Skip to content

Conversation

@CFenner
Copy link
Owner

@CFenner CFenner commented Dec 4, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
Yes Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: simple-oauth2 The new version differs by 35 commits.
  • b23969e Merge branch 'release/2.0.0' into develop
  • 3252877 Release library version 2.0.0
  • fd49fff Merge pull request #174 from lelylan/feature/improve-integration-tests
  • d4ebcf2 Add missing integration test. Add coverage check support. Fix most of linting rules
  • c295fd8 Add editorconfig file
  • 0d86d08 Fix access tokens expiration integration tests
  • 2f45eec Merge branch 'develop' into feature/improve-integration-tests
  • e3f87a5 Resolve conflicts with develop
  • 329cdec Temporal commit
  • 3031378 Add additional integration tests
  • 3d6bbb7 Merge pull request #164 from lelylan/feature/simplify-authorization-options
  • cb93040 Simplify integration tests
  • 378b60d Add clarification of authorizationMethod usage
  • 9bb1e81 Fix typo on README
  • df29213 Update documentation to reflect the authorization method property
  • 9129d1a Simplify authorization mode options from multiple properties to a single one
  • 81b02ae Merge pull request #162 from lelylan/feature/use-async-await
  • 5cbeb75 Restore token revocation explanation comments
  • 11e6c70 Fix formatting on nvmrc file
  • e0b4e25 Add clarifications to module README
  • 025aa84 Add additional debug information
  • 5aff7c0 Refactor core request module to remove all unnecessary branches caused by the previously exposed api method
  • 7149474 Use only async functions. Rewrite Access Token class into a ES6 class
  • bf5c23f Update module entry point to use default args. Update .npmignore file to exclude unnecessary files

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Server-side Request Forgery (SSRF)
🦉 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants