Conversation
Snyk has created this PR to upgrade:
- debug from 2.2.0 to 2.6.9.
See this package in npm: https://www.npmjs.com/package/debug
- body-parser from 1.13.3 to 1.20.2.
See this package in npm: https://www.npmjs.com/package/body-parser
- cookie-parser from 1.3.5 to 1.4.6.
See this package in npm: https://www.npmjs.com/package/cookie-parser
- ejs from 0.3.0 to 0.8.8.
See this package in npm: https://www.npmjs.com/package/ejs
- log4js from 0.1.0 to 0.6.38.
See this package in npm: https://www.npmjs.com/package/log4js
- morgan from 1.6.1 to 1.10.0.
See this package in npm: https://www.npmjs.com/package/morgan
- serve-favicon from 2.3.2 to 2.5.0.
See this package in npm: https://www.npmjs.com/package/serve-favicon
See this project in Snyk:
https://app.snyk.io/org/opsgenie/project/3355716a-cef1-42fb-9138-103dd26b3ea8?utm_source=github&utm_medium=referral&page=upgrade-pr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
debug
from 2.2.0 to 2.6.9 | 23 versions ahead of your current version | 7 years ago
on 2017-09-22
body-parser
from 1.13.3 to 1.20.2 | 21 versions ahead of your current version | 2 years ago
on 2023-02-22
cookie-parser
from 1.3.5 to 1.4.6 | 7 versions ahead of your current version | 3 years ago
on 2021-11-16
ejs
from 0.3.0 to 0.8.8 | 19 versions ahead of your current version | 10 years ago
on 2014-03-24
log4js
from 0.1.0 to 0.6.38 | 68 versions ahead of your current version | 8 years ago
on 2016-07-17
morgan
from 1.6.1 to 1.10.0 | 7 versions ahead of your current version | 4 years ago
on 2020-03-20
serve-favicon
from 2.3.2 to 2.5.0 | 7 versions ahead of your current version | 6 years ago
on 2018-03-29
Issues fixed by the recommended upgrade:
SNYK-JS-QS-3153490
npm:qs:20170213
npm:fresh:20170908
SNYK-JS-MORGAN-72579
npm:debug:20170905
npm:ms:20170412
npm:ms:20170412
Release notes
Package name: debug
-
2.6.9 - 2017-09-22
-
2.6.8 - 2017-05-18
-
2.6.7 - 2017-05-17
-
2.6.6 - 2017-04-27
-
2.6.5 - 2017-04-27
-
2.6.4 - 2017-04-20
-
2.6.3 - 2017-03-14
-
2.6.2 - 2017-03-10
-
2.6.1 - 2017-02-10
-
2.6.0 - 2016-12-29
-
2.5.2 - 2016-12-26
-
2.5.1 - 2016-12-21
-
2.5.0 - 2016-12-21
-
2.4.5 - 2016-12-18
-
2.4.4 - 2016-12-15
-
2.4.3 - 2016-12-14
-
2.4.2 - 2016-12-14
-
2.4.1 - 2016-12-14
-
2.4.0 - 2016-12-14
-
2.3.3 - 2016-11-19
-
2.3.2 - 2016-11-10
-
2.3.1 - 2016-11-10
-
2.3.0 - 2016-11-07
-
2.2.0 - 2015-05-10
from debug GitHub release notesPackage name: body-parser
-
1.20.2 - 2023-02-22
- Fix strict json error message on Node.js 19+
- deps: content-type@~1.0.5
- perf: skip value escaping when unnecessary
- deps: raw-body@2.5.2
-
1.20.1 - 2022-10-06
- deps: qs@6.11.0
- perf: remove unnecessary object clone
-
1.20.0 - 2022-04-03
- Fix error message for json parse whitespace in
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: depd@2.0.0
- Replace internal
- Use instance methods on
- deps: http-errors@2.0.0
- deps: depd@2.0.0
- deps: statuses@2.0.1
- deps: on-finished@2.4.1
- deps: qs@6.10.3
- deps: raw-body@2.5.1
- deps: http-errors@2.0.0
-
1.19.2 - 2022-02-16
- deps: bytes@3.1.2
- deps: qs@6.9.7
- Fix handling of
- deps: raw-body@2.4.3
- deps: bytes@3.1.2
-
1.19.1 - 2021-12-10
- deps: bytes@3.1.1
- deps: http-errors@1.8.1
- deps: inherits@2.0.4
- deps: toidentifier@1.0.1
- deps: setprototypeof@1.2.0
- deps: qs@6.9.6
- deps: raw-body@2.4.2
- deps: bytes@3.1.1
- deps: http-errors@1.8.1
- deps: safe-buffer@5.2.1
- deps: type-is@~1.6.18
-
1.19.0 - 2019-04-26
- deps: bytes@3.1.0
- Add petabyte (
- deps: http-errors@1.7.2
- Set constructor name when possible
- deps: setprototypeof@1.1.1
- deps: statuses@'>= 1.5.0 < 2'
- deps: iconv-lite@0.4.24
- Added encoding MIK
- deps: qs@6.7.0
- Fix parsing array brackets after index
- deps: raw-body@2.4.0
- deps: bytes@3.1.0
- deps: http-errors@1.7.2
- deps: iconv-lite@0.4.24
- deps: type-is@~1.6.17
- deps: mime-types@~2.1.24
- perf: prevent internal
-
1.18.3 - 2018-05-14
- Fix stack trace for strict json parse error
- deps: depd@~1.1.2
- perf: remove argument reassignment
- deps: http-errors@~1.6.3
- deps: depd@~1.1.2
- deps: setprototypeof@1.1.0
- deps: statuses@'>= 1.3.1 < 2'
- deps: iconv-lite@0.4.23
- Fix loading encoding with year appended
- Fix deprecation warnings on Node.js 10+
- deps: qs@6.5.2
- deps: raw-body@2.3.3
- deps: http-errors@1.6.3
- deps: iconv-lite@0.4.23
- deps: type-is@~1.6.16
- deps: mime-types@~2.1.18
-
1.18.2 - 2017-09-22
- deps: debug@2.6.9
- perf: remove argument reassignment
-
1.18.1 - 2017-09-12
- deps: content-type@~1.0.4
- perf: remove argument reassignment
- perf: skip parameter parsing when no parameters
- deps: iconv-lite@0.4.19
- Fix ISO-8859-1 regression
- Update Windows-1255
- deps: qs@6.5.1
- Fix parsing & compacting very deep objects
- deps: raw-body@2.3.2
- deps: iconv-lite@0.4.19
-
1.18.0 - 2017-09-09
-
1.17.2 - 2017-05-18
-
1.17.1 - 2017-03-06
-
1.17.0 - 2017-03-01
-
1.16.1 - 2017-02-11
-
1.16.0 - 2017-01-18
-
1.15.2 - 2016-06-20
-
1.15.1 - 2016-05-06
-
1.15.0 - 2016-02-11
-
1.14.2 - 2015-12-16
-
1.14.1 - 2015-09-28
-
1.14.0 - 2015-09-16
-
1.13.3 - 2015-07-31
from body-parser GitHub release notesstrictevalusage withFunctionconstructorprocessto check for listeners__proto__keyspb) supportthrowon invalid typePackage name: cookie-parser
-
1.4.6 - 2021-11-16
- deps: cookie@0.4.1
-
1.4.5 - 2020-03-15
- deps: cookie@0.4.0
-
1.4.4 - 2019-02-13
- perf: normalize
-
1.4.3 - 2016-05-27
- deps: cookie@0.3.1
- perf: use for loop in parse
-
1.4.2 - 2016-05-21
- deps: cookie@0.2.4
- perf: enable strict mode
- perf: use for loop in parse
- perf: use string concatination for serialization
-
1.4.1 - 2016-01-11
- deps: cookie@0.2.3
- perf: enable strict mode
-
1.4.0 - 2015-09-18
-
1.3.5 - 2015-05-20
- deps: cookie@0.1.3
- Slight optimizations
from cookie-parser GitHub release notessecretargument only once1.4.0
Package name: ejs
-
0.8.8 - 2014-03-24
-
0.8.6 - 2014-03-21
-
0.8.5 - 2013-11-22
-
0.8.4 - 2013-05-08
-
0.8.3 - 2012-09-13
-
0.8.2 - 2012-08-16
-
0.8.1 - 2012-08-11
-
0.8.0 - 2012-07-25
-
0.7.2 - 2012-06-22
-
0.7.1 - 2012-03-26
-
0.7.0 - 2012-03-25
-
0.6.1 - 2011-12-10
-
0.6.0 - 2011-12-09
-
0.5.0 - 2011-11-20
-
0.4.3 - 2011-06-20
-
0.4.2 - 2011-05-11
-
0.4.1 - 2011-04-21
-
0.4.0 - 2011-04-21
-
0.3.1 - 2011-02-24
-
0.3.0 - 2011-02-14
from ejs GitHub release notesPackage name: log4js
-
0.6.38 - 2016-07-17
-
0.6.37 - 2016-06-14
-
0.6.36 - 2016-05-05
-
0.6.35 - 2016-04-14
-
0.6.34 - 2016-04-14
-
0.6.33 - 2016-03-08
-
0.6.32 - 2016-02-28
-
0.6.31 - 2016-02-01
-
0.6.30 - 2016-01-26
-
0.6.29 - 2015-11-26
-
0.6.28 - 2015-11-18
-
0.6.27 - 2015-09-21
-
0.6.26 - 2015-06-10
-
0.6.25 - 2015-05-12
-
0.6.24 - 2015-04-17
-
0.6.23 - 2015-04-16
-
0.6.22 - 2015-01-10
-
0.6.21 - 2014-09-10
-
0.6.20 - 2014-08-25
-
0.6.19 - 2014-08-21
-
0.6.18 - 2014-08-19
-
0.6.17 - 2014-08-15
-
0.6.16 - 2014-07-18
-
0.6.15 - 2014-07-02
-
0.6.14 - 2014-04-22
-
0.6.13 - 2014-04-08
-
0.6.12 - 2014-03-05
-
0.6.11 - 2014-03-04
-
0.6.10 - 2014-02-10
-
0.6.9 - 2013-09-29
-
0.6.8 - 2013-08-22
-
0.6.7 - 2013-08-02
-
0.6.6 - 2013-05-25
-
0.6.5 - 2013-05-16
-
0.6.4 - 2013-05-05
-
0.6.3 - 2013-04-11
-
0.6.2 - 2013-04-02
-
0.6.1 - 2013-04-01
-
0.6.0 - 2013-03-20
-
0.5.8 - 2013-04-01
-
0.5.7 - 2013-02-25
-
0.5.6 - 2012-12-02
-
0.5.5 - 2012-11-09
-
0.5.4 - 2012-10-16
-
0.5.3 - 2012-09-25
-
0.5.2 - 2012-08-14
-
0.5.1 - 2012-07-03
-
0.5.0 - 2012-06-01
-
0.4.3 - 2012-03-21
-
0.4.2 - 2012-03-06
-
0.4.1 - 2011-11-23
-
0.4.0 - 2011-11-21
-
0.3.9 - 2011-09-14
-
0.3.8 - 2011-08-11
-
0.3.7 - 2011-07-27
-
0.3.6 - 2011-07-27
-
0.3.5 - 2011-07-25
-
0.3.4 - 2011-07-21
-
0.3.3 - 2011-07-21
-
0.3.2 - 2011-07-20
-
0.3.1 - 2011-07-18
-
0.3.0 - 2011-07-17
-
0.2.6 - 2011-06-05
-
0.2.5 - 2011-04-17
-
0.2.4 - 2011-03-04
-
0.2.3 - 2011-01-16
-
0.2.2 - 2011-01-16
-
0.2.0 - 2011-01-16
-
0.1.0 - 2011-01-16
from log4js GitHub release notesPackage name: morgan
-
1.10.0 - 2020-03-20
- Add
- Fix trailing space in colored status code for
- deps: basic-auth@~2.0.1
- deps: safe-buffer@5.1.2
- deps: depd@~2.0.0
- Replace internal
- Use instance methods on
- deps: on-headers@~1.0.2
- Fix
-
1.9.1 - 2018-09-11
- Fix using special characters in format
- deps: depd@~1.1.2
- perf: remove argument reassignment
-
1.9.0 - 2017-09-27
- Use
- deps: basic-auth@~2.0.0
- Use
- deps: debug@2.6.9
- deps: depd@~1.1.1
- Remove unnecessary
-
1.8.2 - 2017-05-24
- deps: debug@2.6.8
- Fix
- deps: ms@2.0.0
-
1.8.1 - 2017-02-11
- deps: debug@2.6.1
- Fix deprecation messages in WebStorm and other editors
- Undeprecate
-
1.8.0 - 2017-02-05
- Fix sending unnecessary
- deps: basic-auth@~1.1.0
- deps: debug@2.6.0
- Allow colors in workers
- Deprecated
- Fix error when running under React Native
- Use same color for same namespace
- deps: ms@0.7.2
- perf: enable strict mode in compiled functions
-
1.7.0 - 2016-02-19
- Add
- deps: depd@~1.1.0
- Enable strict mode in more places
- Support web browser loading
- deps: on-headers@~1.0.1
- perf: enable strict mode
-
1.6.1 - 2015-07-04
- deps: basic-auth@~1.0.3
from morgan GitHub release notes:total-timetokendevformatevalusage withFunctionconstructorprocessto check for listenersres.writeHeadpatch missing return valueres.headersSentwhen availablesafe-bufferfor improved Buffer APIBufferloadingDEBUG_MAX_ARRAY_LENGTHDEBUG_FDset to1or2undefinedargument to token functionsDEBUG_FDenvironment variabledigitsargument toresponse-timetokenPackage name: serve-favicon
-
2.5.0 - 2018-03-29
- Ignore requests without
- deps: ms@2.1.1
- Add
- Add
-
2.4.5 - 2017-09-26
- deps: etag@~1.8.1
- perf: replace regular expression with substring
- deps: fresh@0.5.2
- Fix regression matching multiple ETags in
- perf: improve
-
2.4.4 - 2017-09-12
- deps: fresh@0.5.1
- Fix handling of modified headers with invalid dates
- perf: improve ETag match loop
- deps: parseurl@~1.3.2
- perf: reduce overhead for full URLs
- perf: unroll the "fast-path"
- deps: safe-buffer@5.1.1
-
2.4.3 - 2017-05-16
- Use
- deps: ms@2.0.0
-
2.4.2 - 2017-03-25
- deps: ms@1.0.0
-
2.4.1 - 2017-02-28
- Remove usage of
- deps: fresh@0.5.0
- Fix incorrect result when
- Fix weak
- perf: skip checking modified time if ETag check failed
- perf: skip parsing
- perf: use
-
2.4.0 - 2017-02-20
- deps: etag@~1.8.0
- Use SHA1 instead of MD5 for ETag hashing
- Works with FIPS 140-2 OpenSSL configuration
- deps: fresh@0.4.0
- Fix false detection of
- perf: enable strict mode
- perf: hoist regular expressions
- perf: remove duplicate conditional
- perf: remove unnecessary boolean coercions
- perf: simplify initial argument checking
-
2.3.2 - 2016-11-17
- deps: ms@0.7.2
from serve-favicon GitHub release notesurlpropertyweekwIf-None-MatchIf-None-Matchtoken parsingRegExpsafe-bufferfor improved Buffer APIres._headersprivate fieldIf-None-Matchhas both*and ETagsETagmatching to match specIf-None-Matchwhen noETagheaderDate.parseinstead ofnew Dateno-cacherequest directiveImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: