mongodb / docs-realm

Realm Database SDK documentation
https://www.mongodb.com/docs/realm/
46 stars 88 forks source link

[Snyk] Upgrade firebase from 10.11.0 to 10.11.1 #3262

Closed admin-token-bot closed 6 months ago

admin-token-bot commented 6 months ago

Snyk has created this PR to upgrade firebase from 10.11.0 to 10.11.1.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Path Traversal
SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
477/1000
Why? Proof of Concept exploit, CVSS 7.4
Proof of Concept
Improper Control of Dynamically-Managed Code Resources
SNYK-JS-EJS-6689533
477/1000
Why? Proof of Concept exploit, CVSS 7.4
No Known Exploit
Open Redirect
SNYK-JS-EXPRESS-6474509
477/1000
Why? Proof of Concept exploit, CVSS 7.4
No Known Exploit
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
477/1000
Why? Proof of Concept exploit, CVSS 7.4
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: firebase
  • 10.11.1 - 2024-04-25
  • 10.11.1-dataconnect-preview.f2ddc3d7b - 2024-05-08
  • 10.11.1-dataconnect-preview.f2a1a4bfb - 2024-05-08
  • 10.11.1-dataconnect-preview.b8e015c81 - 2024-05-08
  • 10.11.1-dataconnect-preview.81ee5169c - 2024-05-09
  • 10.11.1-dataconnect-preview.4f89ef789 - 2024-05-08
  • 10.11.1-dataconnect-preview.42eb5e521 - 2024-05-08
  • 10.11.1-dataconnect-preview.323fdc1b8 - 2024-05-09
  • 10.11.1-canary.f631553c3 - 2024-05-06
  • 10.11.1-canary.f25b9e53e - 2024-05-02
  • 10.11.1-canary.e80b80738 - 2024-05-08
  • 10.11.1-canary.ab883d016 - 2024-05-09
  • 10.11.1-canary.7709f1016 - 2024-04-25
  • 10.11.1-canary.506b8a6ab - 2024-05-08
  • 10.11.1-canary.4b49630c7 - 2024-05-01
  • 10.11.1-canary.14f9da66f - 2024-05-02
  • 10.11.1-20240424141009 - 2024-04-24
  • 10.11.0 - 2024-04-11
from firebase GitHub release notes
Commit messages
Package name: firebase
  • 7709f10 Version Packages (#8202)
  • e16d613 Merge master into release
  • e1a7764 Go back using xmlhttprequest for bidi-streams (#8197)
  • 36b283f Emit a module package file into esm2017 auth webextension bundle (#8191)
  • 62a20ff Update bug_report_v2.yaml (#8199)
  • 03069bb Fix typo and link formatting in contribution guide (#8183)
  • f24c953 Update recommended Node version for development (#8188)
  • b74d8a2 Bump async from 3.2.0 to 3.2.4 in /e2e (#6447)
  • 02b4ea9 Bump shell-quote from 1.7.2 to 1.7.3 (#6381)
  • 71ab2f5 Bump ua-parser-js from 0.7.31 to 0.7.37 (#8179)
  • 6333607 Bump ansi-regex from 5.0.0 to 5.0.1 in /e2e (#6257)
  • 44a66b9 Change Markdown links in code docs to JSDoc links (#8182)
  • 2244194 Firestore: Fix spurious "Backend didn't respond within 10 seconds" errors when network just slow (#8145)
  • 84f9ff0 Firestore: simple_db.ts: move getAndroidVersion() to a free function (#8178)
  • 399ae5a Bump json5 from 1.0.1 to 1.0.2 (#6933)
  • 55fef6d Bump jszip from 3.7.1 to 3.10.1 (#7001)
  • 3376384 Bump http-cache-semantics in /packages/auth-compat/demo (#7003)
  • d1eae3a Bump http-cache-semantics from 4.1.0 to 4.1.1 (#7004)
  • 4be78a3 Bump minimist from 1.2.5 to 1.2.8 in /e2e (#7061)
  • 07b2dc7 Update deploy-config.yml (#8168)
  • aa412d3 Bump minimist from 1.2.5 to 1.2.8 in /packages/auth-compat/demo (#7062)
  • 55435c9 Bump semver from 7.5.2 to 7.5.3 (#8164)
  • ef3039b Bump semver from 6.3.0 to 6.3.1 in /e2e (#7437)
  • be59b95 Update health-metrics-pull-request.yml (#8158)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

docs-builder-bot commented 6 months ago

✨ Staging URL: https://docs-atlas-staging.mongodb.com/realm/docsworker-xlarge/snyk-upgrade-9e255dd0b824d30fa8de59149333692b/

🪵 Logs