Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #62

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JS-APOLLOSERVERCORE-2928764
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @nestjs/graphql The new version differs by 250 commits.
  • 69b3d78 chore(): release v7.4.3
  • 278e091 fix(plugin): add test for optional booleans (strict mode)
  • c6160e9 fix(): add symbol to query if used as return type #979
  • 1bc1026 Merge pull request #990 from nestjs/renovate/uuid-8.x
  • 138180a fix(deps): update dependency uuid to v8.2.0
  • c18d77c chore(deps): update dependency jest to v26.1.0
  • 631d2cf chore(): update apollo federation deps
  • 3e80bd6 chore(): release v7.4.2
  • 9f7b973 Merge pull request #958 from timhall/fix-object-extension
  • 0466104 Merge pull request #967 from nestjs/renovate/fast-glob-3.x
  • e1d65c3 Merge pull request #978 from nestjs/dependabot/npm_and_yarn/apollo-server-core-2.15.0
  • 135a396 fix(): add enhancer type to the public api
  • 685bef3 Merge branch 'master' of https://github.com/nestjs/graphql
  • f5dd302 fix(): add more descriptive message when no type defs found
  • 24dbec5 fix(plugin): recognize boolean properties in strict mode
  • 6e4a962 chore(): update eslint config
  • e550426 fix(): add is optional to properties detected by plugin
  • e0ccf86 chore(deps): update dependency eslint to v7.3.1
  • 4f4b53f chore(deps): update typescript-eslint monorepo to v3.4.0
  • 1938ac1 chore(deps): update dependency ts-jest to v26.1.1
  • 8d6402a chore(deps): update commitlint monorepo to v9
  • a97a6ce chore(deps): update dependency eslint to v7.3.0
  • 07ea12a chore(deps): update nest monorepo to v7.2.0
  • 6c3bc88 Merge pull request #977 from mattleff/patch-1

See the full diff

Package name: apollo-server-core The new version differs by 250 commits.
  • 36ecbb1 Release
  • a640e91 Finalizing docs fixes, rework CHANGELOG entries
  • 9387cba Update caching docs (#6547)
  • b6fda1b Add changelog entry
  • 549070e Reinstate bounded documentStore (#6548)
  • ac8f9bf Warn on unconfigured `cache` (#6545)
  • 999adf5 Remove caching packages (#6541)
  • f66fddc Add `cache: "bounded"` configuration option (#6536)
  • 67d9036 Implement simple `UnboundedCache` (#6535)
  • 29bb2f7 Use new `KeyValueCache` and friends from `@ apollo/utils.keyvaluecache` (#6522)
  • 5bd3d69 chore(deps): update dependency nock to v13.2.7 (#6574)
  • 6cc2c28 chore(deps): update dependency @ types/express-serve-static-core to v4.17.29 (#6570)
  • 76675b6 chore(deps): update dependency prettier to v2.7.0 (#6568)
  • 0050495 chore(deps): update all non-major dependencies (#6565)
  • 54416e2 fix: add missing await to catch errors thrown in parsingDidEnd() (#6559)
  • e0bc3ca Fix mistake in docs (#6560)
  • 482f0d7 chore(deps): update all non-major dependencies (#6561)
  • 30a2231 chore(deps): update dependency @ types/aws-lambda to v8.10.100 (#6557)
  • 72f663e Fix typo about request/response (#6540)
  • ea8578c renovate: we are not upgrading Fastify in AS3
  • ad8555c chore(deps): update dependency @ types/aws-lambda to v8.10.99 (#6539)
  • 12f0f6d chore(deps): update all non-major dependencies (#6533)
  • bdd9153 Update @ apollo/federation -> @ apollo/subgraph (#6538)
  • 6a5242a chore(deps): update all non-major dependencies (#6531)

See the full diff

Package name: apollo-server-express The new version differs by 250 commits.
  • bcfd36c Release
  • a97684f docs: get ready for 3.0.0 to be released to `next` (#5442)
  • 81ae16f Update header comment to say @ 3.x instead of @ rc
  • 76344b6 docs/READMEs: add `@ 3.x` to all `npm install` invocations
  • 537cf1c docs: remove migration to 2.x doc (old, already unlinked)
  • 348aa97 chore(deps): update dependency @ types/node-fetch to v2.5.11 (#5441)
  • 74b1d97 chore(deps): update dependency @ types/lru-cache to v5.1.1 (#5440)
  • c8062f7 chore(deps): update dependency @ types/lodash to v4.14.171 (#5439)
  • 84b7587 chore(deps): update dependency @ types/koa-router to v7.4.3 (#5438)
  • 4a8726c chore(deps): update dependency @ types/jest to v26.0.24 (#5437)
  • 87d4dcf chore(deps): update dependency @ types/ioredis to v4.26.5 (#5436)
  • 6ce5ecc chore(deps): update dependency @ types/hapi__hapi to v20.0.9 (#5435)
  • d60fd62 chore(deps): update dependency @ types/express-serve-static-core to v4.17.23 (#5434)
  • d948605 chore(deps): update dependency @ types/express to v4.17.13 (#5433)
  • 8aca7a4 chore(deps): update dependency @ types/cors to v2.8.11 (#5432)
  • 3f0450b chore(deps): update dependency @ types/connect to v3.4.35 (#5431)
  • 02e71dd chore(deps): update dependency @ types/bunyan to v1.8.7 (#5430)
  • 055b67d chore(deps): update dependency @ types/body-parser to v1.19.1 (#5429)
  • e7c0329 chore(deps): update dependency @ types/aws-lambda to v8.10.78 (#5428)
  • e5fbaf6 chore(deps): update dependency @ types/async-retry to v1.4.3 (#5427)
  • f30bc26 chore(deps): update dependency @ apollo/client to v3.3.21 (#5426)
  • b61f082 chore(deps): update dependency nock to v13.1.1 (#5423)
  • fab9351 chore(deps): update dependency @ types/uuid to v8.3.1 (#5421)
  • ad2cdb5 Release

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant