tonesto7 / homebridge-hubitat-tonesto7

Hubitat Homebridge Plugin
109 stars 34 forks source link

[Snyk] Upgrade express from 4.18.2 to 4.18.3 #217

Closed tonesto7 closed 2 months ago

tonesto7 commented 8 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade express from 4.18.2 to 4.18.3.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **1 version** ahead of your current version. - The recommended version was released **21 days ago**, on 2024-02-29. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Cross-site Request Forgery (CSRF)
[SNYK-JS-AXIOS-6032459](https://snyk.io/vuln/SNYK-JS-AXIOS-6032459) | **676/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.1 | Proof of Concept | Prototype Pollution
[SNYK-JS-AXIOS-6144788](https://snyk.io/vuln/SNYK-JS-AXIOS-6144788) | **676/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.1 | No Known Exploit | Improper Input Validation
[SNYK-JS-FOLLOWREDIRECTS-6141137](https://snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6141137) | **676/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.1 | Proof of Concept | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-AXIOS-6124857](https://snyk.io/vuln/SNYK-JS-AXIOS-6124857) | **676/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.1 | Proof of Concept | Information Exposure
[SNYK-JS-FOLLOWREDIRECTS-6444610](https://snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6444610) | **676/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.1 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: express from express GitHub release notes
Commit messages
Package name: express
  • 1b51eda 4.18.3
  • b625132 build: pin Node 21.x to minor
  • e3eca80 build: pin Node 21.x to minor
  • 23b44b3 build: support Node.js 21.6.2
  • b9fea12 build: support Node.js 21.x in appveyor
  • c259c34 build: support Node.js 21.x
  • fdeb1d3 build: support Node.js 20.x in appveyor
  • 734b281 build: support Node.js 20.x
  • 0e3ab6e examples: improve view count in cookie-sessions
  • 59af63a build: Node.js@18.19
  • e720c5a docs: add documentation for benchmarks
  • 3abea7f examples: remove multipart example
  • 2a89eb5 tests: fix handling multiple callbacks
  • 59aae76 docs: add project captains to contribution
  • c4fe7de docs: update TC governance rules
  • a229207 build: actions/checkout@v4
  • 02d1c39 build: Node.js@19.9
  • 8d8bfaa build: Node.js@18.17
  • 13df1de build: eslint@8.47.0
  • 2a00da2 tests: use random port in listen test
  • 24e4a25 build: Node.js@16.20
  • 91b6fb8 build: use nyc@14.1.1 for Node.js < 10
  • 3531987 lint: remove unused function arguments in Route tests
  • f540c3b build: Node.js@18.15
Compare

**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/tonesto7/project/878dfb67-a805-4269-9dee-3d86542bb748?utm_source=github&utm_medium=referral&page=upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/tonesto7/project/878dfb67-a805-4269-9dee-3d86542bb748/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/tonesto7/project/878dfb67-a805-4269-9dee-3d86542bb748/settings/integration?pkg=express&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)
github-actions[bot] commented 2 months ago

This pull request has been marked stale automatically after no activity for the last 180 days.