seppevs / migrate-mongo

A database migration tool for MongoDB in Node
MIT License
931 stars 166 forks source link

Snyk issues for fast-xml-parser@4.0.11 #428

Open prince-kumar95 opened 1 year ago

prince-kumar95 commented 1 year ago

Snyk is failing for migrate-mongo@9.0.0

Issues with no direct upgrade or patch: ✗ Prototype Pollution [High Severity][https://security.snyk.io/vuln/SNYK-JS-FASTXMLPARSER-3325616] in fast-xml-parser@4.0.11 introduced by migrate-mongo@9.0.0 > mongodb@4.14.0 > @aws-sdk/credential-providers@3.267.0 > @aws-sdk/client-cognito-identity@3.267.0 > @aws-sdk/client-sts@3.267.0 > fast-xml-parser@4.0.11 and 2 other path(s) This issue was fixed in versions: 4.1.2