rogerballard / nestjs-relay

A batteries-included toolkit for building Relay-compliant GraphQL APIs with NestJS v7
MIT License
58 stars 14 forks source link

[Snyk] Security upgrade @nestjs/graphql from 7.7.0 to 7.11.0 #228

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JS-APOLLOSERVERCORE-2928764
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @nestjs/graphql The new version differs by 250 commits.
  • 2dff6df Merge pull request #1469 from timhall/fix/resolve-type-issue
  • c526701 Merge pull request #1482 from randomprofilename/graphql_federation_schemahost_fix
  • ca0872b Merge pull request #1503 from kuskoman/call-apollo-start
  • 47dbdaf Merge pull request #1544 from maazkabir/fastify-fix
  • 9a1cdb2 Merge pull request #1561 from Koala-gentil/enums-as-types
  • b162658 chore(): upgrade deps, remove apollo-env dependency
  • 43870f7 Merge pull request #1508 from bzuker/bz/fix-field-middleware-type
  • f2fa65d Merge pull request #1501 from nestjs/renovate/graphql-tools-monorepo
  • bcb9eab Merge pull request #1558 from nestjs/renovate/ts-morph-11.x
  • 4317b76 Merge pull request #1563 from nestjs/renovate/circleci-node-16.x
  • 9b118d1 Merge pull request #1578 from nestjs/dependabot/npm_and_yarn/glob-parent-5.1.2
  • c85f5ed Merge pull request #1582 from nestjs/renovate/tslib-2.x
  • 85b9721 Merge pull request #1586 from nestjs/renovate/chokidar-3.x
  • eab7460 chore(deps): update nest monorepo to v7.6.18
  • 852c2ab fix(deps): update dependency chokidar to v3.5.2
  • 62e14e7 chore(deps): update typescript-eslint monorepo to v4.27.0
  • a7ab414 chore(deps): update dependency release-it to v14.9.0
  • 0f2a43c fix(deps): update dependency tslib to v2.3.0
  • 86c93b1 chore(deps): bump glob-parent from 5.1.0 to 5.1.2
  • 2d7f689 chore(deps): update dependency @ types/node to v14.17.3
  • 1100e90 chore(deps): update typescript-eslint monorepo to v4.26.1
  • 6098b67 chore(deps): update dependency release-it to v14.8.0
  • a725b3a chore(deps): update dependency prettier to v2.3.1
  • 66ba50c chore(deps): update dependency @ types/node to v14.17.2
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

coveralls commented 2 years ago

Pull Request Test Coverage Report for Build 2536881026


Totals Coverage Status
Change from base Build 810674891: 0.0%
Covered Lines: 241
Relevant Lines: 243

💛 - Coveralls