Skip to content

[Snyk] Fix for 124 vulnerabilities - #383

Open
TheRedHatter wants to merge 1 commit into
masterfrom
snyk-fix-4b05d6be33e409dbc3181a0b3bcb0c1a
Open

[Snyk] Fix for 124 vulnerabilities#383
TheRedHatter wants to merge 1 commit into
masterfrom
snyk-fix-4b05d6be33e409dbc3181a0b3bcb0c1a

Conversation

@TheRedHatter

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 124 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-12613773
high severity Prototype Pollution
SNYK-JS-AXIOS-15252993
medium severity Unintended Proxy or Intermediary ('Confused Deputy')
SNYK-JS-AXIOS-15965856
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-16298162
critical severity Prototype Pollution
SNYK-JS-AXIOS-16299904
high severity Uncontrolled Recursion
SNYK-JS-AXIOS-16299923
high severity Prototype Pollution
SNYK-JS-AXIOS-17111060
high severity Prototype Pollution
SNYK-JS-AXIOS-17111079
medium severity Prototype Pollution
SNYK-JS-AXIOS-17111081
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-17172532
medium severity Prototype Pollution
SNYK-JS-AXIOS-18065355
high severity Inefficient Algorithmic Complexity
SNYK-JS-BRACEEXPANSION-17706650
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-BRACEEXPANSION-18313044
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-BRACEEXPANSION-18512280
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-FINDMYWAY-8055229
critical severity Out-of-bounds Read
SNYK-JS-LIBXMLJS-10557390
high severity Improper Input Validation
SNYK-JS-LIBXMLJS-10557391
high severity Use After Free
SNYK-JS-LIBXMLJS-10557401
high severity Use After Free
SNYK-JS-LIBXMLJS-10557403
high severity NULL Pointer Dereference
SNYK-JS-LIBXMLJS-10557404
medium severity Out-of-bounds Read
SNYK-JS-LIBXMLJS-10557406
high severity Improper Input Validation
SNYK-JS-LIBXMLJS-10557407
high severity Memory Leak
SNYK-JS-LIBXMLJS-10557408
medium severity Out-of-bounds Read
SNYK-JS-LIBXMLJS-10557410
critical severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557411
critical severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557414
medium severity Denial of Service (DoS)
SNYK-JS-LIBXMLJS-10557417
high severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557418
high severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557419
medium severity Use After Free
SNYK-JS-LIBXMLJS-10557420
high severity Out-of-bounds Read
SNYK-JS-LIBXMLJS-10557424
high severity Out-of-bounds Read
SNYK-JS-LIBXMLJS-10557425
medium severity Denial of Service (DoS)
SNYK-JS-LIBXMLJS-10557428
medium severity Denial of Service (DoS)
SNYK-JS-LIBXMLJS-10557429
high severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557430
critical severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557431
high severity Denial of Service (DoS)
SNYK-JS-LIBXMLJS-10557433
high severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557434
high severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557436
high severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557437
medium severity Use After Free
SNYK-JS-LIBXMLJS-10557440
medium severity Out-of-bounds Read
SNYK-JS-LIBXMLJS-10557441
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-15353387
high severity Symlink Attack
SNYK-JS-TAR-15416075
high severity Symlink Attack
SNYK-JS-TAR-15456201
medium severity Interpretation Conflict
SNYK-JS-TAR-17342362
high severity Infinite loop
SNYK-JS-TAR-17909068
medium severity Incorrect Type Conversion or Cast
SNYK-JS-TAR-17909104
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-TAR-17909152
medium severity Uncaught Exception
SNYK-JS-TAR-17909225
high severity Uncaught Exception
SNYK-JS-UNDICI-15518070
medium severity CRLF Injection
SNYK-JS-UNDICI-15518072
medium severity Improper Neutralization
SNYK-JS-UNDICI-18426061
medium severity HTTP Request Smuggling
SNYK-JS-UNDICI-18426063
low severity CRLF Injection
SNYK-JS-UNDICI-18426067
medium severity Improper Validation of Specified Index, Position, or Offset in Input
SNYK-JS-UUID-16133035
critical severity HTTP Response Splitting
SNYK-JS-AXIOS-16298058
high severity Insertion of Sensitive Information Into Sent Data
SNYK-JS-AXIOS-17172681
critical severity XML External Entity (XXE) Injection
SNYK-JS-LIBXMLJS-10557412
critical severity Use of Externally-Controlled Format String
SNYK-JS-LIBXMLJS-10557422
critical severity SQL Injection
SNYK-JS-MIKROORMCORE-15916609
high severity Insufficient Session Expiration
SNYK-JS-FASTIFYSESSION-6969137
high severity Out-of-bounds Write
SNYK-JS-LIBXMLJS-10557402
high severity Use After Free
SNYK-JS-LIBXMLJS-10557432
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-FASTIFYMULTIPART-8660811
high severity Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
high severity Out-of-bounds Write
SNYK-JS-LIBXMLJS-10557439
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-16298130
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-6124857
medium severity Interpretation Conflict
SNYK-JS-NODEMAILER-13378253
high severity Prototype Pollution
SNYK-JS-MIKROORMCORE-15917139
medium severity Improper Encoding or Escaping of Output
SNYK-JS-AXIOS-16298055
medium severity Prototype Pollution
SNYK-JS-AXIOS-16299925
high severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-17111062
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-9292519
medium severity Insertion of Sensitive Information Into Sent Data
SNYK-JS-AXIOS-17172930
high severity Improper Input Validation
SNYK-JS-LIBXMLJS-10557405
high severity Denial of Service (DoS)
SNYK-JS-LIBXMLJS-10557413
high severity Deserialization of Untrusted Data
SNYK-JS-LIBXMLJS-10557421
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-15309438
high severity Inefficient Algorithmic Complexity
SNYK-JS-MINIMATCH-15353389
high severity Improper Handling of Highly Compressed Data (Data Amplification)
SNYK-JS-UNDICI-15518068
high severity SQL Injection
SNYK-JS-KNEX-3175610
high severity HTTP Response Splitting
SNYK-JS-AXIOS-15969258
high severity Directory Traversal
SNYK-JS-TAR-15307072
medium severity Insertion of Sensitive Information Into Sent Data
SNYK-JS-AXIOS-16299478
medium severity Use of a Broken or Risky Cryptographic Algorithm
SNYK-JS-JSONWEBTOKEN-3180026
medium severity Improper Restriction of Security Token Assignment
SNYK-JS-JSONWEBTOKEN-3180024
medium severity Out-of-Bounds
SNYK-JS-LIBXMLJS-10557389
medium severity Denial of Service (DoS)
SNYK-JS-LIBXMLJS-10557409
medium severity Denial of Service (DoS)
SNYK-JS-LIBXMLJS-10557415
medium severity Out-of-bounds Read
SNYK-JS-LIBXMLJS-10557416
medium severity Improper Authentication
SNYK-JS-JSONWEBTOKEN-3180022
medium severity Arbitrary Code Injection
SNYK-JS-NESTJSCOMMON-9538801
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-9403194
high severity Command Injection
SNYK-JS-GLOB-14040952
critical severity CRLF Injection
SNYK-JS-UNDICI-17372658
high severity Excessive Platform Resource Consumption within a Loop
SNYK-JS-BRACES-6838727
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
medium severity NULL Pointer Dereference
SNYK-JS-LIBXMLJS-10557435
high severity Infinite loop
SNYK-JS-BRACEEXPANSION-15789759
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-UNDICI-17372754
medium severity XML External Entity (XXE) Injection
SNYK-JS-LIBXMLJS-10557423
medium severity Uncontrolled Recursion
SNYK-JS-AXIOS-18060730
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
medium severity Uncontrolled Recursion
SNYK-JS-TAR-18319500
medium severity HTTP Request Smuggling
SNYK-JS-UNDICI-15518061
medium severity Resource Exhaustion
SNYK-JS-JOSE-6419224
high severity Permissive List of Allowed Inputs
SNYK-JS-UNDICI-17372758
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
medium severity Improper Handling of Unicode Encoding
SNYK-JS-TAR-15038581
medium severity Prototype Pollution
SNYK-JS-AXIOS-18065349
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
medium severity Directory Traversal
SNYK-JS-TAR-15032660
high severity Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-16298095
medium severity Denial of Service (DoS)
SNYK-JS-GRAPHQL-5905181
medium severity Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
medium severity Time-of-check Time-of-use (TOCTOU) Race Condition
SNYK-JS-UNDICI-17372752
medium severity Directory Traversal
SNYK-JS-TAR-15127355
medium severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-UNDICI-14943963
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling
🦉 Prototype Pollution
🦉 Server-side Request Forgery (SSRF)
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-AXIOS-12613773
- https://snyk.io/vuln/SNYK-JS-AXIOS-15252993
- https://snyk.io/vuln/SNYK-JS-AXIOS-15965856
- https://snyk.io/vuln/SNYK-JS-AXIOS-16298162
- https://snyk.io/vuln/SNYK-JS-AXIOS-16299904
- https://snyk.io/vuln/SNYK-JS-AXIOS-16299923
- https://snyk.io/vuln/SNYK-JS-AXIOS-17111060
- https://snyk.io/vuln/SNYK-JS-AXIOS-17111079
- https://snyk.io/vuln/SNYK-JS-AXIOS-17111081
- https://snyk.io/vuln/SNYK-JS-AXIOS-17172532
- https://snyk.io/vuln/SNYK-JS-AXIOS-18065355
- https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-17706650
- https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18313044
- https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280
- https://snyk.io/vuln/SNYK-JS-FINDMYWAY-8055229
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557390
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557391
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557401
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557403
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557404
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557406
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557407
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557408
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557410
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557411
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557414
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557417
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557418
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557419
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557420
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557424
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557425
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557428
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557429
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557430
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557431
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557433
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557434
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557436
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557437
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557440
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557441
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-15353387
- https://snyk.io/vuln/SNYK-JS-TAR-15416075
- https://snyk.io/vuln/SNYK-JS-TAR-15456201
- https://snyk.io/vuln/SNYK-JS-TAR-17342362
- https://snyk.io/vuln/SNYK-JS-TAR-17909068
- https://snyk.io/vuln/SNYK-JS-TAR-17909104
- https://snyk.io/vuln/SNYK-JS-TAR-17909152
- https://snyk.io/vuln/SNYK-JS-TAR-17909225
- https://snyk.io/vuln/SNYK-JS-UNDICI-15518070
- https://snyk.io/vuln/SNYK-JS-UNDICI-15518072
- https://snyk.io/vuln/SNYK-JS-UNDICI-18426061
- https://snyk.io/vuln/SNYK-JS-UNDICI-18426063
- https://snyk.io/vuln/SNYK-JS-UNDICI-18426067
- https://snyk.io/vuln/SNYK-JS-UUID-16133035
- https://snyk.io/vuln/SNYK-JS-AXIOS-16298058
- https://snyk.io/vuln/SNYK-JS-AXIOS-17172681
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557412
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557422
- https://snyk.io/vuln/SNYK-JS-MIKROORMCORE-15916609
- https://snyk.io/vuln/SNYK-JS-FASTIFYSESSION-6969137
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557402
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557432
- https://snyk.io/vuln/SNYK-JS-FASTIFYMULTIPART-8660811
- https://snyk.io/vuln/SNYK-JS-AXIOS-6032459
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557439
- https://snyk.io/vuln/SNYK-JS-AXIOS-16298130
- https://snyk.io/vuln/SNYK-JS-AXIOS-6124857
- https://snyk.io/vuln/SNYK-JS-NODEMAILER-13378253
- https://snyk.io/vuln/SNYK-JS-MIKROORMCORE-15917139
- https://snyk.io/vuln/SNYK-JS-AXIOS-16298055
- https://snyk.io/vuln/SNYK-JS-AXIOS-16299925
- https://snyk.io/vuln/SNYK-JS-AXIOS-17111062
- https://snyk.io/vuln/SNYK-JS-AXIOS-9292519
- https://snyk.io/vuln/SNYK-JS-AXIOS-17172930
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557405
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557413
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557421
- https://snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-15309438
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-15353389
- https://snyk.io/vuln/SNYK-JS-UNDICI-15518068
- https://snyk.io/vuln/SNYK-JS-KNEX-3175610
- https://snyk.io/vuln/SNYK-JS-AXIOS-15969258
- https://snyk.io/vuln/SNYK-JS-TAR-15307072
- https://snyk.io/vuln/SNYK-JS-AXIOS-16299478
- https://snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180026
- https://snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180024
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557389
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557409
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557415
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557416
- https://snyk.io/vuln/SNYK-JS-JSONWEBTOKEN-3180022
- https://snyk.io/vuln/SNYK-JS-NESTJSCOMMON-9538801
- https://snyk.io/vuln/SNYK-JS-AXIOS-9403194
- https://snyk.io/vuln/SNYK-JS-GLOB-14040952
- https://snyk.io/vuln/SNYK-JS-UNDICI-17372658
- https://snyk.io/vuln/SNYK-JS-BRACES-6838727
- https://snyk.io/vuln/SNYK-JS-WS-7266574
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557435
- https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-15789759
- https://snyk.io/vuln/SNYK-JS-UNDICI-17372754
- https://snyk.io/vuln/SNYK-JS-LIBXMLJS-10557423
- https://snyk.io/vuln/SNYK-JS-AXIOS-18060730
- https://snyk.io/vuln/SNYK-JS-PATHTOREGEXP-7925106
- https://snyk.io/vuln/SNYK-JS-TAR-18319500
- https://snyk.io/vuln/SNYK-JS-UNDICI-15518061
- https://snyk.io/vuln/SNYK-JS-JOSE-6419224
- https://snyk.io/vuln/SNYK-JS-UNDICI-17372758
- https://snyk.io/vuln/SNYK-JS-TAR-6476909
- https://snyk.io/vuln/SNYK-JS-TAR-15038581
- https://snyk.io/vuln/SNYK-JS-AXIOS-18065349
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
- https://snyk.io/vuln/SNYK-JS-TAR-15032660
- https://snyk.io/vuln/SNYK-JS-UNSETVALUE-2400660
- https://snyk.io/vuln/SNYK-JS-AXIOS-16298095
- https://snyk.io/vuln/SNYK-JS-GRAPHQL-5905181
- https://snyk.io/vuln/SNYK-JS-COOKIE-8163060
- https://snyk.io/vuln/SNYK-JS-UNDICI-17372752
- https://snyk.io/vuln/SNYK-JS-TAR-15127355
- https://snyk.io/vuln/SNYK-JS-MICROMATCH-6838728
- https://snyk.io/vuln/SNYK-JS-UNDICI-14943963
- https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-9789073
@TheRedHatter

Copy link
Copy Markdown
Owner Author

Merge Risk: High

This release includes several high-risk major version upgrades that require immediate attention and code modifications. The most critical are the upgrades for NestJS, Mikro-ORM, and jsonwebtoken.

Top 3 Impactful Upgrades

1. NestJS Framework: v9 → v10 (@nestjs/core, @nestjs/common, etc.)
This is a significant framework upgrade with several breaking changes. Key actions include:

  • Node.js Requirement: Support for Node.js v12 is dropped; Node.js v16+ is now required.
  • CacheModule: The CacheModule has been extracted from @nestjs/common into its own package, @nestjs/cache-manager. You must install the new package and update your imports.
  • TypeScript Version: Projects using CLI plugins for Swagger or GraphQL now require TypeScript v4.8 or higher.

Recommendation: Follow the official migration guide, update your Node.js runtime, and refactor CacheModule usage.

2. Mikro-ORM: v4 → v6 (@mikro-orm/core, @mikro-orm/postgresql)
This upgrade spans two major versions (v4→v5 and v5→v6) and introduces substantial breaking changes.

  • v4 → v5: Node.js v14+ is required. Many core methods like em.find() and em.findOne() now use a single options object instead of multiple arguments. The @Repository() decorator is removed in favor of an entity option.
  • v5 → v6: Node.js v18.12+ and TypeScript 5.0+ are required. The default loading strategy for SQL drivers is now joined. The MikroORM.init() no longer accepts a Configuration instance, and extensions like Migrator must be registered in the config.

Recommendation: This is a multi-step migration. Carefully follow the official v4-to-v5 and v5-to-v6 upgrade guides. Expect to refactor entity manager calls, configuration, and repository definitions.

3. jsonwebtoken: v8 → v9`
This security-focused update introduces strict, non-backwards-compatible changes to enhance security. [5]

  • Unsigned Tokens: The verify() function no longer accepts unsigned tokens by default. You must explicitly add 'none' to the algorithms array in the options if this is intended. [6]
  • Key Validation: Asymmetric keys (RSA/ECDSA) can no longer be used for HMAC algorithms (e.g., HS256). Additionally, RSA keys must now be 2048 bits or greater. [6]

Recommendation: Review all verify() calls. Explicitly specify the algorithms you expect to prevent security bypasses. Ensure your RSA keys meet the new size requirement.

Other Notable Major Upgrades

  • @mercuriusjs/gateway v1 → v4: This jump likely contains significant breaking changes to the GraphQL gateway setup. Review the changelogs for versions 2, 3, and 4 is highly recommended.
  • rimraf v3 → v6: Glob pattern support was removed in v4 and then re-added as an opt-in feature. The main function now returns a Promise instead of using a callback. [3, 17, 29]
  • bcrypt v5 → v6: Drops support for Node.js versions below 16. [22]
  • @fastify/static v7 → v9: The setHeaders function signature has changed; it now receives the FastifyReply object instead of the raw response object. [18]
  • libxmljs v0.19.8 → v1.0.0: This is a significant jump to a stable 1.0 release. Review for API changes is critical.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@TheRedHatter

TheRedHatter commented Aug 26, 2026

Copy link
Copy Markdown
Owner Author

Snyk checks have failed. 5 issues have been found so far.

Status Scan Engine Critical High Medium Low Total (5)
Open Source Security 0 2 3 0 5 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@TheRedHatter

TheRedHatter commented Aug 26, 2026

Copy link
Copy Markdown
Owner Author

Snyk checks have failed. 5 issues have been found so far.

Status Scan Engine Critical High Medium Low Total (5)
Open Source Security 0 2 3 0 5 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants