[Snyk] Upgrade: dotenv, farmhash, fs-extra, fuse.js, js2xmlparser, rate-limiter-flexible, request-ip, svcorelib, url-parse, xss#38
Open
usernamerandom11 wants to merge 1 commit intomasterfrom
Conversation
Snyk has created this PR to upgrade:
- dotenv from 8.2.0 to 8.6.0.
See this package in npm: https://www.npmjs.com/package/dotenv
- farmhash from 3.1.0 to 3.3.1.
See this package in npm: https://www.npmjs.com/package/farmhash
- fs-extra from 9.0.1 to 9.1.0.
See this package in npm: https://www.npmjs.com/package/fs-extra
- fuse.js from 6.4.1 to 6.6.2.
See this package in npm: https://www.npmjs.com/package/fuse.js
- js2xmlparser from 4.0.1 to 4.0.2.
See this package in npm: https://www.npmjs.com/package/js2xmlparser
- rate-limiter-flexible from 2.2.1 to 2.4.2.
See this package in npm: https://www.npmjs.com/package/rate-limiter-flexible
- request-ip from 2.1.3 to 2.2.0.
See this package in npm: https://www.npmjs.com/package/request-ip
- svcorelib from 1.11.1 to 1.18.2.
See this package in npm: https://www.npmjs.com/package/svcorelib
- url-parse from 1.4.7 to 1.5.10.
See this package in npm: https://www.npmjs.com/package/url-parse
- xss from 1.0.8 to 1.0.15.
See this package in npm: https://www.npmjs.com/package/xss
See this project in Snyk:
https://app.snyk.io/org/mail-in4/project/98814f29-04d4-4b2c-ae9b-87ecf84a61a2?utm_source=github&utm_medium=referral&page=upgrade-pr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
dotenv
from 8.2.0 to 8.6.0 | 5 versions ahead of your current version | 3 years ago
on 2021-05-05
farmhash
from 3.1.0 to 3.3.1 | 6 versions ahead of your current version | 5 months ago
on 2024-04-17
fs-extra
from 9.0.1 to 9.1.0 | 1 version ahead of your current version | 4 years ago
on 2021-01-19
fuse.js
from 6.4.1 to 6.6.2 | 12 versions ahead of your current version | 2 years ago
on 2022-05-11
js2xmlparser
from 4.0.1 to 4.0.2 | 1 version ahead of your current version | 3 years ago
on 2021-10-31
rate-limiter-flexible
from 2.2.1 to 2.4.2 | 19 versions ahead of your current version | a year ago
on 2023-07-27
request-ip
from 2.1.3 to 2.2.0 | 1 version ahead of your current version | 2 years ago
on 2022-06-01
svcorelib
from 1.11.1 to 1.18.2 | 12 versions ahead of your current version | 2 years ago
on 2023-02-20
url-parse
from 1.4.7 to 1.5.10 | 11 versions ahead of your current version | 3 years ago
on 2022-02-22
xss
from 1.0.8 to 1.0.15 | 7 versions ahead of your current version | 6 months ago
on 2024-03-03
Issues fixed by the recommended upgrade:
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-URLPARSE-2407770
SNYK-JS-XSS-1584355
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-SIMPLEGET-2361683
SNYK-JS-URLPARSE-2407759
SNYK-JS-URLPARSE-2412697
SNYK-JS-MINIMATCH-3050818
SNYK-JS-URLPARSE-1078283
SNYK-JS-URLPARSE-1533425
SNYK-JS-URLPARSE-2401205
Release notes
Package name: dotenv
-
8.6.0 - 2021-05-05
-
8.5.1 - 2021-05-05
-
8.5.0 - 2021-05-05
-
8.4.0 - 2021-05-05
-
8.3.0 - 2021-05-05
-
8.2.0 - 2019-10-16
from dotenv GitHub release notesShow as 'added' in changelog
Bump version 8.5.1
Bump version 8.5.0
Point to types file for VS Code. Bump 8.4.0
Drop node 8 support
chore(release): 8.2.0
Package name: farmhash
-
3.3.1 - 2024-04-17
-
3.3.0 - 2023-02-04
-
3.2.2 - 2021-12-03
-
3.2.1 - 2021-03-23
-
3.2.0 - 2020-12-01
-
3.1.1 - 2020-11-05
-
3.1.0 - 2020-05-06
from farmhash GitHub release notesNo content.
No content.
No content.
No content.
No content.
No content.
No content.
Package name: fs-extra
-
9.1.0 - 2021-01-19
-
9.0.1 - 2020-06-04
from fs-extra GitHub release notes9.1.0
9.0.1
Package name: fuse.js
-
6.6.2 - 2022-05-11
- value fetched at the end must be a string (1de1dff), closes #661
-
6.6.1 - 2022-05-06
- typescript: Change
- typescript: type definition for
-
6.6.0 - 2022-05-03
- allow passing getFn for a specific key (1d445b9), closes #627
- excessive splitting in parseQuery (2c78022)
- type mismatch on toJSON (f5425ea)
-
6.5.3 - 2021-12-23
- logical: scoring for logical OR (6f6af51), closes #593
-
6.5.2 - 2021-12-23
-
6.5.1 - 2021-12-23
- rollback min node version (9918f67)
-
6.5.0 - 2021-12-22
-
6.4.6 - 2021-01-05
- typescript: fix search typings (94766b2), closes #527
-
6.4.5 - 2021-01-01
- typescript: export
-
6.4.4 - 2020-12-29
- extended: correctly score include-match results (443c863), closes #522
-
6.4.3 - 2020-10-30
-
6.4.2 - 2020-10-20
-
6.4.1 - 2020-07-26
from fuse.js GitHub release notesBug Fixes
Bug Fixes
fieldNormWeightto be optional, fixes [#658]FuseOptionKeyObject, fixes [#655] and [#656]Features
Bug Fixes
6.5.3 (2021-12-23)
Bug Fixes
6.5.2 (2021-12-23)
Purely created this version as minification failed in the prior one.
6.5.1 (2021-12-23)
Bug Fixes
chore(release): 6.5.0
Bug Fixes
Bug Fixes
FuseIndextype (2e60bee), closes #519Bug Fixes
Package name: js2xmlparser
-
4.0.2 - 2021-10-31
- Update dependencies
- Export options interfaces in main module
- Update example to include root attribute
-
4.0.1 - 2020-02-02
- Update dependencies
- Use ESLint instead of TSLint
- Use npm instead of gulp
from js2xmlparser GitHub release notesPackage name: rate-limiter-flexible
-
2.4.2 - 2023-07-27
-
2.4.1 - 2022-10-24
-
2.4.0 - 2022-10-21
-
2.3.12 - 2022-10-13
-
2.3.11 - 2022-09-25
- RateLimiterQueue
- clear timeout on key delete from memory storage. #146 Thank you @ jiddmeye
- fix negative remaining points in memory limiter. #172 Thank you @ MiniKraken-Team
- added
- use
-
2.3.10 - 2022-09-12
-
2.3.9 - 2022-09-06
-
2.3.8 - 2022-07-29
-
2.3.7 - 2022-05-01
-
2.3.6 - 2021-12-01
-
2.3.5 - 2021-11-21
-
2.3.4 - 2021-11-09
- MongoDB version detection is fixed for
- MongoDB version detection is fixed for 3.6.7+. Thank you @ pavittarx
- Internal fix of
- TypeScript type for
- TypeScript type for
-
2.3.3 - 2021-11-01
-
2.3.2 - 2021-10-26
-
2.3.1 - 2021-10-02
-
2.3.0 - 2021-09-28
- replace
- new
- @ evan361425 also added tests to cover new lines 🥇
-
2.2.4 - 2021-07-24
-
2.2.3 - 2021-07-10
- Missing get/set Typescript types added and documentation improved. Thanks @ rijkvanzanten
- mongodb client v4 support. Thank you @ backflip
-
2.2.2 - 2021-05-04
-
2.2.1 - 2021-01-10
- TypeORM Support for RateLimitPostgres, thank you @ seromenho
- Readme links fixed, thanks @ mriedem
- RateLimiterQueue TS types fixed
- Fix postgres consumed points increment on block, issue #95
from rate-limiter-flexible GitHub release notesThank you @ dmozgovoi for the quick improvement.
In some cases especially with insuranceLimiter set it is important to reject requests quickly based on Redis client status being not
ready. Thanks @ dmozgovoiThank you @ svsool
getTokensRemainingwith RateLimiterPostgres fixed. #125clearExpiredByTimeoutis added to TS types for MySQL and Postgres limiters. #156browserpackage.json settings to allow bundling. 6ce34b3 Thank you @ achingbrainnodejs.util.inspect.customfor Symbol flexibility. 2c8bedb Thank you @ shlavikinmemoryBlockOnConsumedandinmemoryBlockDurationoptions are renamed toinMemoryBlockOnConsumedandinMemoryBlockDuration. Old options are still supported, but deprecated and will be removed in v3 major release. #106mongooseclient. Thank you @ adrianvlupugetmethod. It incorrectly processedundefinedresult from a store. Thank you @ animir.editorconfigadded. Thank you @ vinibeloniRateLimiterQueueErroradded. Thank you @ adilhafeezdeleteInMemoryBlockedAllmethod is added. Thank you @ animirreplaceOnewithfindOneAndUpdateto fix a bug related to absentopsattribute in MongoDB client v4+. Thank you @ vdiezdeletemethod on any store limiter deletes inMemoryBlocked key if it is there. Thank you @ evan361425deleteInMemoryBlockedAllmethod added to clean up all blocked keys at once. Thank you @ evan361425 again :-)Package name: request-ip
-
2.2.0 - 2022-06-01
-
2.1.3 - 2018-10-29
from request-ip GitHub release notes2.2.0
bump version number and add new build
Package name: svcorelib
-
1.18.2 - 2023-02-20
- Made
- Corrected wrong color code for
- Fixed docs in a few places
-
1.18.1 - 2022-10-11
- Fix some TS typings
-
1.18.0 - 2022-10-11
- Additions
- Fixes
- Reverted dynamic imports issue #51
- Support Error options issue #52
-
1.17.0 - 2022-08-13
- Additions
- Added function
- Added function
- Added function
- Added function
- colors
- Added
- Added
- Breaking changes
- Changed state
- colors
- Removed brightness modifier from
- Renamed
- Fixes
- Added missing documentation for
- Fixed docs in various places
-
1.16.0 - 2022-06-29
- Additions
- Added clamp() to ensure a number is between a min and max limit
- Fixes
- randRange() now doesn't depend on the
- Updated deps
-
1.15.0 - 2022-06-15
- Breaking changes
- Shortened namespace names:
- Renamed functions:
- Additions
- Added function
- Added function
- Added function
- Added function
- Fixes
- Fixed missing argument in
- Updated dependencies
-
1.14.2 - 2021-08-08
- Fixes
- Fixed
- Fixed
- Set
- Improved documentation a little bit
- Internal stuff
- Added CodeQL analysis workflow
-
1.14.1 - 2021-06-07
-
1.14.0 - 2021-05-11
- Additions
- Added class
- Added single-parameter overload to
- Added string array overload to
- Changes
- Moved repository to @ Sv443-Network
- Improved type declaration file (
- Security
- Audited dependencies
-
1.13.1 - 2021-03-30
-
1.13.0 - 2021-03-17
- You will need to modify all occurrences of
- The namespace of a few functions has changed (see changes)
- Replaced
- Added base class
- Moved a few functions to the new
- Package
- Definition of
-
1.12.0 - 2021-01-26
-
1.11.1 - 2020-08-31
from svcorelib GitHub release notesFixes:
system.inDebugger()no longer dependant on V8'sinspectormodule which errored in environments likepkgcolors.fatFixes:
splitIntoParts()function to split an array into n partssplitIntoPartsOfLength()function to split an array into parts of n lengthallInstanceOf()to check if all items in an array are an instance of a classisClass()to check if a value is a reference to a classrandomItemIndex()to get a random item and its index from an arraytakeRandomItem()to delete a random item from an array and return itcolors.fgbandcolors.bgbfor bright colorsdim,underscore,reverseandhiddenfulfilledtoresolvedin StatePromisecolors.fgandcolors.bgcolors.fattocolors.brightallOfType()performancemodule anymoregenerateUUID->uuidfilesystem->filesseededRNG.generateRandomSeed()->seededRNG.randomSeed()seededRNG.generateRandomNumbers()->seededRNG.generateNumbers()pause()->system.pause()halves()to get the two halves of an arrayparseDuration()to parse out time units from a passed duration in millisecondsformatDuration()to convert a duration in milliseconds to a string with custom formatfiles.existsSync()as a synchronous counterpart tofiles.exists()SelectionMenunow supports EventEmitter's.on("submit")methodreserialize()now keeps the type of the passed object (#38)seededRNG.validateSeed()now returns false when a seed starts with0(#34)system.inDebugger()(#37).d.tstype declarations (#27)system.inDebugger()not detecting debugger (#30)mysqlas a peer dependency (#29)Fixed bug where
filesystem.exists()wasn't exported (see #25)StatePromisethat keeps track of the state of a promiserandRange()generateUUID.custom(), deprecated older overloadsoftShutdown()now accepts a Promise for async code execution before shutdown.d.ts) by a lotMigration warnings:
FolderDaemonwith the new syntax shown in the docsAdded functions:
filesystem.exists()to provide a reimplementation tofs' deprecatedexists()function (#14)filesystem.ensureDirs()to ensure a set of directories exists (#18)filesystem.ensureDirsSync()as a synchronous counterpart toensureDirs()(#18)system.usedHeap()to get the current heap usage in percent (#19)Changes:
FolderDaemon's configuration parameters with a single settings object (#13)SCLErrorto all errors to implement thedateproperty (#17)systemnamespace:noShutdown()- moved tosystemyesShutdown()- moved tosystemsoftShutdown()- moved tosysteminDebugger()- moved tosystemsetWindowTitle()- moved tosystemFixed bugs:
isEmpty()with valuenullthrew a TypeError (#15)mysqlisn't included in the dependencies (#21)system.softShutdown()'s callback function was wrong (#20)Package name: url-parse
-
1.5.10 - 2022-02-22
-
1.5.9 - 2022-02-20
-
1.5.8 - 2022-02-19
-
1.5.7 - 2022-02-16
-
1.5.6 - 2022-02-13
-
1.5.5 - 2022-02-13
-
1.5.4 - 2021-12-28
-
1.5.3 - 2021-07-25
-
1.5.2 - 2021-07-25
-
1.5.1 - 2021-02-18
-
1.5.0 - 2021-02-17
-
1.4.7 - 2019-04-26
from url-parse GitHub release notes1.5.10
1.5.9
1.5.8
1.5.7
1.5.6
1.5.5
[dist] 1.5.4
[dist] 1.5.3
[dist] 1.5.2
[dist] 1.5.1
Package name: xss
-
1.0.15 - 2024-03-03
-
1.0.14 - 2022-08-16
-
1.0.13 - 2022-06-06
-
1.0.12 - 2022-06-03
-
1.0.11 - 2022-03-06
-
1.0.10 - 2021-10-08
-
1.0.9 - 2021-05-06
-
1.0.8 - 2020-07-27
from xss GitHub release notesv1.0.15
v1.0.14
v1.0.13
No content.
v1.0.11
v1.0.10
No content.
v1.0.8
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: