chore(deps): bump lodash and express - #1
Conversation
🔍 lockvet report40 packages changed: 3 major Vulnerabilities: 0 introduced, 3 fixed, 11 unresolved (via OSV.dev)
|
| Package | From | To | Level | Age | |
|---|---|---|---|---|---|
| 🔼 | matteo-sung/lockvet direct |
v0.5.20 | v0.6.4 | minor |
📝 matteo-sung/lockvet release notes (1 release)
pdm.lock support — format #61
PDM's lockfile completes lockvet's Python lineup: uv, poetry, pipenv,
requirements.txt, PEP 751pylock.toml— and now PDM.Every locked package gets the full PyPI treatment: OSV advisories with
the exactfixed inrelease, publish ages, registry-verified unlisted
checks, typosquat screening, and via-chains read from the lockfile's own
PEP 508dependenciesarrays:pdm.lock (PyPI) …
package-lock.json — 39 changes
| Package | From | To | Level | Age | |
|---|---|---|---|---|---|
| 🔼 | depd via express |
1.1.2 | 2.0.0 | MAJOR | 7y |
| 🔼 | http-errors via express |
1.7.2 | 2.0.0 | MAJOR | 4y |
| 🔼 | statuses via express |
1.5.0 | 2.0.1 | MAJOR | 5y |
| 🔼 | body-parser via express |
1.19.0 | 1.20.1 | minor | 3y |
| 🟡 | ↳ 2 known advisories affect both versions | worst: high, GHSA-qwcr-r2fm-qrc7 — all fixed in ≥ 1.20.6 | |||
| 🔼 | cookie via express |
0.4.0 | 0.5.0 | minor | 4y |
| 🟡 | ↳ 1 known advisory affects both versions | worst: low, GHSA-pxg6-pf52-xh8x — all fixed in ≥ 0.7.0 | |||
| 🔼 | destroy via express › body-parser |
1.0.4 | 1.2.0 | minor | 4y |
| 🔼 | express direct |
4.17.1 | 4.18.2 | minor | 3y |
| 🟡 | ↳ 2 known advisories affect both versions | worst: moderate, GHSA-rv95-896h-c2vc — all fixed in ≥ 4.20.0 | |||
| 🔼 | finalhandler via express |
1.1.2 | 1.2.0 | minor | 4y |
| 🔼 | on-finished via express |
2.3.0 | 2.4.1 | minor | 4y |
| 🔼 | qs via express |
6.7.0 | 6.11.0 | minor | 4y |
| ✅ | ↳ fixes GHSA-hrpp-h998-j3pp (high) | qs vulnerable to Prototype Pollution | |||
| 🟡 | ↳ 2 known advisories affect both versions | worst: moderate, GHSA-6rw7-vpxm-498p — all fixed in ≥ 6.14.2 | |||
| 🔼 | raw-body via express › body-parser |
2.4.0 | 2.5.1 | minor | 4y |
| 🔼 | safe-buffer via express |
5.1.2 | 5.2.1 | minor | 6y |
| 🔼 | send via express |
0.17.1 | 0.18.0 | minor | 4y |
| 🟡 | ↳ 1 known advisory affects both versions | worst: low, GHSA-m6fv-jmcg-4jfg — all fixed in ≥ 0.19.0 | |||
| 🔼 | serve-static via express |
1.14.1 | 1.15.0 | minor | 4y |
| 🟡 | ↳ 1 known advisory affects both versions | worst: low, GHSA-cm22-4g7w-348p — all fixed in ≥ 1.16.0 | |||
| 🔼 | setprototypeof via express |
1.1.1 | 1.2.0 | minor | 7y |
| 🔼 | bytes via express › body-parser |
3.1.0 | 3.1.2 | patch | 4y |
| 🔼 | content-disposition via express |
0.5.3 | 0.5.4 | patch | 4y |
| 🔼 | inherits via express › http-errors |
2.0.3 | 2.0.4 | patch | 7y |
| 🔼 | lodash direct |
4.17.19 | 4.17.21 | patch | 5y |
| ✅ | ↳ fixes GHSA-35jh-r3h4-6jhm (high) | Command Injection in lodash | |||
| ✅ | ↳ fixes GHSA-29mw-wpgm-hmr9 (moderate) | Regular Expression Denial of Service (ReDoS) in lodash | |||
| 🟡 | ↳ 2 known advisories affect both versions | worst: high, GHSA-r5fr-rjxr-66jc — all fixed in ≥ 4.18.0 | |||
| 🔼 | toidentifier via express › http-errors |
1.0.0 | 1.0.1 | patch | 4y |
| 🔼 | ms via express › debug |
2.0.0, 2.1.1 | 2.0.0, 2.1.3 | patch | 5y |
| ➕ | call-bind-apply-helpers via express › qs › side-channel › side-channel-map › call-bound |
1.0.2 | added | 18mo | |
| ➕ | call-bound via express › qs › side-channel › side-channel-map |
1.0.4 | added | 17mo | |
| ➕ | dunder-proto via express › qs › side-channel › side-channel-map › get-intrinsic › get-proto |
1.0.1 | added | 20mo | |
| ➕ | es-define-property via express › qs › side-channel › side-channel-map › get-intrinsic |
1.0.1 | added | 20mo | |
| ➕ | es-errors via express › qs › side-channel |
1.3.0 | added | 2y | |
| ➕ | es-object-atoms via express › qs › side-channel › side-channel-map › get-intrinsic |
1.1.2 | added | 2mo | |
| ➕ | function-bind via express › qs › side-channel › side-channel-map › get-intrinsic |
1.1.2 | added | 2y | |
| ➕ | get-intrinsic via express › qs › side-channel › side-channel-map |
1.3.0 | added | 17mo | |
| ➕ | get-proto via express › qs › side-channel › side-channel-map › get-intrinsic |
1.0.1 | added | 19mo | |
| ➕ | gopd via express › qs › side-channel › side-channel-map › get-intrinsic |
1.2.0 | added | 20mo | |
| ➕ | has-symbols via express › qs › side-channel › side-channel-map › get-intrinsic |
1.1.0 | added | 20mo | |
| ➕ | hasown via express › qs › side-channel › side-channel-map › get-intrinsic |
2.0.4 | added | 2mo | |
| ➕ | math-intrinsics via express › qs › side-channel › side-channel-map › get-intrinsic |
1.1.0 | added | 19mo | |
| ➕ | object-inspect via express › qs › side-channel |
1.13.4 | added | 18mo | |
| ➕ | side-channel via express › qs |
1.1.1 | added | 2mo | |
| ➕ | side-channel-list via express › qs › side-channel |
1.0.1 | added | 4mo | |
| ➕ | side-channel-map via express › qs › side-channel |
1.0.1 | added | 20mo | |
| ➕ | side-channel-weakmap via express › qs › side-channel |
1.0.2 | added | 20mo |
📝 depd release notes (1 release)
- Drop support for Node.js 0.6
- Replace internal
evalusage withFunctionconstructor- Use instance methods on
processto check for listeners
📝 http-errors release notes (1 release)
- Drop support for Node.js 0.6
- Remove
I'mateapotexport; useImATeapotinstead- Remove support for status being non-first argument
- Rename
UnorderedCollectionconstructor toTooEarly- deps: depd@2.0.0
- Replace internal
evalusage withFunctionconstructor- Use instance methods on
processto check for listeners- deps: statuses@2.0.1
- Fix messaging casing of
418 I'm a Teapot- Remove code 306
- Rename
425 Unordered Collectionto standard425 Too Early…
📝 statuses release notes (2 releases)
- Fix returning values from
Object.prototype
- Drop support for Node.js 0.6
- Fix messaging casing of
418 I'm a Teapot- Remove code 306
- Remove
status[code]exports; usestatus.message[code]- Remove
status[msg]exports; usestatus.code[msg]- Rename
425 Unordered Collectionto standard425 Too Early- Rename
STATUS_CODESexport tomessage- Return status message for
statuses(code)when given code
📝 body-parser release notes (4 releases)
- deps: qs@6.11.0
- perf: remove unnecessary object clone
- Fix error message for json parse whitespace in
strict- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: depd@2.0.0
- Replace internal
evalusage withFunctionconstructor- Use instance methods on
processto check for listeners- deps: http-errors@2.0.0
- deps: depd@2.0.0
- deps: statuses@2.0.1
- deps: on-finished@2.4.1
- deps: qs@6.10.3
…
- deps: bytes@3.1.2
- deps: qs@6.9.7
- Fix handling of
__proto__keys- deps: raw-body@2.4.3
- deps: bytes@3.1.2
- deps: bytes@3.1.1
- deps: http-errors@1.8.1
- deps: inherits@2.0.4
- deps: toidentifier@1.0.1
- deps: setprototypeof@1.2.0
- deps: qs@6.9.6
- deps: raw-body@2.4.2
- deps: bytes@3.1.1
- deps: http-errors@1.8.1
- deps: safe-buffer@5.2.1
- deps: type-is@~1.6.18
📝 cookie release notes (3 releases)
- Add
priorityoption- Fix
expiresoption to reject invalid dates- pref: improve default decode speed
- pref: remove slow string split in parse
- pref: read value only when assigning in parse
- pref: remove unnecessary regexp in parse
- Fix
maxAgeoption to reject invalid values
📝 destroy release notes (3 releases)
- Add
suppressargument
- Work around Zlib close bug in Node.js < 4.5.5
- Add Zlib steam support and Node.js leak work around
📝 express release notes (5 releases)
- Fix regression routing a large stack in a single route
- deps: body-parser@1.20.1
- deps: qs@6.11.0
- perf: remove unnecessary object clone
- deps: qs@6.11.0
- Fix hanging on large stack of sync routes
- Add "root" option to
res.download- Allow
optionswithoutfilenameinres.download- Deprecate string and non-integer arguments to
res.status- Fix behavior of
null/undefinedasmaxAgeinres.cookie- Fix handling very large stacks of sync middleware
- Ignore
Object.prototypevalues in settings throughapp.set/app.get- Invoke
defaultwith same arguments as types inres.format- Support proper 205 responses using
res.send- Use
http-errorsforres.formaterror- deps: body-parser@1.20.0
- Fix error message for json parse whitespace in
strict- Fix internal error when inflated body exceeds limit
…
- deps: accepts@~1.3.8
- deps: mime-types@~2.1.34
- deps: negotiator@0.6.3
- deps: body-parser@1.19.2
- deps: bytes@3.1.2
- deps: qs@6.9.7
- deps: raw-body@2.4.3
- deps: cookie@0.4.2
- deps: qs@6.9.7
- Fix handling of
__proto__keys- pref: remove unnecessary regexp for trust proxy
- Fix handling of
undefinedinres.jsonp- Fix handling of
undefinedwhen"json escape"is enabled- Fix incorrect middleware execution with unanchored
RegExps- Fix
res.jsonp(obj, status)deprecation message- Fix typo in
res.isJSDoc- deps: body-parser@1.19.1
- deps: bytes@3.1.1
- deps: http-errors@1.8.1
- deps: qs@6.9.6
- deps: raw-body@2.4.2
- deps: safe-buffer@5.2.1
- deps: type-is@~1.6.18
…
📝 finalhandler release notes (1 release)
- Remove set content headers that break response
- deps: on-finished@2.4.1
- deps: statuses@2.0.1
- Rename
425 Unordered Collectionto standard425 Too Early
📝 on-finished release notes (2 releases)
- Fix error on early async hooks implementations
- Prevent loss of async hooks context
📝 raw-body release notes (5 releases)
- Fix error on early async hooks implementations
- Prevent loss of async hooks context
- Prevent hanging when stream is not readable
- deps: http-errors@2.0.0
- deps: depd@2.0.0
- deps: statuses@2.0.1
- deps: bytes@3.1.2
- deps: bytes@3.1.1
- deps: http-errors@1.8.1
- deps: setprototypeof@1.2.0
- deps: toidentifier@1.0.1
- deps: http-errors@1.7.3
- deps: inherits@2.0.4
📝 send release notes (2 releases)
- Fix emitted 416 error missing headers property
- Limit the headers removed for 304 response
- deps: depd@2.0.0
- Replace internal
evalusage withFunctionconstructor- Use instance methods on
processto check for listeners- deps: destroy@1.2.0
- deps: http-errors@2.0.0
- deps: depd@2.0.0
- deps: statuses@2.0.1
- deps: on-finished@2.4.1
- deps: statuses@2.0.1
- pref: ignore empty http tokens
- deps: http-errors@1.8.1
- deps: inherits@2.0.4
- deps: toidentifier@1.0.1
- deps: setprototypeof@1.2.0
- deps: ms@2.1.3
📝 serve-static release notes (2 releases)
- deps: send@0.18.0
- Fix emitted 416 error missing headers property
- Limit the headers removed for 304 response
- deps: depd@2.0.0
- deps: destroy@1.2.0
- deps: http-errors@2.0.0
- deps: on-finished@2.4.1
- deps: statuses@2.0.1
- deps: send@0.17.2
- deps: http-errors@1.8.1
- deps: ms@2.1.3
- pref: ignore empty http tokens
📝 call-bind-apply-helpers release notes (1 release)
v1.0.2 — https://github.com/ljharb/call-bind-apply-helpers/compare/v1.0.1...v1.0.2) - 2025-02-12
Commits
📝 call-bound release notes (1 release)
v1.0.4 — https://github.com/ljharb/call-bound/compare/v1.0.3...v1.0.4) - 2025-03-03
Commits
📝 dunder-proto release notes (1 release)
v1.0.1 — https://github.com/es-shims/dunder-proto/compare/v1.0.0...v1.0.1) - 2024-12-16
Commits
📝 es-define-property release notes (1 release)
v1.0.1 — https://github.com/ljharb/es-define-property/compare/v1.0.0...v1.0.1) - 2024-12-06
Commits
- [types] use shared tsconfig
954a663- [actions] split out node 10-20, and 20+
3a8e84b- [Dev Deps] update
@ljharb/eslint-config,@ljharb/tsconfig,@types/get-intrinsic,@types/tape,auto-changelog,gopd,tape86ae27b- [Refactor] avoid using
get-intrinsic02480c0- [Tests] replace
audwithnpm auditf6093ff
…
📝 es-errors release notes (1 release)
v1.3.0 — https://github.com/ljharb/es-errors/compare/v1.2.1...v1.3.0) - 2024-02-05
Commits
- [New] add
EvalErrorandURIError1927627
release notes for 13 more packages omitted to keep this comment small — run lockvet locally for the rest
generated by lockvet
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
| "express": "4.17.1", | ||
| "lodash": "4.17.19" | ||
| "express": "4.18.2", | ||
| "lodash": "4.17.21" |
| "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.19.0.tgz", | ||
| "integrity": "sha512-dhEPs72UPbDnAQJ9ZKMNTP6ptJaionhP5cBb541nXPlW60Jepo9RV/a4fX4XWW9CuFNK22krhrj1+rgzifNCsw==", | ||
| "version": "1.20.1", | ||
| "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.20.1.tgz", |
| "dependencies": { | ||
| "express": "4.17.1", | ||
| "lodash": "4.17.19" | ||
| "express": "4.18.2", |
| "raw-body": "2.4.0", | ||
| "type-is": "~1.6.17" | ||
| "on-finished": "2.4.1", | ||
| "qs": "6.11.0", |
| "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.19.0.tgz", | ||
| "integrity": "sha512-dhEPs72UPbDnAQJ9ZKMNTP6ptJaionhP5cBb541nXPlW60Jepo9RV/a4fX4XWW9CuFNK22krhrj1+rgzifNCsw==", | ||
| "version": "1.20.1", | ||
| "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.20.1.tgz", |
| "raw-body": "2.4.0", | ||
| "type-is": "~1.6.17" | ||
| "on-finished": "2.4.1", | ||
| "qs": "6.11.0", |
| "resolved": "https://registry.npmjs.org/cookie/-/cookie-0.4.0.tgz", | ||
| "integrity": "sha512-+Hp8fLp57wnUSt0tY0tHEXh4voZRDnoIrZPqlo3DPiI4y9lwg/jqx+1Om94/W6ZaPDOUbnjOt/99w66zk+l1Xg==", | ||
| "version": "0.5.0", | ||
| "resolved": "https://registry.npmjs.org/cookie/-/cookie-0.5.0.tgz", |
| "setprototypeof": "1.1.1", | ||
| "statuses": "~1.5.0", | ||
| "safe-buffer": "5.2.1", | ||
| "send": "0.18.0", |
| "statuses": "~1.5.0", | ||
| "safe-buffer": "5.2.1", | ||
| "send": "0.18.0", | ||
| "serve-static": "1.15.0", |
| "express": "4.17.1", | ||
| "lodash": "4.17.19" | ||
| "express": "4.18.2", | ||
| "lodash": "4.17.21" |
Bumps lodash 4.17.19 → 4.17.21 and express 4.17.1 → 4.18.2. lockvet should explain this diff below.