punchcard-cms / punchcard

The Punchcard CMS
Apache License 2.0
31 stars 19 forks source link

[Snyk] Fix for 2 vulnerabilities #724

Open Snugug opened 2 months ago

Snugug commented 2 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Uncontrolled resource consumption
[SNYK-JS-BRACES-6838727](https://snyk.io/vuln/SNYK-JS-BRACES-6838727) | Yes | No Known Exploit ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Inefficient Regular Expression Complexity
[SNYK-JS-MICROMATCH-6838728](https://snyk.io/vuln/SNYK-JS-MICROMATCH-6838728) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: connect-session-knex The new version differs by 221 commits.
  • 0976205 2.1.1
  • 7ad41bd Update Changelog
  • 6d3f386 Update packages
  • 36eb1bd Fix default export in typings (#89)
  • d9242c8 Updated for compatability with Knex 0.95.0+ (#82)
  • af5b932 2.1.0
  • e91012c Update Changelog
  • 6897bf7 Update package.json
  • 01d6548 Update Readme.md
  • 03bb19e Implemented store.all() method (#81)
  • 03e8aa7 Merge pull request #80 from mehmetb/code-linting
  • 9d4380a Merge pull request #79 from sn1ff/master
  • 0e448d3 Merge pull request #78 from medicalminds/master
  • a36195e Linted the code
  • 6d38312 Added lint and lint-fix scripts to package.json
  • e2fd0c2 Add Postgres support for case sensitive custom tablename
  • fa0703d disableDbCleanup option to readme / simple test
  • 74fffad add disableDbCleanup option
  • 9070566 Bump ini from 1.3.5 to 1.3.8 (#76)
  • c83b5ec Update dependencies
  • 1b4fcb2 Fix typings for createtable option (#73)
  • 8ad445b 1.7.3
  • bc9cd57 Changelog 1.7.3
  • 815285f fix: handling datatype in older mysql versions(< 5.7.8) (#68)
See the full diff
Package name: knex The new version differs by 250 commits.
  • ed0e8a5 Fix SQLite not doing rollback when altering columns fails (#4336)
  • 3c70dca Prepare 0.95.0 for release
  • c1ab23c Await asynchronous expect assertions (#4334)
  • 3e6176a SQLite parser improvements (#4333)
  • a98614d Made the constraint detection case-insensitive (#4330)
  • 5d2db21 Fix ArrayIfAlready type (#4331)
  • 887a4f6 Improve join and conflict types v2 (#4318)
  • 29b8a36 Adjust generateDdlCommands return type (#4326)
  • d807832 mssql: schema builder - attempt to drop default constraints when changing default value on columns (#4321)
  • c0d8c5c mssql: schema builder - add predictable constraint names for default values (#4319)
  • 5ec76f5 Convert produced statements to objects before querying (#4323)
  • 9e28a72 Add support for altering columns to SQLite (#4322)
  • 7db2d18 fix mssql alter column must have its own query (#4317)
  • 371864d Bump typescript from 4.1.5 to 4.2.2 (#4312)
  • 6c3e7b5 mssql: don't raise query-error twice (#4314)
  • 168f2af Bump eslint-config-prettier from 7.2.0 to 8.1.0 (#4315)
  • 3718d64 Respect KNEX_TEST, support omitting sqlite3 from DB, and reduce outside mssql test db config (#4313)
  • c58794b Prepare to release 0.95.0-next3
  • 61e1046 Avoid importing entire lodash to ensure tree-shaking is working correctly (#4302)
  • 8c73417 events: introduce queryContext on query-error (#4301)
  • b6fd941 Include 'name' property in MigratorConfig (#4300)
  • 9581100 Prepare to release 0.95.0-next2
  • 5614c18 Timestamp UTC Standardization for Migrations (#4245)
  • 4899346 Fix for ES Module detection using npm@7 (#4295) (#4296)
See the full diff
Package name: nodemon The new version differs by 7 commits.
  • 9a67f36 feat: update chokidar to v3
  • 6781b40 docs: add license file
  • 0e6ba3c fix: wait for all subprocesses to terminate (fixes issue #1476)
  • b58cf7d chore: Merge branch 'master'
  • 95a4c09 docs: add to faq
  • 3a2eaf7 choe: merge master
  • 3d90879 chore: add logo to site
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/snugug/project/e6bd704c-a9eb-439f-916b-2859df7a076f?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/snugug/project/e6bd704c-a9eb-439f-916b-2859df7a076f?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"9c0bef2b-366d-4f77-b6f1-a9b29b94e028","prPublicId":"9c0bef2b-366d-4f77-b6f1-a9b29b94e028","dependencies":[{"name":"connect-session-knex","from":"1.7.3","to":"2.1.1"},{"name":"knex","from":"0.13.0","to":"0.95.0"},{"name":"nodemon","from":"1.19.4","to":"2.0.0"},{"name":"vinyl-fs","from":"2.4.4","to":"3.0.0"}],"packageManager":"npm","projectPublicId":"e6bd704c-a9eb-439f-916b-2859df7a076f","projectUrl":"https://app.snyk.io/org/snugug/project/e6bd704c-a9eb-439f-916b-2859df7a076f?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"upgrade":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[661,661],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Uncontrolled resource consumption](https://learn.snyk.io/lesson/redos/?loc=fix-pr)