vlasn / mets-be

Metsahaldur backend
0 stars 1 forks source link

[Snyk] Security upgrade express-fileupload from 0.1.4 to 1.1.8 #31

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-EXPRESSFILEUPLOAD-595969
Yes Proof of Concept
Commit messages
Package name: express-fileupload The new version differs by 250 commits.
  • 829f395 version bump
  • db49535 Merge pull request #237 from richardgirges/fix-236-proto-pollution
  • d81bee9 Upgrade latest packages; run npm audit fix; add logic to prevent prototype pollution in parseNested
  • e9848fc Update package-lock.json
  • d536cfb Update package.json
  • c7a6b9c Merge pull request #233 from RomanBurunkov/master
  • a53b93f Update tests to support empty files
  • d8c00c5 Add empty files support for tempFileHandler
  • b24233d Comment extra condition in fileFactory(issue #1), add more logging
  • d57ee02 Formatting utilities
  • b6097df Merge pull request #232 from RomanBurunkov/master
  • 05004b7 Merge pull request #230 from Code42Cate/readme-timeout
  • 1afa527 Update dependencies
  • 880c2b7 Improve timeout option documentation
  • 3f130b0 Add timeout option to README.MD
  • d55fa83 Merge pull request #222 from wbt/patch-1
  • d61f02f Fix some small typos
  • f20389a Merge pull request #219 from wbt/patch-1
  • b95d3c7 Small typo fix usefull => useful
  • 0f1ff52 Merge pull request #214 from RomanBurunkov/master
  • 2257106 Update package.json
  • 62e3419 Merge pull request #213 from RomanBurunkov/master
  • 055ceac Destroy file stream in case of upload timeout.
  • 5fb6150 Add debug loggin for temp file cleaning up insted throwing error
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic