x-cold / yuque-hexo

同步语雀的文章到你的 Hexo 项目吧!
http://blog.lxstart.net/
MIT License
711 stars 83 forks source link

[Snyk] Security upgrade ali-oss from 6.8.0 to 6.17.0 #108

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity XML External Entity (XXE) Injection
SNYK-JS-JSTOXML-1017039
No No Known Exploit
Commit messages
Package name: ali-oss The new version differs by 238 commits.
  • b0f5930 chore: publish 6.17.0
  • 96141c6 chore: publish beta version
  • 4790a19 chore: build 6.17.0
  • e65ec97 chore: update 6.17.0 changelog
  • b2cef94 chore(release): 6.17.0
  • 7ece938 Merge branch 'master' of github.com:ali-sdk/ali-oss
  • a759699 chore: release 6.17.0 (#1047)
  • c884299 chore: document the completion
  • 45a0730 chore: rebuild
  • 95abe3b chore: rebuild
  • 7cf195f chore: use stream-http 2.8.2
  • 4f19fe6 fix(test): test case optimized (#1045)
  • e8eed0a fix(test): test case optimized (#1044)
  • 4fc3bd4 fix: fix list() and listV2() params and test case (#1043)
  • 9b0e299 chore:merge master
  • c60ae46 chore(test): test case optimized (#1041)
  • 17206a1 chore(CI):github action optimized (#1039)
  • 2bfd726 chore(CI):github action optimized (#1040)
  • 8e35cad chore(test case): fix test case (#1037)
  • f7e9255 chore: remove 6.17.0 changelog
  • 374231c chore: develop merge master (#1035)
  • 102f362 add multipartUploadCopy method (#1032)
  • 2678db8 fix: to append method signatureNotMath (#1033)
  • 78ffb5d fix: fix some test error and variable (#1030)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic