Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency mongoose [security] #1704

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 1, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
mongoose (source) 5.13.9 -> 5.13.20 age adoption passing confidence
mongoose (source) 5.13.15 -> 5.13.20 age adoption passing confidence
mongoose (source) 6.8.2 -> 6.11.3 age adoption passing confidence
mongoose (source) 6.2.10 -> 6.11.3 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-3696

Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.3, 6.11.3, and 5.13.20.


Release Notes

Automattic/mongoose (mongoose)

v5.13.20

Compare Source

v5.13.19

Compare Source

v5.13.18

Compare Source

v5.13.17

Compare Source

====================

v5.13.16

Compare Source

====================

v5.13.15

Compare Source

====================

v5.13.14

Compare Source

====================

  • fix(timestamps): avoid setting createdAt on documents that already exist but dont have createdAt #​11024
  • docs(models): fix up nModified example for 5.x #​11055

v5.13.13

Compare Source

====================

v5.13.12

Compare Source

====================

  • fix(cursor): use stream destroy method on close to prevent emitting duplicate 'close' #​10897 iovanom
  • fix(index.d.ts): backport streamlining of FilterQuery and DocumentDefinition to avoid "excessively deep and possibly infinite" TS errors #​10617

v5.13.11

Compare Source

====================

  • fix: upgrade mongodb -> 3.7.2 #​10871 winstonralph
  • fix(connection): call setMaxListeners(0) on MongoClient to avoid event emitter memory leak warnings with useDb() #​10732

v5.13.10

Compare Source

====================

  • fix(index.d.ts): allow using type: SchemaDefinitionProperty in schema definitions #​10674
  • fix(index.d.ts): allow AnyObject as param to findOneAndReplace() #​10714

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from 8f3ddc4 to 1b5bc29 Compare February 1, 2023 10:23
@renovate renovate bot changed the title chore(deps): update dependency mongoose to 6.4.6 [security] chore(deps): update dependency mongoose [security] Feb 1, 2023
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch 2 times, most recently from 2747035 to dc48afb Compare February 8, 2023 17:46
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from dc48afb to 48592da Compare February 15, 2023 16:27
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from 48592da to 748ce29 Compare February 28, 2023 00:25
@renovate renovate bot changed the title chore(deps): update dependency mongoose [security] fix(deps): update dependency mongoose [security] Mar 24, 2023
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch 22 times, most recently from 17a0498 to 8172727 Compare April 3, 2023 09:25
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from 8172727 to 89ecc58 Compare April 3, 2023 19:05
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch 2 times, most recently from 09dae24 to 3b5eade Compare April 18, 2023 18:42
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from 3b5eade to 979d305 Compare May 2, 2023 12:20
@renovate renovate bot changed the title fix(deps): update dependency mongoose [security] chore(deps): update dependency mongoose [security] May 17, 2023
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from 979d305 to b2b7891 Compare May 28, 2023 12:08
@renovate renovate bot changed the title chore(deps): update dependency mongoose [security] fix(deps): update dependency mongoose [security] May 28, 2023
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from b2b7891 to a1bd65a Compare June 4, 2023 12:31
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch 3 times, most recently from ff51390 to 0a1964f Compare June 19, 2023 07:32
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from 0a1964f to 9b5efa8 Compare June 29, 2023 12:02
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch 3 times, most recently from 92e86a7 to f3abccd Compare July 9, 2023 09:14
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch 3 times, most recently from d84f2bd to e21e58a Compare July 26, 2023 05:15
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch 2 times, most recently from 756f6df to db252c4 Compare August 1, 2023 20:24
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from db252c4 to d368f23 Compare August 6, 2023 08:11
@renovate renovate bot force-pushed the renovate/npm-mongoose-vulnerability branch from d368f23 to 6dfd038 Compare August 13, 2023 05:52
@hybridx hybridx closed this Aug 23, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant