ooade / next-apollo-auth

Authentication Boilerplate with Next.js and Apollo GraphQL
https://next-auth-apollo.now.sh
202 stars 36 forks source link

[Snyk] Fix for 1 vulnerabilities #112

Open ooade opened 1 month ago

ooade commented 1 month ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 601/1000
Why? Recently disclosed, Has a fix available, CVSS 6.3
Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: cookie-parser The new version differs by 150 commits.
  • 5d61e1e 1.4.7
  • ccf1f54 deps: cookie@0.7.2 (#116)
  • 429cfd4 ci: Use GITHUB_OUTPUT envvar instead of set-output command (#100)
  • ca4c97e ci: fix errors in ci pipeline for node 8 and 9 (#104)
  • 97bdf39 ci: add support for OSSF scorecard reporting (#103)
  • e5862bd build: Node.js@17.6
  • f0688d2 build: Node.js@14.19
  • 44ec541 build: Node.js@16.14
  • 695435a deps: cookie@0.4.2
  • f66e7e1 build: mocha@9.2.1
  • 05e40b1 build: Node.js@17.3
  • bc1d501 build: use supertest@3.4.2 for Node.js 6.x
  • dda4c5b 1.4.6
  • 8653e78 build: support Node.js 17.x
  • 6ec9c5b deps: cookie@0.4.1
  • ee68a8a build: eslint-plugin-standard@4.1.0
  • 7828d66 build: mocha@9.1.3
  • dafa811 build: use nyc for coverage testing
  • d80cf11 build: eslint-plugin-promise@4.3.1
  • c954873 build: supertest@6.1.6
  • 8ad6c54 build: mocha@8.4.0
  • 716f5a4 build: support Node.js 16.x
  • 90c418d build: eslint@7.32.0
  • a3cff78 build: support Node.js 15.x
See the full diff
Package name: express The new version differs by 189 commits.
  • 8e229f9 4.21.1
  • a024c8a fix(deps): cookie@0.7.1
  • 7e562c6 4.21.0
  • 1bcde96 fix(deps): qs@6.13.0 (#5946)
  • 7d36477 fix(deps): serve-static@1.16.2 (#5951)
  • 40d2d8f fix(deps): finalhandler@1.3.1
  • 77ada90 Deprecate `"back"` magic string in redirects (#5935)
  • 21df421 4.20.0
  • 4c9ddc1 feat: upgrade to serve-static@0.16.0
  • 9ebe5d5 feat: upgrade to send@0.19.0 (#5928)
  • ec4a01b feat: upgrade to body-parser@1.20.3 (#5926)
  • 54271f6 fix: don't render redirect values in anchor href
  • 125bb74 path-to-regexp@0.1.10 (#5902)
  • 2a980ad merge-descriptors@1.0.3 (#5781)
  • a3e7e05 docs: specify new instructions for `question` and `discuss`
  • c5addb9 deps: path-to-regexp@0.1.8 (#5603)
  • e35380a docs: add @ IamLizu to the triage team (#5836)
  • f5b6e67 docs: update scorecard link (#5814)
  • 2177f67 docs: add OSSF Scorecard badge (#5436)
  • f4bd86e Replace Appveyor windows testing with GHA (#5599)
  • 2ec589c Fix Contributor Covenant link definition reference in attribution section (#5762)
  • 4cf7eed remove minor version pinning from ci (#5722)
  • 6d08471 📝 update people, add ctcpip to TC (#5683)
  • 61421a8 skip QUERY tests for Node 21 only, still not supported (#5695)
See the full diff
Package name: express-session The new version differs by 250 commits.
  • bbeca94 1.18.1
  • 341b179 dep: cookie@0.7.2 (#997)
  • 8f0a1c4 ci: add support for OSSF scorecard reporting (#984)
  • 24d4972 1.18.0
  • 855f21a docs: add connect-ottoman to the list of session stores
  • 991b7ee Add debug log for pathname mismatch
  • 408229e Add "partitioned" to cookie options
  • 50e1429 build: Node.js@20.11
  • 6153b3f build: Node.js@21.6
  • 88e0f2e build: actions/checkout@v4
  • d9354ef Fix handling errors from setting cookie
  • f9f2318 docs: remove session-rethinkdb to the list of session stores
  • 3ee08c4 Add "priority" to cookie options
  • 71c3f74 docs: add connect-cosmosdb to the list of session stores
  • 9d377c5 docs: add dynamodb-store-v3 to the list of session stores
  • a1f884f docs: add @ cyclic.sh/session-store to the list of session stores
  • e5f19ce docs: add note on length of secret
  • 2a7a50b eslint@8.56.0
  • a46e857 supertest@6.3.4
  • 7dec651 build: Node.js@18.19
  • 8e9f7a4 build: Node.js@20.10
  • 6b7c9a0 build: Node.js@21.5
  • 825e6c0 build: fix code coverage aggregate upload
  • c1611ad build: actions/checkout@v3
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)