rithinch / event-driven-microservices-docker-example

🐳 Simple example of event driven communication between microservices, based on Docker containers, Docker Compose and RabbitMQ. Microservices are implemented in Node.js using Koa.
MIT License
248 stars 84 forks source link

[Snyk] Upgrade koa-helmet from 4.0.0 to 4.2.1 #5

Closed snyk-bot closed 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to upgrade koa-helmet from 4.0.0 to 4.2.1.

merge advice

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue Exploit Maturity
Configuration Override
SNYK-JS-HELMETCSP-469436
No Known Exploit
Release notes
Package name: koa-helmet
  • 4.2.1 - 2019-08-12
    • Reverts a breaking change introduced in v4.2.0 (Thanks @rahulroy9202!) which dropped node v6 support and should have been done as part of a major-release. Will re-release as part of a major version bump (v.5.0.0)
  • 4.2.0 - 2019-06-05
    • Update helmet dependency to ^3.18.0.
    • Update downstream handlebars dependency to fix WS-2019-0064.
    • Remove support for node 6.x due to it being out of LTS scope.
    • Remove custom promisify method to use node 8's util.promisify method.
  • 4.1.0 - 2019-03-10
    • Update helmet dependency to ^3.15.1
  • 4.0.0 - 2018-03-27
    • Update helmet to ^3.12.0
    • Drop node v4 support. Minimum version is Node v6.0.0
from koa-helmet GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

sonarcloud[bot] commented 4 years ago

Kudos, SonarCloud Quality Gate passed!

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities (and Security Hotspot 0 Security Hotspots to review)
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information