9b765912b9497890d711e0ffa0f on snyk-fix-2a3cf35d2a8ba3ad6048d23998047786 into 42734ba0acdb6d1cc484164a23f33eb87e01fd67 on master.