parse-community / parse-server-push-adapter

A push notification adapter for Parse Server
https://parseplatform.org
MIT License
85 stars 100 forks source link

feat: Upgrade @parse/node-apn from 5.1.3 to 5.2.1 #220

Closed parseplatformorg closed 11 months ago

parseplatformorg commented 11 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade @parse/node-apn from 5.1.3 to 5.2.1.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **2 versions** ahead of your current version. - The recommended version was released **21 days ago**, on 2023-07-16. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-SEMVER-3247795](https://snyk.io/vuln/SNYK-JS-SEMVER-3247795) | **482/1000**
**Why?** Proof of Concept exploit, CVSS 7.5 | Proof of Concept | Improper Authentication
[SNYK-JS-JSONWEBTOKEN-3180022](https://snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180022) | **482/1000**
**Why?** Proof of Concept exploit, CVSS 7.5 | No Known Exploit | Improper Restriction of Security Token Assignment
[SNYK-JS-JSONWEBTOKEN-3180024](https://snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180024) | **482/1000**
**Why?** Proof of Concept exploit, CVSS 7.5 | No Known Exploit | Use of a Broken or Risky Cryptographic Algorithm
[SNYK-JS-JSONWEBTOKEN-3180026](https://snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180026) | **482/1000**
**Why?** Proof of Concept exploit, CVSS 7.5 | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: @parse/node-apn from @parse/node-apn GitHub release notes
Commit messages
Package name: @parse/node-apn
  • 87e7901 chore(release): 5.2.1 [skip ci]
  • 5bc179d fix: Security upgrade jsonwebtoken from 8.5.1 to 9.0.0 (#128)
  • 650c3eb chore(release): 5.2.0 [skip ci]
  • 80717cd feat: Add support for Live Activity with ActivityKit push notifications (#130)
  • 650993d refactor: upgrade node-forge from 1.3.0 to 1.3.1 (#110)
Compare

**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/acinader/project/b0adf7a4-b021-4a61-8d76-16d0d77d4062?utm_source=github&utm_medium=referral&page=upgrade-pr) πŸ›  [Adjust upgrade PR settings](https://app.snyk.io/org/acinader/project/b0adf7a4-b021-4a61-8d76-16d0d77d4062/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) πŸ”• [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/acinader/project/b0adf7a4-b021-4a61-8d76-16d0d77d4062/settings/integration?pkg=@parse/node-apn&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)
parse-github-assistant[bot] commented 11 months ago

I will reformat the title to use the proper commit message syntax.

parse-github-assistant[bot] commented 11 months ago

Thanks for opening this pull request!

codecov[bot] commented 11 months ago

Codecov Report

Patch and project coverage have no change.

Comparison is base (598cb84) 100.00% compared to head (079c870) 100.00%. Report is 1 commits behind head on master.

:exclamation: Current head 079c870 differs from pull request most recent head 77c6a2b. Consider uploading reports for the commit 77c6a2b to get more accurate results

Additional details and impacted files ```diff @@ Coverage Diff @@ ## master #220 +/- ## ========================================= Coverage 100.00% 100.00% ========================================= Files 5 5 Lines 277 277 ========================================= Hits 277 277 ```

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

parseplatformorg commented 11 months ago

πŸŽ‰ This change has been released in version 4.2.0