Skip to content
This repository has been archived by the owner on Feb 4, 2023. It is now read-only.

[Snyk] Security upgrade @strapi/strapi from 4.2.3 to 4.5.5 #12

Merged
merged 1 commit into from Jan 9, 2023

Conversation

snyk-bot
Copy link

@snyk-bot snyk-bot commented Jan 1, 2023

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Prototype Poisoning
SNYK-JS-QS-3153490
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @strapi/strapi The new version differs by 250 commits.
  • 8f19883 v4.5.5
  • 29e6833 Merge pull request #14593 from gary-alway/disable-migrations-config
  • aa08a10 Merge pull request #15258 from ivan-ha/fix/translation-of-profile-experience
  • ba1d649 Merge pull request #15232 from Chessman97/fix/documentation-transalation-settings-page
  • e912c0a Merge branch 'main' into disable-migrations-config
  • 3446db4 Merge pull request #14546 from strapi/security/adminRateLimit
  • ae7c609 change ratelimit to rateLimit
  • 33bd405 refactor config loading
  • 2f87da5 Merge remote-tracking branch 'origin/main' into security/adminRateLimit
  • 44c3c09 Merge pull request #14276 from strapi/fix/delete-duplicate-route-users-delete
  • 43c6874 Merge branch 'main' into fix/delete-duplicate-route-users-delete
  • b76c413 Merge pull request #15254 from strapi/fix/relational-path
  • b767d40 Merge pull request #15241 from GitStartHQ/fix/content-manager-crash-on-nonstring-dynamicfield
  • 863b0a0 fix: Settings.profile.form.section.experience.here in all translation files
  • ae7493f fix: wrong translations key in profile -> experience
  • c078ac2 Merge branch 'main' into fix/content-manager-crash-on-nonstring-dynamicfield
  • e5e2018 fix relation path on nested duplicated keys
  • 05be584 Merge pull request #15235 from strapi/fix/cropper-import
  • 745f344 Merge pull request #15249 from strapi/chore/upgrade-axios
  • 59438be Merge branch 'main' into chore/upgrade-axios
  • 8563719 Chore: Upgrade axios to 1.2.1
  • 237f9bf Merge pull request #15212 from strapi/chore/request-context-interface-update
  • f488558 Merge pull request #15243 from strapi/fix/ML-header-tooltip-and-asset-count
  • 708daec Merge branch 'main' into chore/request-context-interface-update

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
馃 View latest project report

馃洜 Adjust project settings

馃摎 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

馃 Prototype Poisoning

@DzmitrySha DzmitrySha merged commit d8eb1e0 into main Jan 9, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
2 participants