-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Upgrade typeorm from 0.3.7 to 0.3.20 #74
base: main
Are you sure you want to change the base?
Conversation
Snyk has created this PR to upgrade typeorm from 0.3.7 to 0.3.20. See this package in npm: https://www.npmjs.com/package/typeorm See this project in Snyk: https://app.snyk.io/org/naiba3434-ijp/project/a27d6e94-ad38-4316-b947-56b2efee5147?utm_source=github&utm_medium=referral&page=upgrade-pr
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/@actions/core@1.9.0, npm/@aws-sdk/client-dynamodb@3.113.0, npm/@next-auth/adapter-test@0.0.0, npm/@next-auth/fauna-adapter@1.0.4, npm/@next-auth/prisma-adapter@1.0.5, npm/@next-auth/supabase-adapter@0.2.0, npm/@next-auth/tsconfig@0.0.0, npm/@next-auth/typeorm-legacy-adapter@2.0.1, npm/next-auth@4.18.5, npm/nodemailer@6.9.13 |
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
|
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade typeorm from 0.3.7 to 0.3.20.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-XML2JS-5414874
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: typeorm
Bug Fixes
Features
Reverts
Bug Fixes
Cannot read properties of undefined (reading 'sync')
caused after glob package upgradeRead more
Bug Fixes
0.3.16 (2023-05-09)
Bug Fixes
trustServerCertificate
option toSqlServerConnectionOptions
(#9985) (0305805), closes #8093Features
Reverts
Bug Fixes
Features
Bug Fixes
Features
Read more
Read more
Read more
Commit messages
Package name: typeorm
.js
extension to import nextauthjs/next-auth#10123)" (fix(next-auth): improve typing for using Dynamic Route Segments with auth() nextauthjs/next-auth#10624)session-strategies.mdx
copy nextauthjs/next-auth#10634)Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs