Skip to content

[Snyk] Security upgrade epsagon from 1.7.13 to 1.103.1#6

Open
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-c6a745c63f9b403dacc4d7994b0d11b0
Open

[Snyk] Security upgrade epsagon from 1.7.13 to 1.103.1#6
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-c6a745c63f9b403dacc4d7994b0d11b0

Conversation

@snyk-bot
Copy link
Copy Markdown

@snyk-bot snyk-bot commented Jan 7, 2021

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 616/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Server-Side Request Forgery (SSRF)
SNYK-JS-AXIOS-1038255
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: epsagon The new version differs by 250 commits.
  • d06db15 fix(lambda.js): catch unhandled promise rejections (#403)
  • a9661c2 build(deps): bump axios from 0.19.0 to 0.21.1 (#402)
  • ebb3607 feat(cassandra.js): add support for cassandra-driver (#400)
  • 8056c18 fix(index.d.ts): update missing param ignoredKeys (#401)
  • fe5dd5f build(deps): bump ini from 1.3.5 to 1.3.7 (#399)
  • acfb9ee Update README.md (#398)
  • b059899 fix(aws_sdk): add eventbridge support (#397)
  • 3acacd2 fix(google_cloud.js): fix job id extraction (#396)
  • debb13e feat(tracer): export add to pending event function (#394)
  • 280ff5f feat(config.js): add option to remove ignored keys (#393)
  • 97a5b06 fix(batch-processing): post fix (#390)
  • ec434b6 feat(batch processing): traces queue + batch sending + byte size limit (#373)
  • c961ac9 feat(ec2): capture ec2 metadata (#389)
  • bc9ac7f feat(fs): add node fs support (#387)
  • e7d9a2a feat(aws_sdk.js): support filter log events (#388)
  • f859787 feat(sql): collecting response data (#385)
  • e69e6f6 fix(readme): add screenshot to readme (#386)
  • 823c08f fix(index.d.ts): add type declaration for `setWarning` (#384)
  • 1e5bfc3 feat(setwarning): add setWarning method (#383)
  • acf549a feat(sqs): supporting multiple sqs messages for lambda trigger (#380)
  • 33b385a feat(tracer): trimming exceptions when tracer is more than max size (#379)
  • aabd54c fix(const): add lambda main consts to strong id array (#381)
  • a0c6c2d feat(http): saving response/request body even if not json (#378)
  • e9789d0 feat(skip simple auth): skip simple auth requests (#377)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant