tabacws-sandbox / juice-shop-checkPR

MIT License
0 stars 0 forks source link

Update dependency sequelize to ^6.29.0 #73

Open mend-for-github-com[bot] opened 1 year ago

mend-for-github-com[bot] commented 1 year ago

This PR contains the following updates:

Package Type Update Change
sequelize (source) dependencies minor ^6.15.1 -> ^6.29.0

By merging this PR, the issue #72 will be automatically resolved and closed:

Severity CVSS Score CVE
Critical Critical 9.8 CVE-2023-22578
High High 8.8 CVE-2023-22579
High High 7.5 CVE-2023-22580

Release Notes

sequelize/sequelize (sequelize) ### [`v6.29.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.29.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.28.2...v6.29.0) ##### Features - throw an error if attribute includes parentheses (fixes CVE-2023-22578) ([#​15710](https://togithub.com/sequelize/sequelize/issues/15710)) ([d3f5b5a](https://togithub.com/sequelize/sequelize/commit/d3f5b5a65e297f4b6861e6a6ce335a9830b28781)) ### [`v6.28.2`](https://togithub.com/sequelize/sequelize/releases/tag/v6.28.2) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.28.1...v6.28.2) ##### Bug Fixes - accept undefined in where ([#​15703](https://togithub.com/sequelize/sequelize/issues/15703)) ([13f2e89](https://togithub.com/sequelize/sequelize/commit/13f2e89f8b6147897e3e43f01487de51aebcde87)) ### [`v6.28.1`](https://togithub.com/sequelize/sequelize/releases/tag/v6.28.1) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.28.0...v6.28.1) ##### Bug Fixes - throw if where receives an invalid value ([#​15699](https://togithub.com/sequelize/sequelize/issues/15699)) ([d9e0728](https://togithub.com/sequelize/sequelize/commit/d9e0728f2c2c5ae319f337c78091e1081440595d)) - update moment-timezone version ([#​15685](https://togithub.com/sequelize/sequelize/issues/15685)) ([48d6193](https://togithub.com/sequelize/sequelize/commit/48d619379108320831c9c6a0ec42bfda6586fec5)) ### [`v6.28.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.28.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.27.0...v6.28.0) ##### Features - **types:** use retry-as-promised types for retry options to match documentation ([#​15484](https://togithub.com/sequelize/sequelize/issues/15484)) ([fd4afa6](https://togithub.com/sequelize/sequelize/commit/fd4afa6a89c111c6d6d0c94f0b98bf421b5357b6)) ### [`v6.27.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.27.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.26.0...v6.27.0) ##### Features - add support for bigints (backport of [#​14485](https://togithub.com/sequelize/sequelize/issues/14485)) ([#​15413](https://togithub.com/sequelize/sequelize/issues/15413)) ([1247c01](https://togithub.com/sequelize/sequelize/commit/1247c01265743e4bdbd6d91a51cf64cd9d1e6617)) ### [`v6.26.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.26.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.25.8...v6.26.0) ##### Features - **postgres:** add support for lock_timeout \[[#​15345](https://togithub.com/sequelize/sequelize/issues/15345)] ([#​15355](https://togithub.com/sequelize/sequelize/issues/15355)) ([94beace](https://togithub.com/sequelize/sequelize/commit/94beace4ca666765ec9c84a3f7ef0e826e09699d)) ### [`v6.25.8`](https://togithub.com/sequelize/sequelize/releases/tag/v6.25.8) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.25.7...v6.25.8) ##### Bug Fixes - **oracle:** remove hardcoded maxRows value ([#​15323](https://togithub.com/sequelize/sequelize/issues/15323)) ([7885000](https://togithub.com/sequelize/sequelize/commit/7885000a70eb451100fa8f54d45361887241521c)) ### [`v6.25.7`](https://togithub.com/sequelize/sequelize/releases/tag/v6.25.7) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.25.6...v6.25.7) ##### Bug Fixes - fix parameters not being replaced when after $$ strings ([#​15307](https://togithub.com/sequelize/sequelize/issues/15307)) ([bc39fd6](https://togithub.com/sequelize/sequelize/commit/bc39fd69919e0af0cb0732ca9bfe3e60691c778a)) ### [`v6.25.6`](https://togithub.com/sequelize/sequelize/releases/tag/v6.25.6) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.25.5...v6.25.6) ##### Bug Fixes - **postgres:** invalidate connection after client-side timeout ([#​15283](https://togithub.com/sequelize/sequelize/issues/15283)) ([a205765](https://togithub.com/sequelize/sequelize/commit/a20576527b84d4986372b25303b61536fae7479a)), closes [/github.com/brianc/node-postgres/blob/5538df6b446f4b4f921947b460fe38acb897e579/packages/pg/lib/client.js#L529](https://togithub.com//github.com/brianc/node-postgres/blob/5538df6b446f4b4f921947b460fe38acb897e579/packages/pg/lib/client.js/issues/L529) ### [`v6.25.5`](https://togithub.com/sequelize/sequelize/releases/tag/v6.25.5) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.25.4...v6.25.5) ##### Bug Fixes - remove options.model overwrite on bulkUpdate ([#​15252](https://togithub.com/sequelize/sequelize/issues/15252)) ([67e69cd](https://togithub.com/sequelize/sequelize/commit/67e69cdb0e9d3dc16f61449cf0cf4f609c724719)), closes [#​15231](https://togithub.com/sequelize/sequelize/issues/15231) ### [`v6.25.4`](https://togithub.com/sequelize/sequelize/releases/tag/v6.25.4) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.25.3...v6.25.4) ##### Bug Fixes - **types:** add instance.dataValues property to model.d.ts ([#​15240](https://togithub.com/sequelize/sequelize/issues/15240)) ([00c6da3](https://togithub.com/sequelize/sequelize/commit/00c6da326630a85363b6d5e7d5570ac8ca8b31b8)) ### [`v6.25.3`](https://togithub.com/sequelize/sequelize/releases/tag/v6.25.3) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.25.2...v6.25.3) ##### Bug Fixes - don't treat \ as escape in standard strings, support E-strings, support vars after ->> operator, treat lowercase e as valid e-string prefix ([#​15139](https://togithub.com/sequelize/sequelize/issues/15139)) ([7990095](https://togithub.com/sequelize/sequelize/commit/7990095e369b226844669ec691cc7bce94c3dbbe)), closes [#​14700](https://togithub.com/sequelize/sequelize/issues/14700) ### [`v6.25.2`](https://togithub.com/sequelize/sequelize/releases/tag/v6.25.2) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.25.1...v6.25.2) ##### Bug Fixes - **types:** fix TS 4.9 excessive depth error on `InferAttributes` (v6) ([#​15135](https://togithub.com/sequelize/sequelize/issues/15135)) ([851daaf](https://togithub.com/sequelize/sequelize/commit/851daafc73ff218f7de4455fe9f96eb896106210)) ### [`v6.25.1`](https://togithub.com/sequelize/sequelize/releases/tag/v6.25.1) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.25.0...v6.25.1) ##### Bug Fixes - **types:** expose legacy "types" folder in export alias ( [#​15123](https://togithub.com/sequelize/sequelize/issues/15123)) ([9dd93b8](https://togithub.com/sequelize/sequelize/commit/9dd93b8461b0ff0452d7db998d0686c3ef176150)) ### [`v6.25.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.25.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.24.0...v6.25.0) ##### Features - **oracle:** add support for `dialectOptions.connectString` ([#​15042](https://togithub.com/sequelize/sequelize/issues/15042)) ([06ad05d](https://togithub.com/sequelize/sequelize/commit/06ad05df260a745cf97bc8e7365c74aea57e5220)) ### [`v6.24.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.24.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.23.2...v6.24.0) ##### Features - **snowflake:** Add support for `QueryGenerator#tableExistsQuery` ([#​15087](https://togithub.com/sequelize/sequelize/issues/15087)) ([a44772e](https://togithub.com/sequelize/sequelize/commit/a44772ec58175cfdc2cea84eb359966e48ed1c7b)) ### [`v6.23.2`](https://togithub.com/sequelize/sequelize/releases/tag/v6.23.2) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.23.1...v6.23.2) ##### Bug Fixes - **postgres:** add custom order direction to subQuery ordering with minified alias ([#​15056](https://togithub.com/sequelize/sequelize/issues/15056)) ([7203b66](https://togithub.com/sequelize/sequelize/commit/7203b6626ed38c06f91f09f73571fb7df56fe348)) ### [`v6.23.1`](https://togithub.com/sequelize/sequelize/releases/tag/v6.23.1) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.23.0...v6.23.1) ##### Bug Fixes - **oracle:** add support for Oracle DB 18c CI ([#​15016](https://togithub.com/sequelize/sequelize/issues/15016)) ([5f621d7](https://togithub.com/sequelize/sequelize/commit/5f621d72c1f265bb7659b54eb33469db8a4443fd)), closes [#​1](https://togithub.com/sequelize/sequelize/issues/1) [#​7](https://togithub.com/sequelize/sequelize/issues/7) [#​9](https://togithub.com/sequelize/sequelize/issues/9) [#​13](https://togithub.com/sequelize/sequelize/issues/13) [#​14](https://togithub.com/sequelize/sequelize/issues/14) [#​16](https://togithub.com/sequelize/sequelize/issues/16) ### [`v6.23.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.23.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.22.1...v6.23.0) ##### Features - **types:** add typescript 4.8 compatibility ([#​14990](https://togithub.com/sequelize/sequelize/issues/14990)) ([3468378](https://togithub.com/sequelize/sequelize/commit/34683786d7ec832b179845188076ea2121ea78ff)) ### [`v6.22.1`](https://togithub.com/sequelize/sequelize/releases/tag/v6.22.1) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.22.0...v6.22.1) ##### Bug Fixes - **types:** missing type for oracle dialect in v6 ([#​14992](https://togithub.com/sequelize/sequelize/issues/14992)) ([1da6657](https://togithub.com/sequelize/sequelize/commit/1da6657de18fc4918dc165f61aedf8888faa3704)), closes [#​14991](https://togithub.com/sequelize/sequelize/issues/14991) ### [`v6.22.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.22.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.21.6...v6.22.0) ##### Features - **oracle:** add oracle dialect support ([#​14638](https://togithub.com/sequelize/sequelize/issues/14638)) ([c230d80](https://togithub.com/sequelize/sequelize/commit/c230d80676450169d9cd74fe4cdf0da261de77b8)), closes [#​1](https://togithub.com/sequelize/sequelize/issues/1) [#​7](https://togithub.com/sequelize/sequelize/issues/7) [#​9](https://togithub.com/sequelize/sequelize/issues/9) [#​13](https://togithub.com/sequelize/sequelize/issues/13) [#​14](https://togithub.com/sequelize/sequelize/issues/14) [#​16](https://togithub.com/sequelize/sequelize/issues/16) ### [`v6.21.6`](https://togithub.com/sequelize/sequelize/releases/tag/v6.21.6) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.21.5...v6.21.6) ##### Bug Fixes - **types:** backport [#​14704](https://togithub.com/sequelize/sequelize/issues/14704) for v6 ([#​14964](https://togithub.com/sequelize/sequelize/issues/14964)) ([33d94b2](https://togithub.com/sequelize/sequelize/commit/33d94b223988d29bf1032ea2b589797664310839)) ### [`v6.21.5`](https://togithub.com/sequelize/sequelize/releases/tag/v6.21.5) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.21.4...v6.21.5) ##### Bug Fixes - **mariadb:** do not automatically parse JSON fields ([#​14800](https://togithub.com/sequelize/sequelize/issues/14800)) ([d047f32](https://togithub.com/sequelize/sequelize/commit/d047f3275a451df73294f222c8a2c99ffdd22299)) ### [`v6.21.4`](https://togithub.com/sequelize/sequelize/releases/tag/v6.21.4) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.21.3...v6.21.4) ##### Bug Fixes - minified aliases are now properly referenced in subqueries (v6) ([#​14852](https://togithub.com/sequelize/sequelize/issues/14852)) ([5a257bc](https://togithub.com/sequelize/sequelize/commit/5a257bc93c7e760f6b0158f55b3cb48878698450)), closes [#​14804](https://togithub.com/sequelize/sequelize/issues/14804) ### [`v6.21.3`](https://togithub.com/sequelize/sequelize/releases/tag/v6.21.3) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.21.2...v6.21.3) ##### Bug Fixes - **postgres:** attach postgres error-handler earlier in lifecycle (v6) ([#​14731](https://togithub.com/sequelize/sequelize/issues/14731)) ([90bb694](https://togithub.com/sequelize/sequelize/commit/90bb69485021344351732dcafe31cb67a54175f7)) ### [`v6.21.2`](https://togithub.com/sequelize/sequelize/releases/tag/v6.21.2) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.21.1...v6.21.2) ##### Bug Fixes - properly escape multiple `$` in `fn` args ([#​14678](https://togithub.com/sequelize/sequelize/issues/14678)) ([7bb60e3](https://togithub.com/sequelize/sequelize/commit/7bb60e3531127da684cc1f75307410c53dfc9c8c)) ### [`v6.21.1`](https://togithub.com/sequelize/sequelize/releases/tag/v6.21.1) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.21.0...v6.21.1) ##### Bug Fixes - **postgres:** use schema set in sequelize config by default ([#​14665](https://togithub.com/sequelize/sequelize/issues/14665)) ([2f3b924](https://togithub.com/sequelize/sequelize/commit/2f3b9247ad4ef74d1ec1027562eaafb6b1e9755f)) ### [`v6.21.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.21.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.20.1...v6.21.0) ##### Features - exports types to support typescript >= 4.5 nodenext module ([#​14620](https://togithub.com/sequelize/sequelize/issues/14620)) ([cbdf73e](https://togithub.com/sequelize/sequelize/commit/cbdf73e9ee52ebebf92679b183ce95c760e914db)) ### [`v6.20.1`](https://togithub.com/sequelize/sequelize/releases/tag/v6.20.1) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.20.0...v6.20.1) ##### Bug Fixes - kill connection on commit/rollback error ([#​14535](https://togithub.com/sequelize/sequelize/issues/14535)) ([e1a9c28](https://togithub.com/sequelize/sequelize/commit/e1a9c28375e3bdd11347835b2f796290638ad58a)) ### [`v6.20.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.20.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.19.2...v6.20.0) ##### Features - support cyclic foreign keys ([#​14499](https://togithub.com/sequelize/sequelize/issues/14499)) ([b37df96](https://togithub.com/sequelize/sequelize/commit/b37df964333c39b9e19daa9a2c45c1d0bb475433)) ### [`v6.19.2`](https://togithub.com/sequelize/sequelize/releases/tag/v6.19.2) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.19.1...v6.19.2) ##### Bug Fixes - accept replacements in `ARRAY[]` & followed by `;` ([#​14518](https://togithub.com/sequelize/sequelize/issues/14518)) ([e37c572](https://togithub.com/sequelize/sequelize/commit/e37c57255fbd77244be22dc57d0a86490597831a)) ### [`v6.19.1`](https://togithub.com/sequelize/sequelize/releases/tag/v6.19.1) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.19.0...v6.19.1) ##### Bug Fixes - do not replace `:replacements` inside of strings ([#​14472](https://togithub.com/sequelize/sequelize/issues/14472)) ([ccaa399](https://togithub.com/sequelize/sequelize/commit/ccaa3996047fe00048d5993ab2dd43ebadd4f78b)) ⚠️ BREAKING CHANGE: This change is a security fix that patches a serious SQL injection vulnerability, however it is possible that your application made use of it and broke as a result of this change. [Please see this issue for more information](https://togithub.com/sequelize/sequelize/issues/14519). ### [`v6.19.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.19.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.18.0...v6.19.0) ##### Bug Fixes - **types:** make `WhereOptions` more accurate ([#​14368](https://togithub.com/sequelize/sequelize/issues/14368)) ([0d0aade](https://togithub.com/sequelize/sequelize/commit/0d0aadec98871d704743563585eacf87b3403517)) ##### Features - **types:** make `Model.init` aware of pre-configured foreign keys ([#​14370](https://togithub.com/sequelize/sequelize/issues/14370)) ([5954d2c](https://togithub.com/sequelize/sequelize/commit/5954d2cae542f8e4bd3351bc9d55b6880bd751c3)) ### [`v6.18.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.18.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.17.0...v6.18.0) ##### Features - add whereScopeStrategy to merge where scopes with Op.and ([#​14152](https://togithub.com/sequelize/sequelize/issues/14152)) ([8349c02](https://togithub.com/sequelize/sequelize/commit/8349c02c5130fc431adec265e3a3ad043571f1b9)) ### [`v6.17.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.17.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.16.3...v6.17.0) ##### Bug Fixes - fix typo in query-generator.js error message ([#​14151](https://togithub.com/sequelize/sequelize/issues/14151)) ([2d339d0](https://togithub.com/sequelize/sequelize/commit/2d339d0799d224dca79037e8465cf48abef496a8)) - **postgres:** correctly re-acquire connection for pg-native ([#​14090](https://togithub.com/sequelize/sequelize/issues/14090)) ([82506a6](https://togithub.com/sequelize/sequelize/commit/82506a68dbb33e4824ed6b8462cedf52d90d8cfc)) - **types:** drop excess argument for upsert ([#​14156](https://togithub.com/sequelize/sequelize/issues/14156)) ([da8678d](https://togithub.com/sequelize/sequelize/commit/da8678dec6ee6b8e427701e88d7db6810e990f82)) - **types:** export `GroupedCountResultItem` interface ([#​14154](https://togithub.com/sequelize/sequelize/issues/14154)) ([a81b7ab](https://togithub.com/sequelize/sequelize/commit/a81b7ab38da7fea07e00114e88711fbfed9f9a34)) - **types:** update 'replication' option property ([#​14126](https://togithub.com/sequelize/sequelize/issues/14126)) ([7ac1221](https://togithub.com/sequelize/sequelize/commit/7ac122163f63ced2e24dac1d73e0be298f686187)) - **types:** update return type of `Model.update` ([#​14155](https://togithub.com/sequelize/sequelize/issues/14155)) ([b80aeed](https://togithub.com/sequelize/sequelize/commit/b80aeed3c4eccc98da78927e91483ca41035dffe)) ##### Features - **types:** infer nullable creation attributes as optional ([#​14147](https://togithub.com/sequelize/sequelize/issues/14147)) ([f5c06bd](https://togithub.com/sequelize/sequelize/commit/f5c06bd493670a37ba6d6ed039d44ccdf79b126e)) - **types:** make `Model.getAttributes` stricter ([#​14017](https://togithub.com/sequelize/sequelize/issues/14017)) ([e974e20](https://togithub.com/sequelize/sequelize/commit/e974e202ca755a008f450c88123fc166a5497bb2)) ### [`v6.16.3`](https://togithub.com/sequelize/sequelize/releases/tag/v6.16.3) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.16.2...v6.16.3) ##### Bug Fixes - **types:** support union in CreationAttributes ([#​14146](https://togithub.com/sequelize/sequelize/issues/14146)) ([d23bd7a](https://togithub.com/sequelize/sequelize/commit/d23bd7a7e2aac095f8b210f8d0e0f060c215475f)) ### [`v6.16.2`](https://togithub.com/sequelize/sequelize/releases/tag/v6.16.2) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.16.1...v6.16.2) ##### Bug Fixes - **types:** missing snowflake and db2 dialects ([#​14137](https://togithub.com/sequelize/sequelize/issues/14137)) ([0326c2c](https://togithub.com/sequelize/sequelize/commit/0326c2caee201ee7288eb917cb3facd5aefd9b12)) ### [`v6.16.1`](https://togithub.com/sequelize/sequelize/releases/tag/v6.16.1) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.16.0...v6.16.1) ##### Bug Fixes - correct path to `package.json` in Sequelize.version ([#​14073](https://togithub.com/sequelize/sequelize/issues/14073)) ([b95c213](https://togithub.com/sequelize/sequelize/commit/b95c213909ce084ffd98f9e98c9cf881841e27f1)) ### [`v6.16.0`](https://togithub.com/sequelize/sequelize/releases/tag/v6.16.0) [Compare Source](https://togithub.com/sequelize/sequelize/compare/v6.15.1...v6.16.0) ##### Features - gen /lib & /types from /src & drop /dist (v6) ([#​14063](https://togithub.com/sequelize/sequelize/issues/14063)) ([6b8fbb4](https://togithub.com/sequelize/sequelize/commit/6b8fbb48d0d12f2c500f69ce79f7f54386c32b40))