Skip to content

Conversation

jsarafajr
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade jsforce from 1.11.1 to 3.1.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


Warning: This is a major version upgrade, and may be a breaking change.

  • The recommended version is 46 versions ahead of your current version.
  • The recommended version was released 22 days ago, on 2024-04-09.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
432/1000
Why? Proof of Concept exploit, CVSS 6.5
Proof of Concept
Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
432/1000
Why? Proof of Concept exploit, CVSS 6.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: jsforce
  • 3.1.0 - 2024-04-09
    No content.
  • 3.0.0-next.3 - 2024-03-28
    No content.
  • 3.0.0-next.2 - 2024-02-29
    No content.
  • 3.0.0-next.1 - 2023-12-01
    No content.
  • 2.0.0-beta.29 - 2023-11-27
    No content.
  • 2.0.0-beta.28 - 2023-10-09
    No content.
  • 2.0.0-beta.27 - 2023-06-24
    No content.
  • 2.0.0-beta.26 - 2023-06-24
    No content.
  • 2.0.0-beta.25 - 2023-06-22
    No content.
  • 2.0.0-beta.24 - 2023-06-05
  • 2.0.0-beta.23 - 2023-05-19
  • 2.0.0-beta.22 - 2023-05-12
  • 2.0.0-beta.21 - 2023-04-13
  • 2.0.0-beta.20 - 2023-02-15
  • 2.0.0-beta.19 - 2022-10-03
  • 2.0.0-beta.18 - 2022-08-08
  • 2.0.0-beta.17 - 2022-08-08
  • 2.0.0-beta.16 - 2022-07-21
  • 2.0.0-beta.15 - 2022-07-12
  • 2.0.0-beta.14 - 2022-06-23
  • 2.0.0-beta.13 - 2022-06-22
  • 2.0.0-beta.12 - 2022-06-22
  • 2.0.0-beta.11 - 2022-06-21
  • 2.0.0-beta.10 - 2022-05-19
  • 2.0.0-beta.9 - 2022-04-12
  • 2.0.0-beta.8 - 2021-07-23
  • 2.0.0-beta.7 - 2021-07-12
  • 2.0.0-beta.6 - 2021-06-19
  • 2.0.0-beta.5 - 2021-06-14
  • 2.0.0-beta.4 - 2021-06-11
  • 2.0.0-beta.3 - 2021-04-21
  • 2.0.0-beta.2 - 2021-01-01
  • 2.0.0-beta.1 - 2020-12-29
  • 2.0.0-alpha.13 - 2020-11-10
  • 2.0.0-alpha.12 - 2020-06-12
  • 2.0.0-alpha.11 - 2020-02-28
  • 2.0.0-alpha.10 - 2020-01-26
  • 2.0.0-alpha.9 - 2020-01-26
  • 2.0.0-alpha.8 - 2020-01-07
  • 2.0.0-alpha.7 - 2020-01-06
  • 2.0.0-alpha.6 - 2020-01-03
  • 2.0.0-alpha.5 - 2020-01-02
  • 2.0.0-alpha.4 - 2020-01-02
  • 2.0.0-alpha.3 - 2020-01-02
  • 2.0.0-alpha.2 - 2019-12-31
  • 2.0.0-alpha.1 - 2019-12-15
  • 1.11.1 - 2023-04-20
from jsforce GitHub release notes
Commit messages
Package name: jsforce
  • e5434cd chore(release): 3.1.0 [skip ci]
  • a4fd725 feat: remove deprecated jwt class (#1406)
  • 0face5d chore(release): 3.0.0-next.3 [skip ci]
  • 26f9e4d Merge pull request #1403 from jsforce/cd/network-retry
  • 4e2fef3 Merge pull request #1405 from jsforce/mdonnalley/network-retry
  • 084680f test: more tests
  • 7923f8e fix: do not retry if body stream was read
  • 7dd6580 fix: use logger
  • 113a060 test: add UT for network retry
  • 7039ad7 Revert "fix: don't send empty body stream in post reqs"
  • 30ab079 fix: don't send empty body stream in post reqs
  • 4fe209f feat: retry on network errors
  • 3a88038 chore(release): 3.0.0-next.2 [skip ci]
  • b8ae5d5 feat: bulk2 refactor (#1397)
  • e760c28 Merge pull request #1390 from jsforce/cd/http-module-tests
  • 3d9a399 test: fix flaky e2e tests (#1391)
  • 961c45f test(karma): ignore http-api tests
  • 2e524c8 fix: remove unused import
  • b46ea53 test: add UT for `noContentResponse
  • 60009cb chore: backport HTML err handling
  • ff469b5 test: skip http UTs in browser
  • 2a46462 test: add soap UT
  • 6c61466 test: squash
  • 442d045 Merge pull request #1381 from jsforce/cd/add-http-content-length-header

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants