Skip to content

[Snyk] Fix for 1 vulnerabilities#23

Open
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-c4e1c67ccd1a77b1408ff693eec7b36b
Open

[Snyk] Fix for 1 vulnerabilities#23
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-c4e1c67ccd1a77b1408ff693eec7b36b

Conversation

@snyk-bot
Copy link
Copy Markdown

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-LODASH-567746
Yes Proof of Concept
Commit messages
Package name: cheerio The new version differs by 106 commits.

See the full diff

Package name: express-validator The new version differs by 44 commits.

See the full diff

Package name: helmet The new version differs by 37 commits.
  • e99bcb8 0.8.0
  • 9a1262b Prepare changelog for 0.8.0 release
  • f22cb82 More notes that this is an HTTP header module
  • 4344ee7 Minor: changelog order should be new, update, fix, remove
  • e0c3039 Add "deprecate crossdomain" notes to history file
  • bf65c0f Deprecate crossdomain in the code and add relevant tests
  • ecf4f40 Remove "crossdomain.xml" from npm keywords
  • ddc4ce8 Remove crossdomain from the readme
  • 86da539 Bump frameguard to 0.2.2
  • 10ddccf Update CSP and HSTS modules to latest
  • d89df25 Small readme tweaks
  • 6907874 Recommend express-content-length-validator module
  • fed5bfd Readme: disclaimer in recommended modules section
  • 013a135 0.7.1
  • 1c2bc50 Bump dependency versions
  • 8864c69 Readme: Used to be 9, now is 10 middlewares
  • 56b0844 Recommend HPP module
  • 64f8cd8 0.7.0
  • 0697d1c Update history
  • 9a2e0e6 Add note about default middlewares
  • a6ee110 Add hpkp
  • e913076 Update Travis config to use Node 0.12
  • 7798164 Add "minor code cleanup" to unreleased history
  • 3379d9c 0.6.2

See the full diff

Package name: node-linkedin The new version differs by 62 commits.

See the full diff

Package name: stripe The new version differs by 51 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-LODASH-567746
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant