Skip to content
This repository has been archived by the owner on Feb 4, 2023. It is now read-only.

[Snyk] Security upgrade @strapi/strapi from 4.0.2 to 4.1.10 #8

Closed
wants to merge 1 commit into from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 733/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.8
Improper Input Validation
SNYK-JS-STRAPISTRAPI-3034918
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @strapi/strapi The new version differs by 250 commits.
  • 06abcda v4.1.10
  • 8b3ba51 Merge pull request #12881 from strapi/fix/upload-mime-type
  • d69b49b Merge pull request #13185 from strapi/fix/user-hidden-attributes
  • a727b1f Merge pull request #11960 from iicdii/fix/populate-user
  • 8eec9c2 Merge pull request #12929 from strapi/fix/documentation-component-schemas
  • 488f701 Merge pull request #13277 from strapi/fix/hooks-invalid-spread
  • 91bfab5 Merge pull request #13227 from strapi/fix/guided-tour-localstorage
  • 63ecdae Merge pull request #13226 from strapi/enh/ds-v2
  • acd8b1a remi feedback
  • 5616903 rename variables
  • 60dfae1 add unit tests
  • 620418c Remove sensitive fields from sanitize user in the admin
  • b11623d Allow setting CT's config from the CTB services
  • d184161 Fix hooks unit test
  • cd023b6 Merge pull request #13275 from strapi/fix/gcpEmptyDirectory
  • e7acb6c Getter cannot be spread and make execution invalid
  • dda5eac Add database/migrations folder to default generate
  • fdf1e88 Merge pull request #13257 from strapi/fix/single-types-custom-error
  • e918293 Update sanitizer mocking in i18n test
  • 5959788 Refactor sanitizers module to be maintained easily
  • 4429381 Merge branch 'strapi:master' into fix/populate-user
  • 1db90d8 Merge pull request #13168 from strapi/fix/sentryVersion
  • 12d99b1 SingleTypeFormWrapper: Display custom error messages
  • e8215ff Merge pull request #13236 from strapi/enh/wysiwyg-spellcheck

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
馃 View latest project report

馃洜 Adjust project settings

馃摎 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

馃 Learn about vulnerability in an interactive lesson of Snyk Learn.

@DzmitrySha DzmitrySha closed this Jan 26, 2023
@DzmitrySha DzmitrySha deleted the snyk-fix-362a54010cb3e0b8b3885fdc610374ee branch January 26, 2023 15:54
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
2 participants