ohcnetwork / stay_be

CoronaSafe Stay BE NestJS
MIT License
4 stars 8 forks source link

[Snyk] Security upgrade newrelic from 6.5.0 to 6.12.0 #153

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-ASYNC-2441827
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: newrelic The new version differs by 250 commits.
  • 16f99e6 6.12.0
  • 70d13cb Merge pull request #461 from newrelic/release/v6.12.0
  • 419cdf9 fix typo
  • 406ba50 Release/v6.12.0
  • 46f76a9 Merge pull request #456 from tomashanacek/fix-large-json-insert-obfluscation
  • dd7094d Merge pull request #458 from michaelgoin/bump-native-metrics-version
  • eab7131 Updates native metrics license for license tests.
  • 0bd8f8d Bumps @ newrelic/native-metrics to ^5.3.0.
  • c87837a Fix large JSON inserts obfluscation
  • 791a719 Merge pull request #454 from michaelgoin/bump-aws-sdk
  • bdf7aa7 Fix @ newrelic/aws-sdk license in licenses tests.
  • 647e28e Bumps @ newrelic/aws-sdk to ^2.0.0.
  • a8fc4e6 Merge pull request #450 from RyanCopley/patch-1
  • d0e8304 Improved logging in the case of a failed instrumentation
  • 4fa8cad --oops-- Forgot to save test changes. I need to use a new module considering the require cache gets in the way.
  • 7c94c90 BE BOLD.
  • dd01e3e Merge branch 'astorm/shimmer-integration' of github.com:newrelic/node-newrelic into NR-416443
  • 0cd22ec Adding test for __NR_instrumented
  • e25afb1 Correct code style to match New Relic ESLint rules.
  • dd6cee3 NR-416443: On failed instrumentation, prevent multiple requires from re-wrapping shims
  • 761ba2c Merge pull request #448 from michaelgoin/update-license-formatting
  • e701087 Fixes first-line formatting for license file.
  • b66180a Merge pull request #447 from michaelgoin/remove-readme-language
  • 8b098ef Removes the 'remove this...' language from readme.
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution