Skip to content

Update dependency typeorm to ^0.3.0 [SECURITY]#68

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-typeorm-vulnerability
Open

Update dependency typeorm to ^0.3.0 [SECURITY]#68
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-typeorm-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate bot commented May 9, 2021

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
typeorm (source) ^0.2.13^0.3.0 age confidence

GitHub Vulnerability Alerts

CVE-2020-8158

Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.

CVE-2022-33171

The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validation.


Release Notes

typeorm/typeorm (typeorm)

v0.3.0

Compare Source

Bug Fixes
Features
Reverts

v0.2.45

Compare Source

Bug Fixes
Features

v0.2.44

Compare Source

Bug Fixes
Features

v0.2.43

Compare Source

Bug Fixes
  • support require to internal files without explicitly writing .js in the path (#​8660) (96aed8a), closes #​8656
Features
Reverts

v0.2.42

Compare Source

Bug Fixes
Features
Reverts
BREAKING CHANGES
  • update listeners and subscriber no longer triggered by soft-remove and recover

v0.2.41

Compare Source

Bug Fixes
Features

v0.2.40

Compare Source

Bug Fixes
  • BaseEntity finder methods to properly type-check lazy relations conditions (#​5710) (0665ff5)
Features
  • add depth limiter optional parameter when loading nested trees using TreeRepository's findTrees() and findDescendantsTree() (#​7926) (0c44629), closes #​3909
  • add upsert methods for the drivers that support onUpdate (#​8104) (3f98197), closes #​2363
  • Postgres IDENTITY Column support (#​7741) (969af95)
Reverts

v0.2.39

Compare Source

Bug Fixes
Features
Reverts

v0.2.38

Compare Source

Bug Fixes
Features

v0.2.37

Compare Source

Bug Fixes
Features

v0.2.36

Compare Source

Bug Fixes
  • add deprecated WhereExpression alias for WhereExpressionBuilder (#​7980) (76e7ed9)
  • always generate migrations with template string literals (#​7971) (e9c2af6)
  • use js rather than ts in all browser package manifests (#​7982) (0d90bcd)
  • use nvarchar/ntext during transit for SQLServer queries (#​7933) (62d7976)
Features

v0.2.35

Compare Source

Bug Fixes
Features

v0.2.34

Compare Source

Bug Fixes
  • restored buildColumnAlias for backward compatibility (#​7706) (36ceefa)

v0.2.33

Compare Source

Bug Fixes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 3548749 to ce10721 Compare March 7, 2022 13:45
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from ce10721 to 5cc039e Compare March 26, 2022 13:54
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 5cc039e to aec9f39 Compare April 24, 2022 19:50
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from aec9f39 to 0dcc48e Compare May 16, 2022 01:38
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 0dcc48e to 48e3c54 Compare June 18, 2022 19:18
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 48e3c54 to 862ef4d Compare September 25, 2022 16:28
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 862ef4d to 4068721 Compare November 20, 2022 17:32
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 4068721 to ca10785 Compare March 16, 2023 13:59
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from ca10785 to 4907541 Compare May 28, 2023 09:38
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 4907541 to 7e14c0e Compare June 4, 2023 11:54
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 7e14c0e to 0123abb Compare June 29, 2023 07:36
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 0123abb to f98e4f4 Compare July 27, 2023 19:07
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from f98e4f4 to a744b88 Compare August 22, 2023 15:50
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from a744b88 to acf89aa Compare October 1, 2023 11:13
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from acf89aa to f8141b4 Compare January 25, 2024 03:24
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from f8141b4 to 6c8208e Compare February 25, 2024 10:43
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 6c8208e to 3ec54b5 Compare March 21, 2024 23:32
@renovate renovate bot changed the title Update dependency typeorm to v0.2.25 [SECURITY] Update dependency typeorm to ^0.3.0 [SECURITY] Mar 21, 2024
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 3ec54b5 to 0e2c461 Compare August 10, 2025 12:42
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 0e2c461 to 05d64b6 Compare August 19, 2025 17:36
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 05d64b6 to 4d17d8e Compare August 31, 2025 10:33
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 4d17d8e to f0e105d Compare September 25, 2025 13:48
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from f0e105d to d0a59bf Compare November 10, 2025 19:44
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from d0a59bf to 4196679 Compare November 18, 2025 19:50
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 4196679 to 106ed89 Compare December 3, 2025 20:06
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 106ed89 to d9a7704 Compare December 31, 2025 16:05
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from d9a7704 to 47ab317 Compare January 19, 2026 20:03
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 47ab317 to 6ecda1b Compare March 5, 2026 20:04
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 6ecda1b to 8aa7e9c Compare March 13, 2026 18:14
@renovate renovate bot changed the title Update dependency typeorm to ^0.3.0 [SECURITY] Update dependency typeorm to ^0.3.0 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate bot closed this Mar 27, 2026
@renovate renovate bot deleted the renovate/npm-typeorm-vulnerability branch March 27, 2026 01:27
@renovate renovate bot changed the title Update dependency typeorm to ^0.3.0 [SECURITY] - autoclosed Update dependency typeorm to ^0.3.0 [SECURITY] Mar 30, 2026
@renovate renovate bot reopened this Mar 30, 2026
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch 2 times, most recently from 8aa7e9c to ddbd29c Compare March 30, 2026 20:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants