[Snyk] Fix for 1 vulnerabilities - #379
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280
|
This upgrade includes several major version bumps with significant breaking changes, most notably requiring an upgrade to Fastify v5 and Node.js v20+, along with API changes in Top 3 Most Impactful Upgrades:1. rimraf: 3.0.2 → 6.1.1 (High Risk) This upgrade spans multiple major versions and introduces several critical breaking changes that will require code modifications.
Recommendation: Review all 2. mercurius: 12.2.0 → 16.7.0 (High Risk) The upgrade from Mercurius v12 to v16 is a significant jump that requires moving from Fastify v4 to Fastify v5.
Recommendation: This upgrade must be handled as part of a larger migration to Fastify v5. Carefully review the Mercurius and Fastify migration guides. 3. @mercuriusjs/gateway: 1.2.0 → 5.0.0 (High Risk) This upgrade is directly tied to the
Recommendation: Update this package in tandem with Other Major Upgrades:
|
⛔ Snyk checks have failed. 2 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
⛔ Snyk checks have failed. 2 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-BRACEEXPANSION-18512280
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling