[Snyk] Upgrade mongodb from 4.17.0 to 4.17.2 #1304
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade mongodb from 4.17.0 to 4.17.2.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 2 versions ahead of your current version.
The recommended version was released 2 years ago.
Issues fixed by the recommended upgrade:
SNYK-JS-FOLLOWREDIRECTS-6141137
SNYK-JS-IP-6240864
SNYK-JS-FASTXMLPARSER-7573289
SNYK-JS-FOLLOWREDIRECTS-6444610
SNYK-JS-FORMDATA-10841150
SNYK-JS-IP-7148531
Release notes
Package name: mongodb
-
4.17.2 - 2023-12-05
- NODE-5751: RTTPinger always sends legacy hello (#3923) (bc3d020)
- Reference
- API
- Changelog
-
4.17.1 - 2023-08-23
- NODE-5573: fix saslprep import (#3838) (ff6c293)
- Reference
- API
- Changelog
-
4.17.0 - 2023-08-17
from mongodb GitHub release notes4.17.2 (2023-11-16)
The MongoDB Node.js team is pleased to announce version 4.17.2 of the
mongodbpackage!Release Notes
Fix connection leak when serverApi is enabled
When enabling serverApi the driver's RTT mesurment logic (used to determine the closest node) still sent the legacy hello command "isMaster" causing the server to return an error. Unfortunately, the error handling logic did not correctly destroy the socket which would cause a leak.
Both sending the correct hello command and the error handling connection clean up logic are fixed in this change.
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.4.17.1 (2023-08-23)
The MongoDB Node.js team is pleased to announce version 4.17.1 of the
mongodbpackage!Release Notes
Import of
saslprepupdated to correct library.Fixes the import of saslprep to be the correct
@ mongodb-js/saslpreplibrary.Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: