Skip to content

[Snyk] Upgrade mongoose from 6.9.0 to 6.11.1#18

Open
valentin-panov wants to merge 1 commit into
masterfrom
snyk-upgrade-440c513e3e59d73dbaf7d2c4191262d7
Open

[Snyk] Upgrade mongoose from 6.9.0 to 6.11.1#18
valentin-panov wants to merge 1 commit into
masterfrom
snyk-upgrade-440c513e3e59d73dbaf7d2c4191262d7

Conversation

@valentin-panov
Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade mongoose from 6.9.0 to 6.11.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 11 versions ahead of your current version.
  • The recommended version was released 23 days ago, on 2023-05-08.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-FASTXMLPARSER-3325616
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: mongoose
  • 6.11.1 - 2023-05-08

    chore: release 6.11.1

  • 6.11.0 - 2023-05-01

    chore: release 6.11.0

  • 6.10.5 - 2023-04-06
  • 6.10.4 - 2023-03-21
  • 6.10.3 - 2023-03-13
  • 6.10.2 - 2023-03-07
  • 6.10.1 - 2023-03-03
  • 6.10.0 - 2023-02-22
  • 6.9.3 - 2023-02-22
  • 6.9.2 - 2023-02-16
  • 6.9.1 - 2023-02-06
  • 6.9.0 - 2023-01-25
from mongoose GitHub release notes
Commit messages
Package name: mongoose
  • 7a90868 Merge branch '6.x' of github.com:Automattic/mongoose into 6.x
  • 23132db chore: release 6.11.1
  • d96de21 Merge pull request #13384 from Automattic/vkarpov15/gh-13373
  • 0ab335f docs: add note about SUPPRESS_JEST_WARNINGS to jest docs
  • eb28aaf fix: quick error message improvement
  • 9ea1a64 fix: add SUPPRESS_JEST_WARNINGS environment variable to silence jest warnings
  • 76e6456 Merge pull request #13292 from hasezoey/modifyBulkWriteType6
  • 2bbbb3c Merge pull request #13348 from Automattic/vkarpov15/gh-13340
  • 523f6ce Merge pull request #13365 from hasezoey/denoFixCycle6x
  • 48aed67 Revert "test: try removing mongodb memory server to try to fix deno tests"
  • 5f587f7 chore(deno): change to start mocha fixtures before mocha
  • 73ef135 chore: quick fix for versioned deploy
  • d382b73 chore: more docs build fixes
  • f0291e4 chore: improve 6.x docs build
  • 3578ffb docs: improve logic for publishing 6.x docs
  • 644d95e chore: release 6.11.0
  • f070cbb chore: bump bson to match mongodb@4.16 exactly
  • 9b21f69 Merge pull request #13349 from Automattic/vkarpov15/deno-test-fixes
  • 52aa86a test: remove unnecessary catch()
  • 6b0f963 test: try removing mongodb memory server to try to fix deno tests
  • 13352f8 test: avoid global teardown causing errors in deno
  • 6a67115 chore: bump deno tests to use v1.33
  • d0aecea Merge pull request #13337 from Automattic/vkarpov15/gh-13075
  • f2cf85a fix(query): apply schema-level paths before calculating projection for findOneAndUpdate()

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@vercel
Copy link
Copy Markdown

vercel Bot commented May 31, 2023

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
metrobooks ✅ Ready (Inspect) Visit Preview 💬 Add feedback May 31, 2023 7:10pm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants