Skip to content

Conversation

MattyJ007
Copy link
Contributor

No description provided.

Affected versions of this package are vulnerable to Information
Exposure. Fixed in mongoose versions 5.7.5 and up

TRACE-4
Boyscout

TRACE-4
@MattyJ007 MattyJ007 requested a review from BMartinos October 18, 2019 07:56
MattyJ007 and others added 4 commits October 18, 2019 11:18
The tested node versions didn't need 10.15.0
Docker isn't necessary
Node Dubnium is not permitted to fail as it is the LTS
Sudo shouldn't be used in the test
npm test was called by travis by default as this is a node project
however, it seems wrong to rely on that...

TRACE-4
Currently this branch does not implement GridFS

TRACE-3
TRACE-3 Content Chunk is a method needed by GridFS
@codecov-io
Copy link

codecov-io commented Oct 21, 2019

Codecov Report

Merging #1053 into master will decrease coverage by 0.01%.
The diff coverage is n/a.

Impacted file tree graph

@@            Coverage Diff            @@
##           master   #1053      +/-   ##
=========================================
- Coverage   87.82%   87.8%   -0.02%     
=========================================
  Files          74      73       -1     
  Lines        5953    5914      -39     
=========================================
- Hits         5228    5193      -35     
+ Misses        725     721       -4
Impacted Files Coverage Δ
src/middleware/messageStore.js 91.03% <0%> (+0.68%) ⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 84d02dd...eed1d3f. Read the comment docs.

Updated dependencies.

Removed unused functions and their tests

TRACE-3
Copy link
Collaborator

@BMartinos BMartinos left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

@BMartinos BMartinos merged commit ac9bf2b into master Oct 21, 2019
@BMartinos BMartinos deleted the patch-security-risks branch October 21, 2019 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants