[Snyk] Fix for 4 vulnerabilities #41
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to fix 4 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-BODYPARSER-7926860
SNYK-JS-EXPRESS-7926867
SNYK-JS-SEND-7926862
SNYK-JS-SERVESTATIC-7926865
Release notes
Package name: body-parser
-
1.20.3 - 2024-09-09
- deps: [email protected]
- add
- IMPORTANT: The default
- chore: add support for OSSF scorecard reporting by @ inigomarquinez in #522
- ci: fix errors in ci github action for node 8 and 9 by @ inigomarquinez in #523
- fix: pin to [email protected] by @ wesleytodd in #527
- deps: [email protected] by @ melikhov-dev in #521
- Add OSSF Scorecard badge by @ bjohansebas in #531
- Linter by @ UlisesGascon in #534
- Release: 1.20.3 by @ UlisesGascon in #535
- @ inigomarquinez made their first contribution in #522
- @ melikhov-dev made their first contribution in #521
- @ bjohansebas made their first contribution in #531
- @ UlisesGascon made their first contribution in #534
-
1.20.2 - 2023-02-22
- Fix strict json error message on Node.js 19+
- deps: content-type@~1.0.5
- perf: skip value escaping when unnecessary
- deps: [email protected]
-
1.20.1 - 2022-10-06
- deps: [email protected]
- perf: remove unnecessary object clone
-
1.20.0 - 2022-04-03
- Fix error message for json parse whitespace in
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- Replace internal
- Use instance methods on
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
-
1.19.2 - 2022-02-16
- deps: [email protected]
- deps: [email protected]
- Fix handling of
- deps: [email protected]
- deps: [email protected]
-
1.19.1 - 2021-12-10
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: type-is@~1.6.18
-
1.19.0 - 2019-04-26
-
1.18.3 - 2018-05-14
-
1.18.2 - 2017-09-22
-
1.18.1 - 2017-09-12
-
1.18.0 - 2017-09-09
-
1.17.2 - 2017-05-18
-
1.17.1 - 2017-03-06
-
1.17.0 - 2017-03-01
-
1.16.1 - 2017-02-11
-
1.16.0 - 2017-01-18
-
1.15.2 - 2016-06-20
-
1.15.1 - 2016-05-06
-
1.15.0 - 2016-02-11
-
1.14.2 - 2015-12-16
-
1.14.1 - 2015-09-28
-
1.14.0 - 2015-09-16
-
1.13.3 - 2015-07-31
-
1.13.2 - 2015-07-06
-
1.13.1 - 2015-06-16
-
1.13.0 - 2015-06-15
-
1.12.4 - 2015-05-11
-
1.12.3 - 2015-04-16
-
1.12.2 - 2015-03-17
-
1.12.1 - 2015-03-16
-
1.12.0 - 2015-02-14
-
1.11.0 - 2015-01-31
-
1.10.2 - 2015-01-21
-
1.10.1 - 2015-01-02
-
1.10.0 - 2014-12-03
-
1.9.3 - 2014-11-22
-
1.9.2 - 2014-10-28
-
1.9.1 - 2014-10-23
-
1.9.0 - 2014-09-24
from body-parser GitHub release notesWhat's Changed
Important
depthoption to customize the depth level in the parserdepthlevel for parsing URL-encoded data is now32(previously wasInfinity). DocumentationOther changes
New Contributors
Full Changelog: 1.20.2...1.20.3
strictevalusage withFunctionconstructorprocessto check for listeners__proto__keysPackage name: express
What's Changed
"back"magic string in redirects by @ blakeembrey in #5935New Contributors
Full Changelog: 4.20.0...4.21.0
What's Changed
Important
depthlevel for parsing URL-encoded data is now32(previously wasInfinity)res.redirectOther Changes
http-errors,expressjs.com,morgan,cors,body-parserby @ jonchurch in #5587res.clearCookieacceptingoptions.maxAgeandoptions.expiresby @ jonchurch in #5672questionanddiscussby @ IamLizu in #5835merge-descriptorsdependency by @ RobinTail in #5781New Contributors
Full Changelog: 4.19.1...4.20.0
What's Changed
Full Changelog: 4.19.1...4.19.2
What's Changed
Full Changelog: 4.19.0...4.19.1
What's Changed
New Contributors
Full Changelog: 4.18.3...4.19.0
Main Changes
Other Changes
New Contributors