samqdemocorp-mend / box_mojito_lvp

Apache License 2.0
0 stars 0 forks source link

Update Mend: high confidence minor and patch dependency updates #74

Open mend-for-github-com[bot] opened 2 months ago

mend-for-github-com[bot] commented 2 months ago

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
lodash (source) 4.17.13 -> 4.17.21 age adoption passing confidence
moment (source) 2.24.0 -> 2.29.4 age adoption passing confidence
org.quartz-scheduler:quartz (source) 2.2.3 -> 2.3.2 age adoption passing confidence
org.springframework.security.oauth:spring-security-oauth2 (source) 2.0.18.RELEASE -> 2.5.2.RELEASE age adoption passing confidence
commons-io:commons-io (source) 2.5 -> 2.7 age adoption passing confidence

By merging this PR, the issue #17 will be automatically resolved and closed:

Severity CVSS Score CVE Reachability
High High 8.3 CVE-2020-8203
High High 7.3 CVE-2021-23337
Medium Medium 5.5 CVE-2020-28500

By merging this PR, the issue #34 will be automatically resolved and closed:

Severity CVSS Score CVE Reachability
High High 8.7 CVE-2022-24785
High High 8.2 CVE-2022-31129

By merging this PR, the issue #15 will be automatically resolved and closed:

Severity CVSS Score CVE Reachability
Critical Critical 9.2 CVE-2019-13990

Reachable

By merging this PR, the issue #35 will be automatically resolved and closed:

Severity CVSS Score CVE Reachability
High High 7.1 CVE-2022-22969

Unreachable

By merging this PR, the issue #25 will be automatically resolved and closed:

Severity CVSS Score CVE Reachability
Medium Medium 6.3 CVE-2021-29425

Reachable


Release Notes

lodash/lodash (lodash) ### [`v4.17.21`](https://togithub.com/lodash/lodash/compare/4.17.20...4.17.21) [Compare Source](https://togithub.com/lodash/lodash/compare/4.17.20...4.17.21) ### [`v4.17.20`](https://togithub.com/lodash/lodash/compare/4.17.19...4.17.20) [Compare Source](https://togithub.com/lodash/lodash/compare/4.17.19...4.17.20) ### [`v4.17.16`](https://togithub.com/lodash/lodash/compare/4.17.15...4.17.16) [Compare Source](https://togithub.com/lodash/lodash/compare/4.17.15...4.17.16) ### [`v4.17.15`](https://togithub.com/lodash/lodash/compare/4.17.14...4.17.15) [Compare Source](https://togithub.com/lodash/lodash/compare/4.17.14...4.17.15) ### [`v4.17.14`](https://togithub.com/lodash/lodash/compare/4.17.13...4.17.14) [Compare Source](https://togithub.com/lodash/lodash/compare/4.17.13...4.17.14)
moment/moment (moment) ### [`v2.29.4`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2294) [Compare Source](https://togithub.com/moment/moment/compare/2.29.3...2.29.4) - Release Jul 6, 2022 - [#​6015](https://togithub.com/moment/moment/pull/6015) \[bugfix] Fix ReDoS in preprocessRFC2822 regex ### [`v2.29.3`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2293-Full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.29.2...2.29.3) - Release Apr 17, 2022 - [#​5995](https://togithub.com/moment/moment/pull/5995) \[bugfix] Remove const usage - [#​5990](https://togithub.com/moment/moment/pull/5990) misc: fix advisory link ### [`v2.29.2`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2292-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.29.1...2.29.2) - Release Apr 3 2022 Address https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4 ### [`v2.29.1`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2291-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.29.0...2.29.1) - Release Oct 6, 2020 Updated deprecation message, bugfix in hi locale ### [`v2.29.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2290-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.28.0...2.29.0) - Release Sept 22, 2020 New locales (es-mx, bn-bd). Minor bugfixes and locale improvements. More tests. Moment is in maintenance mode. Read more at this link: https://momentjs.com/docs/#/-project-status/ ### [`v2.28.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2280-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.27.0...2.28.0) - Release Sept 13, 2020 Fix bug where .format() modifies original instance, and locale updates ### [`v2.27.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2270-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.26.0...2.27.0) - Release June 18, 2020 Added Turkmen locale, other locale improvements, slight TypeScript fixes ### [`v2.26.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2260-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.25.3...2.26.0) - Release May 19, 2020 TypeScript fixes and many locale improvements ### [`v2.25.3`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2253) [Compare Source](https://togithub.com/moment/moment/compare/2.25.2...2.25.3) - Release May 4, 2020 Remove package.json module property. It looks like webpack behaves differently for modules loaded via module vs jsnext:main. ### [`v2.25.2`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2252) [Compare Source](https://togithub.com/moment/moment/compare/2.25.1...2.25.2) - Release May 4, 2020 This release includes ES Module bundled moment, separate from it's source code under dist/ folder. This might alleviate issues with finding the \`./locale subfolder for loading locales. This might also mean now webpack will bundle all locales automatically, unless told otherwise. ### [`v2.25.1`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2251) [Compare Source](https://togithub.com/moment/moment/compare/2.25.0...2.25.1) - Release May 1, 2020 This is a quick patch release to address some of the issues raised after releasing 2.25.0. - [2e268635](https://togithub.com/moment/moment/commit/2e268635) \[misc] Revert [#​5269](https://togithub.com/moment/moment/issues/5269) due to webpack warning - [226799e1](https://togithub.com/moment/moment/commit/226799e1) \[locale] fil: Fix metadata comment - [a83a521](https://togithub.com/moment/moment/commit/a83a521) \[bugfix] Fix typeoff usages - [e324334](https://togithub.com/moment/moment/commit/e324334) \[pkg] Add ts3.1-typings in npm package - [28cc23e](https://togithub.com/moment/moment/commit/28cc23e) \[misc] Remove deleted generated locale en-SG ### [`v2.25.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2250-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.24.0...2.25.0) - Release May 1, 2020 - [#​4611](https://togithub.com/moment/moment/issues/4611) [022dc038](https://togithub.com/moment/moment/commit/022dc038) \[feature] Support for strict string parsing, fixes [#​2469](https://togithub.com/moment/moment/issues/2469) - [#​4599](https://togithub.com/moment/moment/issues/4599) [4b615b9d](https://togithub.com/moment/moment/commit/4b615b9d) \[feature] Add support for eras in en and jp - [#​4296](https://togithub.com/moment/moment/issues/4296) [757d4ff8](https://togithub.com/moment/moment/commit/757d4ff8) \[feature] Accept custom relative thresholds in duration.humanize - 18 bigfixes - 36 locale fixes - 5 new locales (oc-lnc, zh-mo, en-in, gom-deva, fil)
quartz-scheduler/quartz (org.quartz-scheduler:quartz) ### [`v2.3.2`](https://togithub.com/quartz-scheduler/quartz/releases/tag/v2.3.2): Quartz 2.3.2 [Compare Source](https://togithub.com/quartz-scheduler/quartz/compare/v2.3.1...v2.3.2) This a bug fix release containing fixes for: - [#​508](https://togithub.com/quartz-scheduler/quartz/issues/508) : Error with H2 1.4.200 - [#​505](https://togithub.com/quartz-scheduler/quartz/issues/505) : CronTrigger.getTriggerBuilder() changes misfire instruction from "ignore misfire" to "smart" - [#​491](https://togithub.com/quartz-scheduler/quartz/issues/491) : StdJDBCDelegate.selectTriggerToAcquire may not respect maxCount - [#​490](https://togithub.com/quartz-scheduler/quartz/issues/490) : Return at most maxCount triggers - [#​482](https://togithub.com/quartz-scheduler/quartz/issues/482) : Update C3P0 version to 0.9.5.4 (CVE-2019-5427) - [#​474](https://togithub.com/quartz-scheduler/quartz/issues/474) : StdSchedulerFactory ConcurrentModificationException reading system properties - [#​467](https://togithub.com/quartz-scheduler/quartz/issues/467) : Security: XXE in initDocumentParser
SpringSource/spring-security-oauth (org.springframework.security.oauth:spring-security-oauth2) ### [`v2.5.2.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.5.1.RELEASE...2.5.2.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.5.1.RELEASE...2.5.2.RELEASE) ### [`v2.5.1.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.5.0.RELEASE...2.5.1.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.5.0.RELEASE...2.5.1.RELEASE) ### [`v2.5.0.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.4.2.RELEASE...2.5.0.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.4.2.RELEASE...2.5.0.RELEASE) ### [`v2.4.2.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.4.1.RELEASE...2.4.2.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.4.1.RELEASE...2.4.2.RELEASE) ### [`v2.4.1.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.4.0.RELEASE...2.4.1.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.4.0.RELEASE...2.4.1.RELEASE) ### [`v2.4.0.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.8.RELEASE...2.4.0.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.8.RELEASE...2.4.0.RELEASE) ### [`v2.3.8.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.7.RELEASE...2.3.8.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.7.RELEASE...2.3.8.RELEASE) ### [`v2.3.7.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.6.RELEASE...2.3.7.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.6.RELEASE...2.3.7.RELEASE) ### [`v2.3.6.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.5.RELEASE...2.3.6.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.5.RELEASE...2.3.6.RELEASE) ### [`v2.3.5.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.4.RELEASE...2.3.5.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.4.RELEASE...2.3.5.RELEASE) ### [`v2.3.4.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.3.RELEASE...2.3.4.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.3.RELEASE...2.3.4.RELEASE) ### [`v2.3.3.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.2.RELEASE...2.3.3.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.2.RELEASE...2.3.3.RELEASE) ### [`v2.3.2.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.1.RELEASE...2.3.2.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.1.RELEASE...2.3.2.RELEASE) ### [`v2.3.1.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.0.RELEASE...2.3.1.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.3.0.RELEASE...2.3.1.RELEASE) ### [`v2.3.0.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.6.RELEASE...2.3.0.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.6.RELEASE...2.3.0.RELEASE) ### [`v2.2.6.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.5.RELEASE...2.2.6.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.5.RELEASE...2.2.6.RELEASE) ### [`v2.2.5.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.4.RELEASE...2.2.5.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.4.RELEASE...2.2.5.RELEASE) ### [`v2.2.4.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.3.RELEASE...2.2.4.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.3.RELEASE...2.2.4.RELEASE) ### [`v2.2.3.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.2.RELEASE...2.2.3.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.2.RELEASE...2.2.3.RELEASE) ### [`v2.2.2.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.1.RELEASE...2.2.2.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.1.RELEASE...2.2.2.RELEASE) ### [`v2.2.1.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.0.RELEASE...2.2.1.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.2.0.RELEASE...2.2.1.RELEASE) ### [`v2.2.0.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.6.RELEASE...2.2.0.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.6.RELEASE...2.2.0.RELEASE) ### [`v2.1.6.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.5.RELEASE...2.1.6.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.5.RELEASE...2.1.6.RELEASE) ### [`v2.1.5.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.4.RELEASE...2.1.5.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.4.RELEASE...2.1.5.RELEASE) ### [`v2.1.4.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.3.RELEASE...2.1.4.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.3.RELEASE...2.1.4.RELEASE) ### [`v2.1.3.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.2.RELEASE...2.1.3.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.2.RELEASE...2.1.3.RELEASE) ### [`v2.1.2.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.1.RELEASE...2.1.2.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.1.RELEASE...2.1.2.RELEASE) ### [`v2.1.1.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.0.RELEASE...2.1.1.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.1.0.RELEASE...2.1.1.RELEASE) ### [`v2.1.0.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.0.19.RELEASE...2.1.0.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.0.19.RELEASE...2.1.0.RELEASE) ### [`v2.0.19.RELEASE`](https://togithub.com/SpringSource/spring-security-oauth/compare/2.0.18.RELEASE...2.0.19.RELEASE) [Compare Source](https://togithub.com/SpringSource/spring-security-oauth/compare/2.0.18.RELEASE...2.0.19.RELEASE)