losol / converto

GNU General Public License v3.0
5 stars 1 forks source link

[Snyk] Security upgrade @strapi/strapi from 4.11.7 to 4.12.0 #54

Closed losolio closed 1 year ago

losolio commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **696/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.5 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-SEMVER-3247795](https://snyk.io/vuln/SNYK-JS-SEMVER-3247795) | No | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @strapi/strapi The new version differs by 250 commits.
  • 7f8109a v4.12.0
  • dbcf405 Revert "admin lastname defaults to undefined"
  • f36e925 Merge pull request #17294 from strapi/review-workflow-multiple/amplitude-be
  • 3e91c73 Merge pull request #17426 from strapi/fix/bulk-publish-v2-change-published-label
  • af8eab8 Merge pull request #17431 from strapi/fix/bulk-publish-v2-remove-sorting
  • 42d3fdd Merge pull request #17371 from strapi/fix/16340-transfer-k8s-pv
  • be0f05f Merge pull request #17423 from strapi/fix/bulk-publish-v2-edit-icon-on-the-right
  • a47b111 fix the HeaderCell sortable icon bug
  • 3482c94 change id
  • 9b177cc Merge pull request #17417 from strapi/dependabot/npm_and_yarn/aws-sdk-2.1420.0
  • 89ce73e test(ee): add contentTypes check
  • b32e653 test(ee): review workflows metric calculation
  • d2a2d80 Merge pull request #17428 from strapi/fix/not-call-number-draft-relations-api-with-no-ids
  • d03d981 change the marginLeft definition
  • 7577509 use another id for the Already Published translation
  • 96da309 Merge pull request #17403 from strapi/fix/bulk-publish-v2-fix-select-all
  • f735e5a enable the draft relations count api only if we have ids selected and remove it.only from
  • df79981 Merge pull request #17262 from strapi/fix/relation-reordering-inv
  • 0389630 Add context to the attemptResolveError function
  • 26e9bcf Rename function
  • 1ba5ae3 Update packages/core/strapi/lib/commands/utils/data-transfer.js
  • 7d9f040 Merge pull request #17424 from strapi/fix/deits-ensure-access-before-backup
  • 9bbbccc ensure before attempting
  • 0220db0 change entity published label
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/losolio/project/65056c0f-1d2e-44d9-acca-4df3d487fb94?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/losolio/project/65056c0f-1d2e-44d9-acca-4df3d487fb94?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"ed2cd0e8-e820-4779-afb2-40c1238bfe28","prPublicId":"ed2cd0e8-e820-4779-afb2-40c1238bfe28","dependencies":[{"name":"@strapi/strapi","from":"4.11.7","to":"4.12.0"}],"packageManager":"npm","projectPublicId":"65056c0f-1d2e-44d9-acca-4df3d487fb94","projectUrl":"https://app.snyk.io/org/losolio/project/65056c0f-1d2e-44d9-acca-4df3d487fb94?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-SEMVER-3247795"],"upgrade":["SNYK-JS-SEMVER-3247795"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[696],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr)
losolio commented 1 year ago

Upgraded in #52