lolo32 / fastify-sse

Provide Server-Sent Events to Fastify
20 stars 16 forks source link

[Snyk] Security upgrade fastify from 0.26.2 to 0.39.0 #20

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-AJV-584908
No No Known Exploit
Commit messages
Package name: fastify The new version differs by 250 commits.
  • 069653f Bumped v0.39.0.
  • 5cbbeee Bumped v0.38.1.
  • 43d7a97 Merge pull request #645 from nwoltman/fix-595-response-hanging
  • 5845916 Check the payload in tests
  • edf1225 Merge pull request #647 from jpagarcia/patch-1
  • 7b9af89 Merge pull request #648 from fastify/streams-1
  • eddc4c5 Removed readable === true check for streams.
  • 70354af Added support for streams1 in reply.send()
  • b016b4b Update Getting-Started.md
  • 9c619f6 Fix 595 and a bug when sending an Error object
  • 6c23c92 Merge pull request #641 from fastify/update-lifecycle-after-639
  • 84773d4 Update Lifecycle.md
  • d3cbf0f Merge pull request #639 from fastify/plugin-log-level
  • 26513e8 Test the logs for default 404 handler
  • f6c49a9 Merge pull request #633 from fastify/greenkeeper/ajv-6.0.0
  • dbcce8d Merge pull request #640 from fastify/doc-fix
  • f1064b7 Fix decorateRequest example
  • a7888ef Updated docs
  • 6097d4b Updated test
  • 2f2c9a6 Added custom logLevel support
  • c3a8047 Merge pull request #637 from nwoltman/improve-logging
  • d251913 Improve how stream errors are logged
  • 629c16c Bumped v0.38.0
  • e68e477 Merge pull request #632 from fastify/update-light-my-request
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

coveralls commented 4 years ago

Coverage Status

Coverage remained the same at 100.0% when pulling 4c78c2b848fefe9ffc081ec564339f033fc43eeb on snyk-fix-5f3fef557b32b5ba5d9c91c195d313e9 into 42734ba0acdb6d1cc484164a23f33eb87e01fd67 on master.