ohcnetwork / stay_be

CoronaSafe Stay BE NestJS
MIT License
4 stars 8 forks source link

[Snyk] Security upgrade @nestjs-modules/mailer from 1.4.2 to 1.6.0 #149

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Remote Code Execution (RCE)
SNYK-JS-PACRESOLVER-1564857
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @nestjs-modules/mailer The new version differs by 250 commits.
  • 328b677 chore(release): 1.6.0
  • e4b477e Merge pull request #548 from nest-modules/renovate/eslint-config-prettier-8.x
  • 69b5cfe chore(deps): update dependency eslint-config-prettier to v8.2.0
  • 71568e3 Merge pull request #546 from nest-modules/renovate/eslint-7.x
  • 2a0ca9f chore(deps): update dependency eslint to v7.24.0
  • abbc643 Merge pull request #545 from nest-modules/renovate/typescript-4.x
  • 6115c66 Merge pull request #544 from nest-modules/renovate/standard-version-9.x
  • daacde0 Merge pull request #537 from nest-modules/renovate/typescript-eslint-monorepo
  • 95d6e47 chore(deps): update typescript-eslint monorepo to v4.22.0
  • 7022ea8 chore(deps): update dependency typescript to v4.2.4
  • 9d00897 chore(deps): update dependency standard-version to v9.2.0
  • 2502f91 Merge pull request #538 from nest-modules/renovate/supertest-2.x
  • bcdd6b8 Merge pull request #539 from nest-modules/dependabot/npm_and_yarn/sample/01-basic/y18n-4.0.1
  • 3680489 Merge pull request #540 from nest-modules/dependabot/npm_and_yarn/sample/02-custom-template-adapter/y18n-4.0.1
  • 1d8ff1d chore(deps): update dependency @ types/supertest to v2.0.11
  • b4444fe Merge pull request #541 from nest-modules/renovate/commitlint-monorepo
  • c853cbe Merge pull request #542 from nest-modules/renovate/nodemailer-mock-1.x
  • 21d8606 chore(deps): update dependency nodemailer-mock to v1.5.8
  • eff79be chore(deps): update commitlint monorepo to v12.1.1
  • 8813d42 Merge pull request #536 from nest-modules/renovate/husky-6.x
  • 135a422 chore(deps): bump y18n in /sample/02-custom-template-adapter
  • cf6eee0 chore(deps): bump y18n from 4.0.0 to 4.0.1 in /sample/01-basic
  • 119e974 chore(deps): update dependency husky to v6
  • a095d2c Merge pull request #533 from nest-modules/renovate/eslint-7.x
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic