[Snyk] Upgrade: , , , , express-session, moment, mongodb, next-connect, openid-client, passport, react-bootstrap, react-bootstrap-icons, react-grid-layout, react-rating-stars-component #29
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@i3m/non-repudiation-library
from 2.5.7 to 2.6.4 | 4 versions ahead of your current version | a year ago
on 2023-04-28
@i3m/wallet-protocol
from 2.5.7 to 2.6.1 | 5 versions ahead of your current version | a year ago
on 2023-05-04
@i3m/wallet-protocol-api
from 2.5.7 to 2.6.1 | 5 versions ahead of your current version | a year ago
on 2023-05-04
@i3m/wallet-protocol-utils
from 2.5.7 to 2.6.1 | 5 versions ahead of your current version | a year ago
on 2023-05-04
express-session
from 1.17.3 to 1.18.0 | 1 version ahead of your current version | 7 months ago
on 2024-01-28
moment
from 2.29.4 to 2.30.1 | 2 versions ahead of your current version | 8 months ago
on 2023-12-27
mongodb
from 4.15.0 to 4.17.2 | 4 versions ahead of your current version | 9 months ago
on 2023-12-05
next-connect
from 0.12.2 to 0.13.0 | 1 version ahead of your current version | 2 years ago
on 2022-07-23
openid-client
from 5.4.0 to 5.6.5 | 10 versions ahead of your current version | 6 months ago
on 2024-03-07
passport
from 0.6.0 to 0.7.0 | 1 version ahead of your current version | 9 months ago
on 2023-11-27
react-bootstrap
from 1.6.6 to 1.6.8 | 2 versions ahead of your current version | 9 months ago
on 2023-12-22
react-bootstrap-icons
from 1.10.3 to 1.11.4 | 2 versions ahead of your current version | 5 months ago
on 2024-04-11
react-grid-layout
from 1.3.4 to 1.4.4 | 5 versions ahead of your current version | 10 months ago
on 2023-11-24
react-rating-stars-component
from 2.2.0 to 2.2.3 | 1 version ahead of your current version | 5 years ago
on 2019-04-15
Issues fixed by the recommended upgrade:
SNYK-JS-JOSE-6419224
SNYK-JS-MONGODB-5871303
Release notes
Package name: @i3m/non-repudiation-library
2.6.4
2.6.3
2.6.2
2.6.0
2.5.7
Package name: @i3m/wallet-protocol
v2.6.1
v2.6.0
v2.5.11
v2.5.10
v2.5.8
Package name: @i3m/wallet-protocol-api
v2.6.1
v2.6.0
v2.5.11
v2.5.10
v2.5.9
Package name: @i3m/wallet-protocol-utils
v2.6.1
v2.6.0
v2.5.11
v2.5.10
v2.5.9
Package name: express-session
partitioned
tocookie
optionspriority
tocookie
optionssecret
thatcrypto.createHmac
supportsexpires
option to reject invalid datesPackage name: moment
2.30.1
2.30.0
2.29.4
Package name: mongodb
4.17.2 (2023-11-16)
The MongoDB Node.js team is pleased to announce version 4.17.2 of the
mongodb
package!Release Notes
Fix connection leak when serverApi is enabled
When enabling serverApi the driver's RTT mesurment logic (used to determine the closest node) still sent the legacy hello command "isMaster" causing the server to return an error. Unfortunately, the error handling logic did not correctly destroy the socket which would cause a leak.
Both sending the correct hello command and the error handling connection clean up logic are fixed in this change.
Bug Fixes
Documentation
We invite you to try the
mongodb
library immediately, and report any issues to the NODE project.4.17.1 (2023-08-23)
The MongoDB Node.js team is pleased to announce version 4.17.1 of the
mongodb
package!Release Notes
Import of
saslprep
updated to correct library.Fixes the import of saslprep to be the correct
@ mongodb-js/saslprep
library.Bug Fixes
Documentation
We invite you to try the
mongodb
library immediately, and report any issues to the NODE project.Package name: next-connect
0.13.0
0.12.2
Package name: openid-client
Refactor
Revert "fix: encode client_secret_basic - _ . ! ~ * ' ( ) characters"
This reverts commit 5a2ea80, even though it is the correct implementation some of the most widely used identity providers don't follow the specification.
Fixes
Refactor
Fixes
Fixes
Features
Features
Fixes
Fixes
This release contains only code refactoring, dependency, or documentation updates. The release process now also uses provenance statements.
Package name: passport
0.7.0
0.6.0
Package name: react-bootstrap
1.6.8 (2023-12-22)
Bug Fixes
1.6.7 (2023-05-03)
Bug Fixes
content
prop error (#6612) (3d1df53)Package name: react-bootstrap-icons
v1.11.4
v1.11.3
v1.10.3
Package name: react-grid-layout
release 1.4.4
release 1.4.3
release 1.4.2
Uncategorized
Uncategorized
lodash.isequal
tofast-equals
npm bin
Uncategorized
Package name: react-rating-stars-component
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: