Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , applicationinsights, moment, notifications-node-client, pdfmake, pg #97

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

rtasalem
Copy link

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@azure/storage-blob
from 12.10.0 to 12.24.0 | 152 versions ahead of your current version | 2 months ago
on 2024-07-23
applicationinsights
from 2.3.3 to 2.9.6 | 21 versions ahead of your current version | a month ago
on 2024-08-15
moment
from 2.29.4 to 2.30.1 | 2 versions ahead of your current version | 9 months ago
on 2023-12-27
notifications-node-client
from 7.0.4 to 7.0.6 | 2 versions ahead of your current version | 10 months ago
on 2023-11-13
pdfmake
from 0.2.7 to 0.2.12 | 5 versions ahead of your current version | a month ago
on 2024-08-14
pg
from 8.7.3 to 8.12.0 | 11 versions ahead of your current version | 3 months ago
on 2024-06-04

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ES5EXT-6095076
482 Proof of Concept
Release notes
Package name: moment from moment GitHub release notes
Package name: notifications-node-client from notifications-node-client GitHub release notes
Package name: pdfmake
  • 0.2.12 - 2024-08-14
    • Fixed error message of bad image definition
  • 0.2.11 - 2024-08-09
    • Fixed and validates input values headerRows and keepWithHeaderRows
    • Fixed numbering nested ordered lists
    • Speed up StyleContextStack.autopush() for large tables
    • Fixed widths of table columns with percentages
    • Fixed storing the correct context in the ending cell of a row span when there were nested column groups (columns or tables)
  • 0.2.10 - 2024-03-07
    • Removed unused brfs dependency
  • 0.2.9 - 2024-01-01
    • Added padding option for QR code
    • Allow the document language to be specified
    • Fixed cover image size inside table
    • Fixed "Cannot read properties of undefined (reading 'bottomMost')" if table contains too few rows
    • Fixed invalid source-maps in builded js file
  • 0.2.8 - 2023-11-09
    • Update pdfkit to 0.14.0
    • Update Roboto font (version 3.008)
  • 0.2.7 - 2022-12-17
from pdfmake GitHub release notes
Package name: pg
  • 8.12.0 - 2024-06-04
  • 8.11.6 - 2024-06-04
  • 8.11.5 - 2024-04-02
  • 8.11.4 - 2024-03-30
  • 8.11.3 - 2023-08-16
  • 8.11.2 - 2023-08-01
  • 8.11.1 - 2023-06-26
  • 8.11.0 - 2023-05-15
  • 8.10.0 - 2023-03-06
  • 8.9.0 - 2023-01-27
  • 8.8.0 - 2022-08-23
  • 8.7.3 - 2022-02-04
from pg GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade:
  - @azure/storage-blob from 12.10.0 to 12.24.0.
    See this package in npm: https://www.npmjs.com/package/@azure/storage-blob
  - applicationinsights from 2.3.3 to 2.9.6.
    See this package in npm: https://www.npmjs.com/package/applicationinsights
  - moment from 2.29.4 to 2.30.1.
    See this package in npm: https://www.npmjs.com/package/moment
  - notifications-node-client from 7.0.4 to 7.0.6.
    See this package in npm: https://www.npmjs.com/package/notifications-node-client
  - pdfmake from 0.2.7 to 0.2.12.
    See this package in npm: https://www.npmjs.com/package/pdfmake
  - pg from 8.7.3 to 8.12.0.
    See this package in npm: https://www.npmjs.com/package/pg

See this project in Snyk:
https://app.snyk.io/org/defra-ffc/project/9180d8f3-f151-4775-8f3f-7539905a5adb?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants