[Snyk] Upgrade: , , , axios, commander, consola, koa-body, koa-router, lru-cache, luxon, mysql2, node-sql-parser, octokit, p-queue, pinyin, prom-client, reflect-metadata, tiny-async-pool #881
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@koa/cors
⚠️ This is a major version upgrade, and may be a breaking change | 9 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 5 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 22 days ago
⚠️ This is a major version upgrade, and may be a breaking change | 4 months ago
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
⚠️ This is a major version upgrade, and may be a breaking change | 2 years ago
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 4 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 9 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 3 months ago
⚠️ This is a major version upgrade, and may be a breaking change | 2 years ago
from 3.4.3 to 5.0.0 | 2 versions ahead of your current version
on 2023-12-11
@octokit/core
from 4.2.4 to 6.1.2 | 21 versions ahead of your current version
on 2024-04-09
@octokit/plugin-throttling
from 4.3.2 to 9.3.1 | 29 versions ahead of your current version
on 2024-07-14
axios
from 0.27.2 to 1.7.7 | 46 versions ahead of your current version
on 2024-08-31
commander
from 9.5.0 to 12.1.0 | 8 versions ahead of your current version
on 2024-05-18
consola
from 2.15.3 to 3.2.3 | 13 versions ahead of your current version
on 2023-07-05
koa-body
from 5.0.0 to 6.0.1 | 2 versions ahead of your current version
on 2022-10-29
koa-router
from 10.1.1 to 12.0.1 | 5 versions ahead of your current version
on 2023-10-12
lru-cache
from 7.18.3 to 11.0.0 | 28 versions ahead of your current version
on 2024-07-08
luxon
from 2.5.2 to 3.5.0 | 16 versions ahead of your current version
on 2024-08-03
mysql2
from 2.3.3 to 3.11.0 | 50 versions ahead of your current version
on 2024-07-27
node-sql-parser
from 4.18.0 to 5.3.1 | 5 versions ahead of your current version
on 2024-08-07
octokit
from 1.8.1 to 4.0.2 | 39 versions ahead of your current version
on 2024-05-08
p-queue
from 7.4.1 to 8.0.1 | 2 versions ahead of your current version
on 2023-12-14
pinyin
from 3.0.0-alpha.5 to 3.1.0 | 3 versions ahead of your current version | 10 months ago
on 2023-11-22
prom-client
from 14.2.0 to 15.1.3 | 7 versions ahead of your current version
on 2024-06-27
reflect-metadata
from 0.1.14 to 0.2.2 | 4 versions ahead of your current version | 6 months ago
on 2024-03-29
tiny-async-pool
from 1.3.0 to 2.1.0 | 3 versions ahead of your current version
on 2022-05-10
Issues fixed by the recommended upgrade:
SNYK-JS-OCTOKIT-6129525
SNYK-JS-AXIOS-6032459
SNYK-JS-KOACORS-6117545
SNYK-JS-MYSQL2-6861580
SNYK-JS-AXIOS-6124857
SNYK-JS-MYSQL2-6591084
SNYK-JS-MYSQL2-6591085
SNYK-JS-MYSQL2-6591300
SNYK-JS-MYSQL2-6670046
Release notes
Package name: @koa/cors
-
5.0.0 - 2023-12-11
-
4.0.0 - 2022-10-08
-
3.4.3 - 2022-10-08
from @koa/cors GitHub release notesRelease 5.0.0
Release 4.0.0
Release 3.4.3
Package name: @octokit/core
-
6.1.2 - 2024-04-09
- pkg: add
-
6.1.1 - 2024-04-03
- deps: update dependency @ octokit/types to v13 (ade2813)
-
6.1.0 - 2024-04-03
- security: Add provenance (#671) (1c2bd25)
-
6.0.1 - 2024-02-26
- pkg: add main entry point (#662) (42148fc)
-
6.0.0 - 2024-02-25
- package is now ESM (#661) (77f8a61)
- package is now ESM
-
6.0.0-beta.5 - 2024-02-25
- empty commit to trigger release (4ce6c63)
-
6.0.0-beta.4 - 2024-02-25
- build: correct path (6a4ce19)
-
6.0.0-beta.3 - 2024-02-25
- build: adapt for ESM (1509917)
-
6.0.0-beta.2 - 2024-02-25
-
6.0.0-beta.1 - 2024-02-24
-
5.2.0 - 2024-04-05
- security: Add provenance (#671) (0e2915b)
-
5.1.1 - 2024-04-05
- deps: upgrade
-
5.1.0 - 2024-01-20
-
5.0.2 - 2023-11-22
-
5.0.1 - 2023-09-23
-
5.0.0 - 2023-07-10
-
5.0.0-beta.5 - 2023-07-07
-
5.0.0-beta.4 - 2023-06-18
-
5.0.0-beta.3 - 2023-06-16
-
5.0.0-beta.2 - 2023-06-03
-
5.0.0-beta.1 - 2023-05-21
-
4.2.4 - 2023-06-16
from @octokit/core GitHub release notes6.1.2 (2024-04-09)
Bug Fixes
defaultfallback andtypesexport (#673) (af3d390), closes #665 #6676.1.1 (2024-04-03)
Bug Fixes
6.1.0 (2024-04-03)
Features
6.0.1 (2024-02-26)
Bug Fixes
6.0.0 (2024-02-25)
Features
BREAKING CHANGES
6.0.0-beta.5 (2024-02-25)
Bug Fixes
6.0.0-beta.4 (2024-02-25)
Bug Fixes
6.0.0-beta.3 (2024-02-25)
Bug Fixes
5.2.0 (2024-04-05)
Features
5.1.1 (2024-04-05)
Bug Fixes
@ octokit/typesto v13 (260e360)Package name: @octokit/plugin-throttling
-
9.3.1 - 2024-07-14
- only import Octokit as type (#721) (e3727b4)
-
9.3.0 - 2024-04-29
- Copilot usage endpoints (#697) (f11e11d)
-
9.2.1 - 2024-04-23
- pkg: add a
-
9.2.0 - 2024-04-15
- routes changed from repository_id to nwo and enterprise groups now includes the enterprise in route (#684) (734bcba)
-
9.1.0 - 2024-04-03
- security: Add provenance (#689) (7eb48d5)
-
9.0.4 - 2024-04-03
- deps: update dependency @ octokit/types to v13 (8cc6eb9)
-
9.0.3 - 2024-03-01
- pkg: add
-
9.0.2 - 2024-02-27
- README: update examples for ESM (#679) (0551690)
-
9.0.1 - 2024-02-26
- add missing file extension on bottleneck import (#676) (1c64559)
-
9.0.0 - 2024-02-25
- package is now ESM (#675) (4986fb0)
- package is now ESM
-
8.2.0 - 2024-02-22
-
8.1.3 - 2023-11-18
-
8.1.2 - 2023-10-25
-
8.1.1 - 2023-10-25
-
8.1.0 - 2023-10-24
-
8.0.1 - 2023-10-21
-
8.0.0 - 2023-09-23
-
7.0.0 - 2023-07-10
-
6.1.0 - 2023-06-09
-
6.0.1 - 2023-06-07
-
6.0.0 - 2023-05-22
-
5.2.3 - 2023-05-19
-
5.2.2 - 2023-05-17
-
5.2.1 - 2023-05-13
-
5.2.0 - 2023-05-05
-
5.1.1 - 2023-04-21
-
5.1.0 - 2023-04-20
-
5.0.1 - 2023-01-20
-
5.0.0 - 2023-01-20
-
4.3.2 - 2022-10-31
from @octokit/plugin-throttling GitHub release notes9.3.1 (2024-07-14)
Bug Fixes
9.3.0 (2024-04-29)
Features
9.2.1 (2024-04-23)
Bug Fixes
defaultfallback export (#695) (0f404fb)9.2.0 (2024-04-15)
Features
9.1.0 (2024-04-03)
Features
9.0.4 (2024-04-03)
Bug Fixes
9.0.3 (2024-03-01)
Bug Fixes
mainfield (#678) (f151af4)9.0.2 (2024-02-27)
Bug Fixes
9.0.1 (2024-02-26)
Bug Fixes
9.0.0 (2024-02-25)
Features
BREAKING CHANGES
Package name: axios
-
1.7.7 - 2024-08-31
- fetch: fix stream handling in Safari by fallback to using a stream reader instead of an async iterator; (#6584) (d198085)
- http: fixed support for IPv6 literal strings in url (#5731) (364993f)
Rishi556
Dmitriy Mozgovoy
-
1.7.6 - 2024-08-30
- fetch: fix content length calculation for FormData payload; (#6524) (085f568)
- fetch: optimize signals composing logic; (#6582) (df9889b)
Dmitriy Mozgovoy
Jacques Germishuys
kuroino721
-
1.7.5 - 2024-08-23
- adapter: fix undefined reference to hasBrowserEnv (#6572) (7004707)
- core: add the missed implementation of AxiosError#status property; (#6573) (6700a8a)
- core: fix
- fetch: fix credentials handling in Cloudflare workers (#6533) (550d885)
Dmitriy Mozgovoy
Antonin Bas
Hans Otto Wirtz
-
1.7.4 - 2024-08-13
- sec: CVE-2024-39338 (#6539) (#6543) (6b6b605)
- sec: disregard protocol-relative URL to remediate SSRF (#6539) (07a661a)
Lev Pachmanov
Đỗ Trọng Hải
-
1.7.3 - 2024-08-01
- adapter: fix progress event emitting; (#6518) (e3c76fc)
- fetch: fix withCredentials request config (#6505) (85d4d0e)
- xhr: return original config on errors from XHR adapter (#6515) (8966ee7)
Dmitriy Mozgovoy
Valerii Sidorenko
prianYu
-
1.7.2 - 2024-05-21
- fetch: enhance fetch API detection; (#6413) (4f79aef)
Dmitriy Mozgovoy
-
1.7.1 - 2024-05-20
- fetch: fixed ReferenceError issue when TextEncoder is not available in the environment; (#6410) (733f15f)
Dmitriy Mozgovoy
-
1.7.0 - 2024-05-19
- adapter: add fetch adapter; (#6371) (a3ff99b)
- core/axios: handle un-writable error stack (#6362) (81e0455)
Dmitriy Mozgovoy
Jay
Alexandre ABRIOUX
-
1.7.0-beta.2 - 2024-05-19
- fetch: capitalize HTTP method names; (#6395) (ad3174a)
- fetch: fix & optimize progress capturing for cases when the request data has a nullish value or zero data length (#6400) (95a3e8e)
- fetch: fix headers getting from a stream response; (#6401) (870e0a7)
Dmitriy Mozgovoy
-
1.7.0-beta.1 - 2024-05-07
- core/axios: handle un-writable error stack (#6362) (81e0455)
- fetch: fix cases when ReadableStream or Response.body are not available; (#6377) (d1d359d)
- fetch: treat fetch-related TypeError as an AxiosError.ERR_NETWORK error; (#6380) (bb5f9a5)
Alexandre ABRIOUX
Dmitriy Mozgovoy
-
1.7.0-beta.0 - 2024-04-28
-
1.6.8 - 2024-03-15
-
1.6.7 - 2024-01-25
-
1.6.6 - 2024-01-24
-
1.6.5 - 2024-01-05
-
1.6.4 - 2024-01-03
-
1.6.3 - 2023-12-26
-
1.6.2 - 2023-11-14
-
1.6.1 - 2023-11-08
-
1.6.0 - 2023-10-26
-
1.5.1 - 2023-09-26
-
1.5.0 - 2023-08-26
-
1.4.0 - 2023-04-27
-
1.3.6 - 2023-04-19
-
1.3.5 - 2023-04-05
-
1.3.4 - 2023-02-22
-
1.3.3 - 2023-02-13
-
1.3.2 - 2023-02-03
-
1.3.1 - 2023-02-01
-
1.3.0 - 2023-01-31
-
1.2.6 - 2023-01-28
-
1.2.5 - 2023-01-26
-
1.2.4 - 2023-01-24
-
1.2.3 - 2023-01-17
-
1.2.2 - 2022-12-29
-
1.2.1 - 2022-12-05
-
1.2.0 - 2022-11-22
-
1.2.0-alpha.1 - 2022-11-10
-
1.1.3 - 2022-10-15
-
1.1.2 - 2022-10-07
-
1.1.1 - 2022-10-07
-
1.1.0 - 2022-10-06
-
1.0.0 - 2022-10-04
-
1.0.0-alpha.1 - 2022-05-31
-
0.28.1 - 2024-03-28
-
0.28.0 - 2024-02-12
-
0.27.2 - 2022-04-27
from axios GitHub release notesRelease notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
ReferenceError: navigator is not definedfor custom environments; (#6567) (fed1a4b)Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Release notes:
Features
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Install
Package name: commander
Added
node --evalandnode --printwhen call.parse()with no arguments (#2164)Changed
node:(#2170)Removed
Added
.addHelpOption()as another way of configuring built-in help option (#2006).helpCommand()for configuring built-in help command (#2087)Fixed
passThroughOptionsconstraints when using.addCommandand throw if parent command does not have.enablePositionalOptions()enabled (#1937)Changed
.storeOptionsAsProperties()after setting an option value (#1928)@ api privatewith documented@ private(#1949).addHelpCommand()now takes a Command (passing string or boolean still works as before but deprecated) (#2087)Deprecated
.addHelpCommand()passing string or boolean (use.helpCommand()or pass a Command) (#2087)Removed
programexport instead) (#2017)Migration Tips
global program
If you are using the deprecated default import of the global Command object, you need to switch to using a named import (or create a new
Command).option and command clashes
A couple of configuration problems now throw an error, which will pick up issues in existing programs:
Added
.addHelpOption()as another way of configuring built-in help option (#2006).helpCommand()for configuring built-in help command (#2087)Changed
.addHelpCommand()now takes a Command (passing string or boolean still works as before but deprecated) (#2087)Deprecated
.addHelpCommand()passing string or boolean (use.helpCommand()or pass a Command) (#2087)Fixed
passThroughOptionsconstraints when using.addCommandand throw if parent command does not have.enablePositionalOptions()enabled (#1937)Changed
.storeOptionsAsProperties()after setting an option value (#1928)@ api privatewith documented@ private(#1949)Removed
programexport instead) (#2017)Migration Tips
global program
If you are using the deprecated default import of the global Command object, you need to switch to using a named import (or create a new
Command).option and command clashes
A couple of configuration problems now throw an error, which will pick up issues in existing programs:
Fixed
OptionValueSourceto allow any string, to match supported use of custom sources (#1983)Command.version()can also be used as getter (#1982)Commands.executableDir(), for when not configured (#1965)Added
registeredArgumentsproperty onCommandwith the array of definedArgument(likeCommand.optionsforOption) (#2010)envVar,presetArg(#2019)argChoices,defaultValue,defaultValueDescription(#2019)Changed
Deprecated
Command._argswas private anyway, but now available asregisteredArguments(