Skip to content

Conversation

@BodhithaW
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

ejs
from 3.1.6 to 3.1.10 | 4 versions ahead of your current version | 5 months ago
on 2024-04-12
express
from 4.17.1 to 4.19.2 | 9 versions ahead of your current version | 6 months ago
on 2024-03-25
express-validator
from 6.12.1 to 6.15.0 | 7 versions ahead of your current version | 2 years ago
on 2023-02-16
mongoose
from 5.13.7 to 5.13.22 | 15 versions ahead of your current version | 8 months ago
on 2024-01-02
sequelize
from 6.6.5 to 6.37.3 | 77 versions ahead of your current version | 5 months ago
on 2024-04-13

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-DOTTIE-3332763
586 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-EJS-2803307
586 Proof of Concept
high severity Prototype Poisoning
SNYK-JS-QS-3153490
586 Proof of Concept
high severity Directory Traversal
SNYK-JS-MOMENT-2440688
586 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
586 Proof of Concept
high severity Prototype Pollution
SNYK-JS-MONGOOSE-2961688
586 Proof of Concept
high severity Prototype Pollution
SNYK-JS-MONGOOSE-5777721
586 Proof of Concept
high severity SQL Injection
SNYK-JS-SEQUELIZE-2959225
586 No Known Exploit
high severity Improper Filtering of Special Elements
SNYK-JS-SEQUELIZE-3324088
586 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090600
586 Proof of Concept
medium severity Improper Control of Dynamically-Managed Code Resources
SNYK-JS-EJS-6689533
586 No Known Exploit
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
586 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-MPATH-1577289
586 Proof of Concept
critical severity SQL Injection
SNYK-JS-SEQUELIZE-2932027
586 Proof of Concept
medium severity Information Exposure
SNYK-JS-SEQUELIZE-3324089
586 No Known Exploit
medium severity Access of Resource Using Incompatible Type ('Type Confusion')
SNYK-JS-SEQUELIZE-3324090
586 No Known Exploit
Release notes
Package name: ejs from ejs GitHub release notes
Package name: express from express GitHub release notes
Package name: express-validator from express-validator GitHub release notes
Package name: mongoose
  • 5.13.22 - 2024-01-02
  • 5.13.21 - 2023-10-19
  • 5.13.20 - 2023-07-12
  • 5.13.19 - 2023-06-22
  • 5.13.18 - 2023-06-22
  • 5.13.17 - 2023-04-04
  • 5.13.16 - 2023-02-20
  • 5.13.15 - 2022-08-22
  • 5.13.14 - 2021-12-27
  • 5.13.13 - 2021-11-02
  • 5.13.12 - 2021-10-19
  • 5.13.11 - 2021-10-12
  • 5.13.10 - 2021-10-05
  • 5.13.9 - 2021-09-06
  • 5.13.8 - 2021-08-23
  • 5.13.7 - 2021-08-11
from mongoose GitHub release notes
Package name: sequelize
  • 6.37.3 - 2024-04-13

    6.37.3 (2024-04-13)

    Bug Fixes

    • postgres: use schema for foreign key constrains of a table (#17099) (6aba382)
  • 6.37.2 - 2024-03-29

    6.37.2 (2024-03-29)

    Bug Fixes

    • add readOnly to the transaction options types and docs (#17226) (7c8972f)
  • 6.37.1 - 2024-02-18

    6.37.1 (2024-02-18)

    Bug Fixes

    • types: Add definition of returning in SaveOptions. (#16954) (505467b)
  • 6.37.0 - 2024-02-11

    6.37.0 (2024-02-11)

    Features

    • postgres: support connectionTimeoutMillis dialectOption (#14119) (e81200e)
  • 6.36.0 - 2024-02-02
  • 6.35.2 - 2023-12-11
  • 6.35.1 - 2023-11-19
  • 6.35.0 - 2023-11-12
  • 6.34.0 - 2023-11-03
  • 6.33.0 - 2023-09-08
  • 6.32.1 - 2023-06-17
  • 6.32.0 - 2023-06-01
  • 6.31.1 - 2023-05-01
  • 6.31.0 - 2023-04-09
  • 6.30.0 - 2023-03-24
  • 6.29.3 - 2023-03-10
  • 6.29.2 - 2023-03-09
  • 6.29.1 - 2023-03-07
  • 6.29.0 - 2023-02-23
  • 6.28.2 - 2023-02-22
  • 6.28.1 - 2023-02-21
  • 6.28.0 - 2022-12-20
  • 6.27.0 - 2022-12-12
  • 6.26.0 - 2022-11-29
  • 6.25.8 - 2022-11-22
  • 6.25.7 - 2022-11-19
  • 6.25.6 - 2022-11-15
  • 6.25.5 - 2022-11-07
  • 6.25.4 - 2022-11-05
  • 6.25.3 - 2022-10-19
  • 6.25.2 - 2022-10-15
  • 6.25.1 - 2022-10-13
  • 6.25.0 - 2022-10-11
  • 6.24.0 - 2022-10-04
  • 6.23.2 - 2022-09-27
  • 6.23.1 - 2022-09-22
  • 6.23.0 - 2022-09-17
  • 6.22.1 - 2022-09-16
  • 6.22.0 - 2022-09-15
  • 6.21.6 - 2022-09-09
  • 6.21.5 - 2022-09-08
  • 6.21.4 - 2022-08-18
  • 6.21.3 - 2022-07-11
  • 6.21.2 - 2022-06-28
  • 6.21.1 - 2022-06-25
  • 6.21.0 - 2022-06-16
  • 6.20.1 - 2022-05-27
  • 6.20.0 - 2022-05-23
  • 6.19.2 - 2022-05-18
  • 6.19.1 - 2022-05-17
  • 6.19.0 - 2022-04-12
  • 6.18.0 - 2022-04-03
  • 6.17.0 - 2022-02-25
  • 6.16.3 - 2022-02-24
  • 6.16.2 - 2022-02-18
  • 6.16.1 - 2022-02-09
  • 6.16.0 - 2022-02-08
  • 6.15.1 - 2022-02-06 ...

Snyk has created this PR to upgrade:
  - ejs from 3.1.6 to 3.1.10.
    See this package in npm: https://www.npmjs.com/package/ejs
  - express from 4.17.1 to 4.19.2.
    See this package in npm: https://www.npmjs.com/package/express
  - express-validator from 6.12.1 to 6.15.0.
    See this package in npm: https://www.npmjs.com/package/express-validator
  - mongoose from 5.13.7 to 5.13.22.
    See this package in npm: https://www.npmjs.com/package/mongoose
  - sequelize from 6.6.5 to 6.37.3.
    See this package in npm: https://www.npmjs.com/package/sequelize

See this project in Snyk:
https://app.snyk.io/org/it20204334/project/c8624408-76ab-417f-9c10-46ce0f97c7f8?utm_source=github&utm_medium=referral&page=upgrade-pr
@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants