Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade mysql2 from 2.3.3 to 3.9.4 #11

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

kingjay66
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • docs/recipes/docker-server/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 883/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 9.8
Remote Code Execution (RCE)
SNYK-JS-MYSQL2-6591085
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: mysql2 The new version differs by 250 commits.
  • cf3fa60 chore(master): release 3.9.4 (#2566)
  • 4a964a3 fix(security): improve results object creation (#2574)
  • 71115d8 ci: improve parser tests (#2573)
  • 74abf9e fix(security): improve supportBigNumbers and bigNumberStrings sanitization (#2572)
  • 8a818ce fix(docs): improve the contribution guidelines (#2552)
  • 0f08c7c build(deps-dev): bump @ docusaurus/tsconfig in /website (#2563)
  • 165c4d6 build(deps-dev): bump @ docusaurus/eslint-plugin in /website (#2564)
  • 9b5ed7b build(deps): bump @ docusaurus/preset-classic in /website (#2562)
  • 096db64 build(deps-dev): bump typescript from 5.4.3 to 5.4.4 (#2561)
  • b91fd16 build(deps-dev): bump tsx from 4.7.1 to 4.7.2 in /website (#2557)
  • 8e68d02 build(deps-dev): bump @ types/node from 20.12.3 to 20.12.4 (#2558)
  • 0f2b89f build(deps): bump sass from 1.72.0 to 1.74.1 in /website (#2556)
  • caa8598 build(deps-dev): bump @ types/node from 20.12.2 to 20.12.3 (#2555)
  • 63f7789 chore(website): update dependencies manually (#2553)
  • 63f1055 Separated each certificate into single array element (#2542)
  • 19d378e build(deps-dev): bump @ types/node from 20.11.30 to 20.12.2 (#2544)
  • a9c6c3e build(deps-dev): bump @ typescript-eslint/eslint-plugin in /website (#2535)
  • e315b9e build(deps-dev): bump @ typescript-eslint/parser in /website (#2534)
  • 1609b53 docs: remove RDS related issues (#2533)
  • e82592e docs: fix change logs from v3.9.3 (#2532)
  • f813a65 chore(master): release 3.9.3 (#2529)
  • b603cae ci: drop Node.js 14 and 16 from matrix (#2531)
  • bd30872 ci: fix test file name (#2530)
  • 0d54b0c fix(cache): improve cache key serialization (#2424)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Remote Code Execution (RCE)

Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@storybook/preact@6.5.13 None +3 109 kB shilman
npm/@testing-library/dom@5.6.1 environment 0 1.62 MB testing-library-bot
npm/@types/body-parser@1.17.0 None 0 5.25 kB types
npm/@types/compression@1.0.1 None 0 10.3 kB types
npm/@types/cron@1.7.2 None 0 11.6 kB types
npm/@types/d3@5.7.2 None 0 6.23 kB types
npm/@types/debug@4.1.5 None 0 4.79 kB types
npm/@types/express@4.16.1 None 0 5.63 kB types
npm/@types/inquirer@6.0.3 None 0 19.9 kB types
npm/@types/isomorphic-fetch@0.0.34 None 0 2.67 kB types
npm/@types/jest@24.0.15 None 0 71 kB types
npm/@types/js-yaml@3.12.1 None 0 7.24 kB types
npm/@types/morgan@1.7.35 None 0 10.6 kB types
npm/@types/node@11.13.2 None 0 625 kB types
npm/@types/plotly.js@1.44.9 None 0 48.1 kB types
npm/@types/sequelize@4.27.34 None 0 235 kB types
npm/@types/tmp@0.1.0 None 0 4.5 kB types
npm/@types/umzug@2.2.2 None 0 10.8 kB types
npm/@types/uuid@8.3.0 None 0 5.96 kB types
npm/@types/yargs-parser@11.0.3 None 0 4.38 kB types
npm/@types/yargs@12.0.8 None 0 24.2 kB types
npm/@typescript-eslint/parser@5.10.2 None 0 29 kB jameshenry
npm/core-js@3.20.3 environment, eval, filesystem 0 929 kB zloirock
npm/esbuild@0.15.13 environment, filesystem, network, shell 0 121 kB evanw
npm/eslint-config-google@0.14.0 None 0 24.8 kB philipwalton
npm/eslint-config-prettier@8.3.0 None 0 18.2 kB lydell
npm/eslint-config-react@1.1.7 None 0 12 kB patrio
npm/eslint-plugin-import@2.25.4 filesystem, unsafe 0 1.04 MB ljharb
npm/eslint-plugin-jest@26.0.0 filesystem 0 261 kB simenb
npm/eslint-plugin-prettier@4.0.0 None 0 52 kB bpscott
npm/eslint-plugin-react@7.28.0 filesystem +1 787 kB ljharb
npm/eslint@8.8.0 filesystem 0 2.64 MB eslintbot
npm/fast-deep-equal@3.1.3 None 0 13 kB esp
npm/identity-obj-proxy@3.0.0 None 0 8.38 kB keyanzhang
npm/jest-circus@29.4.3 None 0 67.5 kB simenb
npm/jest-environment-jsdom@29.4.3 None 0 9.4 kB simenb
npm/jest-fetch-mock@3.0.3 network 0 104 kB jefflau
npm/jest-image-snapshot@4.5.1 environment, filesystem, shell 0 3.07 MB amexopensource
npm/jest@29.4.3 None 0 5.01 kB simenb
npm/lerna@3.22.0 None 0 20.4 kB evocateur
npm/lodash@4.17.21 None 0 1.41 MB bnjmnt4n
npm/mysql2@2.1.0 environment, network 0 424 kB sidorares
npm/pg-hstore@2.3.3 None 0 22 kB scarney
npm/pg@8.2.1 environment, network 0 68.9 kB brianc
npm/preact-render-to-json@3.6.6 None 0 24.8 kB nathancahill
npm/prettier@2.5.1 environment, eval, filesystem, unsafe 0 21 MB sosukesuzuki
npm/prop-types@15.7.2 environment 0 97.7 kB ljharb
npm/puppeteer-core@19.7.1 environment, filesystem, network, shell 0 4.01 MB google-wombot
npm/puppeteer@19.7.1 environment, filesystem, shell Transitive: network +1 357 kB google-wombot
npm/regenerator-runtime@0.13.9 None 0 27.4 kB benjamn
npm/sqlite3@5.1.2 None 0 3.21 MB daniellockyer
npm/ts-jest@29.0.5 environment, filesystem, unsafe 0 307 kB kul
npm/typescript@4.5.4 None 0 64 MB typescript-bot
npm/util-deprecate@1.0.2 None 0 5.48 kB tootallnate

🚮 Removed packages: npm/3d-view@2.0.0, npm/@ampproject/remapping@2.3.0, npm/@babel/code-frame@7.0.0, npm/@babel/compat-data@7.16.8, npm/@babel/helper-compilation-targets@7.16.7, npm/@babel/helper-member-expression-to-functions@7.16.7, npm/@babel/helper-module-imports@7.16.7, npm/@babel/helper-module-transforms@7.16.7, npm/@babel/helper-optimise-call-expression@7.16.7, npm/@babel/helper-plugin-utils@7.16.7, npm/@babel/helper-regex@7.4.4, npm/@babel/helper-replace-supers@7.16.7, npm/@babel/helper-simple-access@7.16.7, npm/@babel/helper-validator-identifier@7.16.7, npm/@babel/parser@7.4.3, npm/@babel/plugin-proposal-class-properties@7.16.7, npm/@babel/plugin-proposal-nullish-coalescing-operator@7.16.7, npm/@babel/plugin-proposal-object-rest-spread@7.16.7, npm/@babel/plugin-proposal-optional-chaining@7.16.7, npm/@babel/plugin-proposal-private-methods@7.16.7, npm/@babel/plugin-proposal-private-property-in-object@7.18.6, npm/@babel/plugin-proposal-unicode-property-regex@7.16.7, npm/@babel/plugin-syntax-class-properties@7.12.13, npm/@babel/plugin-syntax-jsx@7.16.7, npm/@babel/plugin-syntax-logical-assignment-operators@7.10.4, npm/@babel/plugin-syntax-numeric-separator@7.10.4, npm/@babel/plugin-syntax-object-rest-spread@7.8.3, npm/@babel/plugin-syntax-top-level-await@7.14.5, npm/@babel/plugin-syntax-typescript@7.16.7, npm/@babel/plugin-transform-arrow-functions@7.16.7, npm/@babel/plugin-transform-block-scoping@7.16.7, npm/@babel/plugin-transform-classes@7.16.7, npm/@babel/plugin-transform-destructuring@7.16.7, npm/@babel/plugin-transform-dotall-regex@7.16.7, npm/@babel/plugin-transform-for-of@7.16.7, npm/@babel/plugin-transform-parameters@7.16.7, npm/@babel/plugin-transform-react-jsx@7.16.7, npm/@babel/plugin-transform-shorthand-properties@7.16.7, npm/@babel/plugin-transform-spread@7.16.7, npm/@babel/plugin-transform-template-literals@7.16.7, npm/@babel/runtime@7.8.4, npm/@babel/template@7.4.0, npm/@babel/types@7.4.0, npm/@choojs/findup@0.2.1, npm/@fontsource/material-icons@4.4.5, npm/@fontsource/roboto-mono@4.4.5, npm/@fontsource/roboto@4.4.5, npm/@jest/types@26.6.2, npm/@jridgewell/gen-mapping@0.3.2, npm/@jridgewell/resolve-uri@3.1.2, npm/@jridgewell/set-array@1.2.1, npm/@jridgewell/source-map@0.3.6, npm/@jridgewell/sourcemap-codec@1.4.14, npm/@jridgewell/trace-mapping@0.3.25, npm/@lhci/cli@0.12.0, npm/@lhci/server@0.12.0, npm/@lhci/server@0.9.0, npm/@mapbox/geojson-area@0.2.2, npm/@mapbox/gl-matrix@0.0.1, npm/@mapbox/jsonlint-lines-primitives@2.0.2, npm/@mapbox/mapbox-gl-supported@1.4.1, npm/@mapbox/point-geometry@0.1.0, npm/@mapbox/shelf-pack@3.2.0, npm/@mapbox/tiny-sdf@1.2.5, npm/@mapbox/whoots-js@3.1.0, npm/@octokit/request-error@1.0.4, npm/@plotly/d3-sankey@0.7.2, npm/@puppeteer/browsers@0.4.0, npm/@sentry/core@6.19.7, npm/@sentry/node@6.19.7

View full report↗︎

Copy link

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

<
Alert Package NoteSource
Filesystem access npm/core-js@3.20.3
Install scripts npm/core-js@3.20.3
  • Install script: postinstall
  • Source: node -e "try{require('./postinstall')}catch(e){}"
Uses eval npm/core-js@3.20.3
Uses eval npm/core-js@3.20.3
Uses eval npm/core-js@3.20.3
Uses eval npm/core-js@3.20.3
Uses eval npm/core-js@3.20.3
Environment variable access npm/core-js@3.20.3
New author npm/is-extendable@1.0.1
  • orphan: npm/is-extendable@1.0.1
Environment variable access npm/detect-libc@1.0.3
Filesystem access npm/detect-libc@1.0.3
New author npm/ansi-regex@2.1.1
  • orphan: npm/ansi-regex@2.1.1
Trivial Package npm/ansi-regex@2.1.1
  • orphan: npm/ansi-regex@2.1.1
Trivial Package npm/arrify@1.0.1
  • orphan: npm/arrify@1.0.1
Environment variable access npm/polished@4.2.2
Dynamic require npm/eslint-plugin-react@7.28.0
Dynamic require npm/eslint-plugin-react@7.28.0
Filesystem access npm/eslint-plugin-react@7.28.0
Environment variable access npm/picocolors@0.2.1
  • orphan: npm/picocolors@0.2.1
Environment variable access npm/picocolors@0.2.1
  • orphan: npm/picocolors@0.2.1
Environment variable access npm/react@17.0.2
  • orphan: npm/react@17.0.2
Environment variable access npm/prop-types@15.7.2
Uses eval npm/react-inspector@5.1.1
New author npm/react-inspector@5.1.1
Uses eval npm/telejson@6.0.8
Uses eval npm/telejson@6.0.8
Environment variable access npm/readable-stream@3.6.0
  • orphan: npm/readable-stream@3.6.0
Filesystem access npm/source-map@0.7.3
  • orphan: npm/source-map@0.7.3
Network access npm/source-map@0.7.3
  • orphan: npm/source-map@0.7.3
Trivial Package npm/ansi-regex@3.0.0
  • orphan: npm/ansi-regex@3.0.0
Environment variable access npm/resolve@1.22.0
  • orphan: npm/resolve@1.22.0
Environment variable access npm/resolve@1.22.0
  • orphan: npm/resolve@1.22.0
Environment variable access npm/resolve@1.22.0
  • orphan: npm/resolve@1.22.0
Environment variable access npm/resolve@1.22.0
  • orphan: npm/resolve@1.22.0
Environment variable access npm/resolve@1.22.0
  • orphan: npm/resolve@1.22.0
Environment variable access npm/resolve@1.22.0
  • orphan: npm/resolve@1.22.0
Environment variable access npm/resolve@1.22.0
  • orphan: npm/resolve@1.22.0
Environment variable access npm/resolve@1.22.0
  • orphan: npm/resolve@1.22.0
Filesystem access npm/eslint@8.8.0
Dynamic require npm/eslint@8.8.0
Dynamic require npm/eslint@8.8.0
Dynamic require npm/eslint@8.8.0
Dynamic require npm/eslint@8.8.0
Debug access npm/eslint-plugin-import@2.25.4
Filesystem access npm/eslint-plugin-import@2.25.4
Dynamic require npm/eslint-plugin-import@2.25.4
Environment variable access npm/pg@8.2.1
Environment variable access npm/pg@8.2.1
Environment variable access npm/pg@8.2.1
Environment variable access npm/pg@8.2.1
Environment variable access npm/pg@8.2.1
Network access npm/pg@8.2.1
Network access npm/pg@8.2.1
Environment variable access npm/pg@8.2.1
Network access npm/pg@8.2.1
Environment variable access npm/pg@8.2.1
Environment variable access npm/pg@8.2.1
Network access npm/jest-fetch-mock@3.0.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants