Skip to content

[Snyk] Upgrade mongoose from 8.20.0 to 8.20.1#268

Open
OOCAZ wants to merge 1 commit intomasterfrom
snyk-upgrade-791ac420db08b9bd69238a21e0da71cb
Open

[Snyk] Upgrade mongoose from 8.20.0 to 8.20.1#268
OOCAZ wants to merge 1 commit intomasterfrom
snyk-upgrade-791ac420db08b9bd69238a21e0da71cb

Conversation

@OOCAZ
Copy link
Owner

@OOCAZ OOCAZ commented Dec 23, 2025

snyk-top-banner

Snyk has created this PR to upgrade mongoose from 8.20.0 to 8.20.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.

  • The recommended version was released a month ago.

Release notes
Package name: mongoose
  • 8.20.1 - 2025-11-20

    8.20.1 / 2025-11-20

    • types: correct Model.schema type and fix unknown check for this param type in schema.methods #15750 #15693
    • docs: add detailed loadClass() TypeScript usage guide #15731 #12813 Necro-Rohan
    • docs: update version support documentation for Mongoose #15761 ManmathX
    • docs: add copy-to-clipboard feature for code blocks in docs #15759 vedansha07
  • 8.20.0 - 2025-11-17
from mongoose GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade mongoose from 8.20.0 to 8.20.1.

See this package in npm:
mongoose

See this project in Snyk:
https://app.snyk.io/org/oocaz/project/52a738f2-082c-454b-8514-84c41ff1c179?utm_source=github&utm_medium=referral&page=upgrade-pr
@github-actions
Copy link

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/mongoose 8.20.1 🟢 6.8
Details
CheckScoreReason
Security-Policy🟢 9security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 5Found 8/16 approved changesets -- score normalized to 5
Maintained🟢 1030 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Pinned-Dependencies⚠️ 2dependency not pinned by hash detected -- score normalized to 2
Vulnerabilities🟢 100 existing vulnerabilities detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Packaging🟢 10packaging workflow detected
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 7SAST tool detected but not run on all commits

Scanned Files

  • package-lock.json

@netlify
Copy link

netlify bot commented Dec 23, 2025

Deploy Preview for splendorous-snickerdoodle-0e3599 ready!

Name Link
🔨 Latest commit 5d195ba
🔍 Latest deploy log https://app.netlify.com/projects/splendorous-snickerdoodle-0e3599/deploys/694a991a8df4a3000805c8e3
😎 Deploy Preview https://deploy-preview-268--splendorous-snickerdoodle-0e3599.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 83
Accessibility: 91
Best Practices: 92
SEO: 100
PWA: -
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify project configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants