Skip to content

[Snyk] Upgrade mongoose from 8.19.2 to 8.20.0#262

Merged
OOCAZ merged 1 commit intomasterfrom
snyk-upgrade-ac4146bee62bd0a27274bb489951ef54
Dec 11, 2025
Merged

[Snyk] Upgrade mongoose from 8.19.2 to 8.20.0#262
OOCAZ merged 1 commit intomasterfrom
snyk-upgrade-ac4146bee62bd0a27274bb489951ef54

Conversation

@OOCAZ
Copy link
Copy Markdown
Owner

@OOCAZ OOCAZ commented Dec 9, 2025

snyk-top-banner

Snyk has created this PR to upgrade mongoose from 8.19.2 to 8.20.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 3 versions ahead of your current version.

  • The recommended version was released 22 days ago.

Release notes
Package name: mongoose
  • 8.20.0 - 2025-11-17

    8.20.0 / 2025-11-17

    • feat: cast id parameter based on schema _id type in DocumentArray.id() #15733 #15725 #15724 Lex-Ashu
    • fix: pass parent schema to SchemaType constructors in interpretAsType to make implementing custom container types easier #15700
    • types(models): default _id type to ObjectId for Document #15688 Catwallon
    • docs: add FAQ entry about DivergentArrayError #15743 Mario5T
    • docs: update browser.md with Mongoose limitations #15744 YashSharma64
    • chore: add benchmark for large nested array documents (related to #9588) #15742 Kundan-CR7
  • 8.19.4 - 2025-11-14

    8.19.4 / 2025-11-14

  • 8.19.3 - 2025-11-04

    8.19.3 / 2025-11-04

    • fix(model+plugins): correctly apply shard key on deleteOne() #15705 #15701
    • fix(schema): correctly cache text indexes as 'text' not 1 #15695
    • types: make inferRawDocType correctly infer empty array type [] as any[] #15704 #15699
  • 8.19.2 - 2025-10-20
from mongoose GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade mongoose from 8.19.2 to 8.20.0.

See this package in npm:
mongoose

See this project in Snyk:
https://app.snyk.io/org/oocaz/project/52a738f2-082c-454b-8514-84c41ff1c179?utm_source=github&utm_medium=referral&page=upgrade-pr
@github-actions
Copy link
Copy Markdown

github-actions bot commented Dec 9, 2025

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/mongoose 8.20.0 🟢 6.5
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review⚠️ 2Found 6/24 approved changesets -- score normalized to 2
Security-Policy🟢 9security policy file detected
Maintained🟢 1030 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
License🟢 10license file detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Vulnerabilities🟢 100 existing vulnerabilities detected
Pinned-Dependencies⚠️ 2dependency not pinned by hash detected -- score normalized to 2
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Packaging🟢 10packaging workflow detected
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 7SAST tool detected but not run on all commits

Scanned Files

  • package-lock.json

@netlify
Copy link
Copy Markdown

netlify bot commented Dec 9, 2025

Deploy Preview for splendorous-snickerdoodle-0e3599 ready!

Name Link
🔨 Latest commit 0f406d4
🔍 Latest deploy log https://app.netlify.com/projects/splendorous-snickerdoodle-0e3599/deploys/693800a314a16a0008d7423c
😎 Deploy Preview https://deploy-preview-262--splendorous-snickerdoodle-0e3599.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 86
Accessibility: 91
Best Practices: 92
SEO: 100
PWA: -
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify project configuration.

@OOCAZ OOCAZ merged commit 89a931f into master Dec 11, 2025
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants