Skip to content

chore: [Snyk] Security upgrade next from 13.5.7 to 13.5.9 #20412

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Mar 28, 2025

Conversation

pumfleet
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • apps/api/v1/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue
critical severity Improper Authorization
SNYK-JS-NEXT-9508709

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Improper Authorization

@pumfleet pumfleet requested review from a team as code owners March 27, 2025 18:52
Copy link

vercel bot commented Mar 27, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

2 Skipped Deployments
Name Status Preview Comments Updated (UTC)
cal ⬜️ Ignored (Inspect) Visit Preview Mar 28, 2025 1:54pm
calcom-web-canary ⬜️ Ignored (Inspect) Visit Preview Mar 28, 2025 1:54pm

@graphite-app graphite-app bot requested a review from a team March 27, 2025 18:52
Copy link
Contributor

github-actions bot commented Mar 27, 2025

Hey there and thank you for opening this pull request! 👋🏼

We require pull request titles to follow the Conventional Commits specification and it looks like your proposed title needs to be adjusted.

Details:

No release type found in pull request title "[Snyk] Security upgrade next from 13.5.7 to 13.5.9". Add a prefix to indicate what kind of release this pull request corresponds to. For reference, see https://www.conventionalcommits.org/

Available types:
 - feat: A new feature
 - fix: A bug fix
 - docs: Documentation only changes
 - style: Changes that do not affect the meaning of the code (white-space, formatting, missing semi-colons, etc)
 - refactor: A code change that neither fixes a bug nor adds a feature
 - perf: A code change that improves performance
 - test: Adding missing tests or correcting existing tests
 - build: Changes that affect the build system or external dependencies (example scopes: gulp, broccoli, npm)
 - ci: Changes to our CI configuration files and scripts (example scopes: Travis, Circle, BrowserStack, SauceLabs)
 - chore: Other changes that don't modify src or test files
 - revert: Reverts a previous commit

@keithwillcode keithwillcode added the core area: core, team members only label Mar 27, 2025
@dosubot dosubot bot added the ⬆️ dependencies Pull requests that update a dependency file label Mar 27, 2025
Copy link

graphite-app bot commented Mar 27, 2025

Graphite Automations

"Add consumer team as reviewer" took an action on this PR • (03/27/25)

1 reviewer was added to this PR based on Keith Williams's automation.

"Add ready-for-e2e label" took an action on this PR • (03/28/25)

1 label was added to this PR based on Keith Williams's automation.

@CLAassistant
Copy link

CLAassistant commented Mar 28, 2025

CLA assistant check
All committers have signed the CLA.

@keithwillcode keithwillcode changed the title [Snyk] Security upgrade next from 13.5.7 to 13.5.9 chore: [Snyk] Security upgrade next from 13.5.7 to 13.5.9 Mar 28, 2025
@keithwillcode keithwillcode enabled auto-merge (squash) March 28, 2025 13:54
Copy link
Contributor

E2E results are ready!

@keithwillcode keithwillcode merged commit 30367cd into main Mar 28, 2025
61 of 65 checks passed
@keithwillcode keithwillcode deleted the snyk-fix-0046b2e6a96b199d180c0fbad05502ce branch March 28, 2025 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
core area: core, team members only ⬆️ dependencies Pull requests that update a dependency file ready-for-e2e
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants