[Snyk] Upgrade: yaml, qs, , , tslib, , , , ioredis, msgpackr, , , , , , , , , , , , , ajv, ansi-colors, env-var, get-tsconfig, gpt-tokenizer, graphql, joi, zod, openai, langchain, micromatch, mysql2, nanoid, neo4j-driver, octokit, passport, pg, pusher, randomstring, remove-markdown, set-cookie-parser, simple-git, stripe, tree-sitter, tree-sitter-typescript, type-fest, typescript, underscore, webpack, winston, winston-transport-sentry-node#713
[Snyk] Upgrade: yaml, qs, , , tslib, , , , ioredis, msgpackr, , , , , , , , , , , , , ajv, ansi-colors, env-var, get-tsconfig, gpt-tokenizer, graphql, joi, zod, openai, langchain, micromatch, mysql2, nanoid, neo4j-driver, octokit, passport, pg, pusher, randomstring, remove-markdown, set-cookie-parser, simple-git, stripe, tree-sitter, tree-sitter-typescript, type-fest, typescript, underscore, webpack, winston, winston-transport-sentry-node#713karlclement wants to merge 1 commit intodevelopmentfrom
Conversation
Snyk has created this PR to upgrade:
- yaml from 2.3.1 to 2.5.0.
See this package in npm: https://www.npmjs.com/package/yaml
- qs from 6.12.1 to 6.13.0.
See this package in npm: https://www.npmjs.com/package/qs
- @gitbeaker/core from 39.13.0 to 39.34.3.
See this package in npm: https://www.npmjs.com/package/@gitbeaker/core
- @gitbeaker/rest from 39.13.0 to 39.34.3.
See this package in npm: https://www.npmjs.com/package/@gitbeaker/rest
- tslib from 2.4.1 to 2.7.0.
See this package in npm: https://www.npmjs.com/package/tslib
- @slack/oauth from 2.6.2 to 2.6.3.
See this package in npm: https://www.npmjs.com/package/@slack/oauth
- @types/express from 4.17.13 to 4.17.21.
See this package in npm: https://www.npmjs.com/package/@types/express
- @slack/bolt from 3.18.0 to 3.21.1.
See this package in npm: https://www.npmjs.com/package/@slack/bolt
- ioredis from 5.3.2 to 5.4.1.
See this package in npm: https://www.npmjs.com/package/ioredis
- msgpackr from 1.10.1 to 1.11.0.
See this package in npm: https://www.npmjs.com/package/msgpackr
- @types/airbnb__node-memwatch from 2.0.0 to 2.0.3.
See this package in npm: https://www.npmjs.com/package/@types/airbnb__node-memwatch
- @types/analytics-node from 3.1.9 to 3.1.14.
See this package in npm: https://www.npmjs.com/package/@types/analytics-node
- @types/command-line-args from 5.2.0 to 5.2.3.
See this package in npm: https://www.npmjs.com/package/@types/command-line-args
- @types/cors from 2.8.12 to 2.8.17.
See this package in npm: https://www.npmjs.com/package/@types/cors
- @types/diff from 5.0.9 to 5.2.2.
See this package in npm: https://www.npmjs.com/package/@types/diff
- @types/js-yaml from 4.0.5 to 4.0.9.
See this package in npm: https://www.npmjs.com/package/@types/js-yaml
- @types/micromatch from 4.0.7 to 4.0.9.
See this package in npm: https://www.npmjs.com/package/@types/micromatch
- @types/morgan from 1.9.3 to 1.9.9.
See this package in npm: https://www.npmjs.com/package/@types/morgan
- @types/passport from 1.0.8 to 1.0.16.
See this package in npm: https://www.npmjs.com/package/@types/passport
- @types/passport-github2 from 1.2.5 to 1.2.9.
See this package in npm: https://www.npmjs.com/package/@types/passport-github2
- @types/passport-jwt from 3.0.6 to 3.0.13.
See this package in npm: https://www.npmjs.com/package/@types/passport-jwt
- @types/set-cookie-parser from 2.4.2 to 2.4.10.
See this package in npm: https://www.npmjs.com/package/@types/set-cookie-parser
- ajv from 8.12.0 to 8.17.1.
See this package in npm: https://www.npmjs.com/package/ajv
- ansi-colors from 4.1.1 to 4.1.3.
See this package in npm: https://www.npmjs.com/package/ansi-colors
- env-var from 7.1.1 to 7.5.0.
See this package in npm: https://www.npmjs.com/package/env-var
- get-tsconfig from 4.7.3 to 4.8.0.
See this package in npm: https://www.npmjs.com/package/get-tsconfig
- gpt-tokenizer from 2.1.2 to 2.2.1.
See this package in npm: https://www.npmjs.com/package/gpt-tokenizer
- graphql from 16.8.1 to 16.9.0.
See this package in npm: https://www.npmjs.com/package/graphql
- joi from 17.13.1 to 17.13.3.
See this package in npm: https://www.npmjs.com/package/joi
- zod from 3.23.4 to 3.23.8.
See this package in npm: https://www.npmjs.com/package/zod
- openai from 4.47.2 to 4.57.0.
See this package in npm: https://www.npmjs.com/package/openai
- langchain from 0.1.36 to 0.2.17.
See this package in npm: https://www.npmjs.com/package/langchain
- micromatch from 4.0.7 to 4.0.8.
See this package in npm: https://www.npmjs.com/package/micromatch
- mysql2 from 3.10.2 to 3.11.0.
See this package in npm: https://www.npmjs.com/package/mysql2
- nanoid from 3.3.3 to 3.3.7.
See this package in npm: https://www.npmjs.com/package/nanoid
- neo4j-driver from 5.17.0 to 5.24.0.
See this package in npm: https://www.npmjs.com/package/neo4j-driver
- octokit from 3.2.0 to 3.2.1.
See this package in npm: https://www.npmjs.com/package/octokit
- passport from 0.6.0 to 0.7.0.
See this package in npm: https://www.npmjs.com/package/passport
- pg from 8.11.3 to 8.12.0.
See this package in npm: https://www.npmjs.com/package/pg
- pusher from 5.0.1 to 5.2.0.
See this package in npm: https://www.npmjs.com/package/pusher
- randomstring from 1.2.3 to 1.3.0.
See this package in npm: https://www.npmjs.com/package/randomstring
- remove-markdown from 0.3.0 to 0.5.3.
See this package in npm: https://www.npmjs.com/package/remove-markdown
- set-cookie-parser from 2.5.1 to 2.7.0.
See this package in npm: https://www.npmjs.com/package/set-cookie-parser
- simple-git from 3.21.0 to 3.25.0.
See this package in npm: https://www.npmjs.com/package/simple-git
- stripe from 15.7.0 to 15.12.0.
See this package in npm: https://www.npmjs.com/package/stripe
- tree-sitter from 0.20.6 to 0.21.1.
See this package in npm: https://www.npmjs.com/package/tree-sitter
- tree-sitter-typescript from 0.20.3 to 0.21.2.
See this package in npm: https://www.npmjs.com/package/tree-sitter-typescript
- type-fest from 4.17.0 to 4.26.0.
See this package in npm: https://www.npmjs.com/package/type-fest
- typescript from 5.4.5 to 5.5.4.
See this package in npm: https://www.npmjs.com/package/typescript
- underscore from 1.13.6 to 1.13.7.
See this package in npm: https://www.npmjs.com/package/underscore
- webpack from 5.91.0 to 5.94.0.
See this package in npm: https://www.npmjs.com/package/webpack
- winston from 3.7.2 to 3.14.2.
See this package in npm: https://www.npmjs.com/package/winston
- winston-transport-sentry-node from 2.3.0 to 2.8.0.
See this package in npm: https://www.npmjs.com/package/winston-transport-sentry-node
See this project in Snyk:
https://app.snyk.io/org/k-qm5/project/d4043113-1d04-4734-91a7-73ef9e4aabad?utm_source=github&utm_medium=referral&page=upgrade-pr
Hi there, Squire here! 👋Here's what I can do today:
You can always clear and then run review again if you've committed more to get a fresh review. For more info, including how to add our generated PR descriptions to a template, check out our docs: https://docs.squire.ai/ |
Pull request summary created by Squire AISummaryThis pull request updates multiple dependencies to their latest versions using Snyk. The updates include packages such as yaml, qs, tslib, ioredis, msgpackr, ajv, ansi-colors, env-var, graphql, joi, zod, openai, langchain, micromatch, mysql2, nanoid, neo4j-driver, octokit, passport, pg, pusher, randomstring, remove-markdown, set-cookie-parser, simple-git, stripe, tree-sitter, type-fest, typescript, underscore, webpack, winston, and winston-transport-sentry-node. These updates aim to improve security, performance, and compatibility. File SummaryFile Changes
|
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
yaml
from 2.3.1 to 2.5.0 | 10 versions ahead of your current version | 2 months ago
on 2024-07-24
qs
from 6.12.1 to 6.13.0 | 3 versions ahead of your current version | 2 months ago
on 2024-08-01
@gitbeaker/core
from 39.13.0 to 39.34.3 | 39 versions ahead of your current version | 7 months ago
on 2024-02-20
@gitbeaker/rest
from 39.13.0 to 39.34.3 | 39 versions ahead of your current version | 7 months ago
on 2024-02-20
tslib
from 2.4.1 to 2.7.0 | 9 versions ahead of your current version | a month ago
on 2024-08-23
@slack/oauth
from 2.6.2 to 2.6.3 | 1 version ahead of your current version | a month ago
on 2024-08-16
@types/express
from 4.17.13 to 4.17.21 | 8 versions ahead of your current version | 10 months ago
on 2023-11-07
@slack/bolt
from 3.18.0 to 3.21.1 | 4 versions ahead of your current version | a month ago
on 2024-08-16
ioredis
from 5.3.2 to 5.4.1 | 2 versions ahead of your current version | 5 months ago
on 2024-04-17
msgpackr
from 1.10.1 to 1.11.0 | 2 versions ahead of your current version | 2 months ago
on 2024-07-15
@types/airbnb__node-memwatch
from 2.0.0 to 2.0.3 | 3 versions ahead of your current version | 10 months ago
on 2023-11-06
@types/analytics-node
from 3.1.9 to 3.1.14 | 5 versions ahead of your current version | 10 months ago
on 2023-11-06
@types/command-line-args
from 5.2.0 to 5.2.3 | 3 versions ahead of your current version | 10 months ago
on 2023-11-07
@types/cors
from 2.8.12 to 2.8.17 | 5 versions ahead of your current version | 10 months ago
on 2023-11-20
@types/diff
from 5.0.9 to 5.2.2 | 3 versions ahead of your current version | 24 days ago
on 2024-08-28
@types/js-yaml
from 4.0.5 to 4.0.9 | 4 versions ahead of your current version | 10 months ago
on 2023-11-07
@types/micromatch
from 4.0.7 to 4.0.9 | 2 versions ahead of your current version | 3 months ago
on 2024-06-29
@types/morgan
from 1.9.3 to 1.9.9 | 6 versions ahead of your current version | 10 months ago
on 2023-11-07
@types/passport
from 1.0.8 to 1.0.16 | 8 versions ahead of your current version | 10 months ago
on 2023-11-21
@types/passport-github2
from 1.2.5 to 1.2.9 | 4 versions ahead of your current version | 10 months ago
on 2023-11-07
@types/passport-jwt
from 3.0.6 to 3.0.13 | 7 versions ahead of your current version | 10 months ago
on 2023-11-07
@types/set-cookie-parser
from 2.4.2 to 2.4.10 | 8 versions ahead of your current version | 2 months ago
on 2024-07-09
ajv
from 8.12.0 to 8.17.1 | 5 versions ahead of your current version | 2 months ago
on 2024-07-12
ansi-colors
from 4.1.1 to 4.1.3 | 2 versions ahead of your current version | 2 years ago
on 2022-05-16
env-var
from 7.1.1 to 7.5.0 | 7 versions ahead of your current version | 4 months ago
on 2024-05-20
get-tsconfig
from 4.7.3 to 4.8.0 | 4 versions ahead of your current version | 23 days ago
on 2024-08-29
gpt-tokenizer
from 2.1.2 to 2.2.1 | 2 versions ahead of your current version | 2 months ago
on 2024-07-18
graphql
from 16.8.1 to 16.9.0 | 4 versions ahead of your current version | 3 months ago
on 2024-06-21
joi
from 17.13.1 to 17.13.3 | 2 versions ahead of your current version | 3 months ago
on 2024-06-19
zod
from 3.23.4 to 3.23.8 | 4 versions ahead of your current version | 4 months ago
on 2024-05-08
openai
from 4.47.2 to 4.57.0 | 34 versions ahead of your current version | 23 days ago
on 2024-08-29
langchain
from 0.1.36 to 0.2.17 | 22 versions ahead of your current version | a month ago
on 2024-08-23
micromatch
from 4.0.7 to 4.0.8 | 1 version ahead of your current version | a month ago
on 2024-08-23
mysql2
from 3.10.2 to 3.11.0 | 2 versions ahead of your current version | 2 months ago
on 2024-07-27
nanoid
from 3.3.3 to 3.3.7 | 4 versions ahead of your current version | a year ago
on 2023-11-06
neo4j-driver
from 5.17.0 to 5.24.0 | 7 versions ahead of your current version | 23 days ago
on 2024-08-29
octokit
from 3.2.0 to 3.2.1 | 2 versions ahead of your current version | 5 months ago
on 2024-05-03
passport
from 0.6.0 to 0.7.0 | 1 version ahead of your current version | 10 months ago
on 2023-11-27
pg
from 8.11.3 to 8.12.0 | 4 versions ahead of your current version | 4 months ago
on 2024-06-04
pusher
from 5.0.1 to 5.2.0 | 5 versions ahead of your current version | 10 months ago
on 2023-11-13
randomstring
from 1.2.3 to 1.3.0 | 1 version ahead of your current version | a year ago
on 2023-06-02
remove-markdown
from 0.3.0 to 0.5.3 | 3 versions ahead of your current version | 23 days ago
on 2024-08-29
set-cookie-parser
from 2.5.1 to 2.7.0 | 2 versions ahead of your current version | 2 months ago
on 2024-08-01
simple-git
from 3.21.0 to 3.25.0 | 4 versions ahead of your current version | 3 months ago
on 2024-06-10
stripe
from 15.7.0 to 15.12.0 | 8 versions ahead of your current version | 3 months ago
on 2024-06-17
tree-sitter
from 0.20.6 to 0.21.1 | 2 versions ahead of your current version | 6 months ago
on 2024-03-28
tree-sitter-typescript
from 0.20.3 to 0.21.2 | 4 versions ahead of your current version | 2 months ago
on 2024-07-06
type-fest
from 4.17.0 to 4.26.0 | 14 versions ahead of your current version | 24 days ago
on 2024-08-28
typescript
from 5.4.5 to 5.5.4 | 106 versions ahead of your current version | 2 months ago
on 2024-07-22
underscore
from 1.13.6 to 1.13.7 | 1 version ahead of your current version | 2 months ago
on 2024-07-24
webpack
from 5.91.0 to 5.94.0 | 4 versions ahead of your current version | a month ago
on 2024-08-22
winston
from 3.7.2 to 3.14.2 | 13 versions ahead of your current version | a month ago
on 2024-08-14
winston-transport-sentry-node
from 2.3.0 to 2.8.0 | 7 versions ahead of your current version | 4 months ago
on 2024-06-03
Issues fixed by the recommended upgrade:
SNYK-JS-WS-7266574
SNYK-JS-MICROMATCH-6838728
SNYK-JS-WEBPACK-7840298
SNYK-JS-REMOVEMARKDOWN-73635
Release notes
Package name: yaml
-
2.5.0 - 2024-07-24
- Add
- Require newline in all cases for props on block sequence (#557)
- Always reset indentation in lexer on
- Ignore
- Drop unused
-
2.4.5 - 2024-06-08
- Improve tab handling (#553, yaml-test-suite tests DK95 & Y79Y)
-
2.4.4 - 2024-06-08
- Allow comment after top-level block scalar with explicit indent indicator (#547)
- Allow tab as indent for line comments before nodes (#548)
- Do not allow tab before block collection (#549)
- In flow collections, allow
- Require indentation for
- Require indentation from block scalar header & flow collections in mapping values (#553)
-
2.4.3 - 2024-06-02
- Improve error when parsing a non-string value (#459)
- Do not parse
- Support
- Check for non-node complex keys when stringifying with simpleKeys (#541)
-
2.4.2 - 2024-04-28
- Restrict YAML 1.1 boolean strings to their explicit capitalization (#530)
- Add sponsorship by Scipress (#536)
-
2.4.1 - 2024-03-06
- cst: Do not drop trailing newline after line comment in block-map if followed by unindented block-seq value (#525)
- Stringify flow collection comments in parent (#528)
- Do not skip folding lines after the first in indented block scalars (#529)
-
2.4.0 - 2024-02-25
- Add a command-line tool (#523)
- Use the
-
2.3.4 - 2023-11-03
- Do not throw for carriage return in tag shorthand (#501)
-
2.3.3 - 2023-10-14
- Do not throw error on malformed URI escape in tag (#498)
-
2.3.2 - 2023-08-28
- Fix docs typo (#489)
- Do not require quotes for implicit keys with flow indicators (#494)
- Update Prettier to v3 & update ESLint config
-
2.3.1 - 2023-05-26
from yaml GitHub release notes--indentoption to CLI tool (#559, with thanks to @ danielbayley)...(#558)minContentWidthif greater thanlineWidth(#562)Collection.maxFlowStringSingleLineLength(#522, #421)With special thanks to @ RedCMD for finding and reporting all of the following:
[]{}immediately after:with plain key (#550)?explicit-key contents (#551)-.NaNor+.nanas NaN (#546)#within%TAGprefixes with trailing#commentslineWidthoption for line breaking in flow collections (#522)Package name: qs
-
6.13.0 - 2024-08-01
-
6.12.3 - 2024-07-08
-
6.12.2 - 2024-07-01
-
6.12.1 - 2024-04-12
from qs GitHub release notesv6.13.0
v6.12.3
v6.12.2
v6.12.1
Package name: tslib
-
2.7.0 - 2024-08-23
- Implement deterministic collapse of
- Use global 'Iterator.prototype' for downlevel generators by @ rbuckton in #267
-
2.6.3 - 2024-06-04
- 'await using' normative changes by @ rbuckton in #258
-
2.6.2 - 2023-08-18
- Fix path to
-
2.6.1 - 2023-07-24
- Allow functions as values in __addDisposableResource by @ rbuckton in #215
- Stop using es6 syntax in the es6 file by @ andrewbranch in #216
-
2.6.0 - 2023-06-26
- Add helpers for
-
2.5.3 - 2023-06-02
- Do not reference tslib.es6.js from package.json exports by @ andrewbranch in #208
-
2.5.2 - 2023-05-18
-
2.5.1 - 2023-05-17
-
2.5.0 - 2023-01-26
- Fix asyncDelegator reporting done too early by @ apendua in #187
- Add support for TypeScript 5.0's
-
2.4.1 - 2022-10-31
from tslib GitHub release notesWhat's Changed
awaitinawait usingby @ rbuckton in #262Full Changelog: v2.6.3...v2.7.0
What's Changed
Full Changelog: v2.6.2...v2.6.3
What's Changed
exports["module"]["types"]by @ andrewbranch in #217Full Changelog: v2.6.1...v2.6.2
What's Changed
Full Changelog: 2.6.0...v2.6.1
What's Changed
usingandawait usingby @ rbuckton in #213Full Changelog: v2.5.3...2.6.0
What's Changed
Full Changelog: 2.5.2...v2.5.3
This release explicitly re-exports helpers to work around TypeScript's incomplete symbol resolution for tslib.
This release of tslib provides fixes for two issues.
First, it reverses the order of
inithooks provided by decorators to correctly reflect proposed behavior.Second, it corrects the
exportsfield of tslib'spackage.jsonand provides accurate declaration files so that it may be consumed under thenode16andbundlersettings formoduleResolution.What's New
__esDecorateand related helpers by @ rbuckton in #193Full Changelog: 2.4.1...2.5.0
This release contains fixes for early
returns andthrows invoked on generators.Package name: @slack/oauth
-
2.6.3 - 2024-08-16
- oauth(build): use a minimum version of @ slack/web-api@6.12.1 - Thanks @ zimeg! #1889
-
2.6.2 - 2024-01-10
from @slack/oauth GitHub release notesWhat's Changed
This patch release bumps the minimum version of axios to 1.7.4 to address a CVE - see Axios 1.7.4 release notes for more information.
Changelog
Full Changelog: https://github.com/slackapi/node-slack-sdk/compare/@ slack/oauth@2.6.2...@ slack/oauth@2.6.3
Package name: @types/express
-
4.17.21 - 2023-11-07
-
4.17.20 - 2023-10-18
-
4.17.19 - 2023-10-10
-
4.17.18 - 2023-09-23
-
4.17.17 - 2023-02-03
-
4.17.16 - 2023-01-23
-
4.17.15 - 2022-12-13
-
4.17.14 - 2022-09-13
-
4.17.13 - 2021-07-06
from @types/express GitHub release notesPackage name: @slack/bolt
What's Changed
This patch release brings improvements to documentation and sureness in our CI, as well as security updates to certain
@ slackpackages - see CVE-2024-39338 andaxios@1.7.4for more details!Changes
📚 Documentation
🔒 Security
🧰 Maintenance
Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.21.0...@ slack/bolt@3.21.1
What's Changed
Bolt-JS now supports Custom Steps! That's right, your trusty Bolt app now let's you expose Custom Steps in Bolt, allowing you to provide steps for use in Workflow Builder.
You can now use the new
function()method to register handlers for thefunction_executedevent. Check out our API docs on the topic to get started.Changelog
New Contributors
Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.20.0...@ slack/bolt@3.21.0
What's Changed
@ slack/bolt@3.20.0by @ filmaj in #2195New Contributors
Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.19.0...@ slack/bolt@3.20.0
What's Changed
More customizations for the
AwsLambdaReceiverhave landed as well as a few touchups to typings and documented details!With this release, the signature verification for
AwsLambdaReceivercan now be turned off if that's something you're interested in! Perhaps you have your own stylish way of verifying these signatures. The following can be added to your receiver to unlock this:const app = new App({
...
receiver: new AwsLambdaReceiver({
signatureVerification: false,
}),
});
Read on and browse around for more details on all of the changes included!
🎁 Enhancements
AwsLambdaReceiverto enable/disable signature verification in #2107 - thanks @ noah-guillory!🐛 Fixes
CodedErrorin #2110 - thanks @ filmaj!📚 Documentation
🧰 Maintenance
📦 Dependencies