Skip to content
This repository has been archived by the owner on Jan 18, 2023. It is now read-only.

Update dependency body-parser to v1.18.2 #7

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Jun 8, 2022

This PR contains the following updates:

Package Type Update Change
body-parser dependencies minor 1.17.2 -> 1.18.2

By merging this PR, the issue #9 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 7.5 CVE-2022-24999
Medium Medium 5.3 CVE-2017-16137

Release Notes

expressjs/body-parser

v1.18.2

Compare Source

===================

  • deps: debug@2.6.9
  • perf: remove argument reassignment

v1.18.1

Compare Source

===================

  • deps: content-type@~1.0.4
    • perf: remove argument reassignment
    • perf: skip parameter parsing when no parameters
  • deps: iconv-lite@0.4.19
    • Fix ISO-8859-1 regression
    • Update Windows-1255
  • deps: qs@6.5.1
    • Fix parsing & compacting very deep objects
  • deps: raw-body@2.3.2
    • deps: iconv-lite@0.4.19

v1.18.0

Compare Source

===================

  • Fix JSON strict violation error to match native parse error
  • Include the body property on verify errors
  • Include the type property on all generated errors
  • Use http-errors to set status code on errors
  • deps: bytes@3.0.0
  • deps: debug@2.6.8
  • deps: depd@~1.1.1
    • Remove unnecessary Buffer loading
  • deps: http-errors@~1.6.2
    • deps: depd@1.1.1
  • deps: iconv-lite@0.4.18
    • Add support for React Native
    • Add a warning if not loaded as utf-8
    • Fix CESU-8 decoding in Node.js 8
    • Improve speed of ISO-8859-1 encoding
  • deps: qs@6.5.0
  • deps: raw-body@2.3.1
    • Use http-errors for standard emitted errors
    • deps: bytes@3.0.0
    • deps: iconv-lite@0.4.18
    • perf: skip buffer decoding on overage chunk
  • perf: prevent internal throw when missing charset

  • If you want to rebase/retry this PR, click this checkbox.

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Jun 8, 2022
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.18.2 Update dependency body-parser to v1.18.2 - autoclosed Aug 12, 2022
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/body-parser-1.x-lockfile branch August 12, 2022 09:03
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.18.2 - autoclosed Update dependency body-parser to v1.18.2 Aug 14, 2022
@mend-for-github-com mend-for-github-com bot reopened this Aug 14, 2022
@mend-for-github-com mend-for-github-com bot restored the whitesource-remediate/body-parser-1.x-lockfile branch August 14, 2022 18:27
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.18.2 Update dependency body-parser to v1.18.2 - autoclosed Nov 27, 2022
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/body-parser-1.x-lockfile branch November 27, 2022 08:43
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.18.2 - autoclosed Update dependency body-parser to v1.18.2 Nov 29, 2022
@mend-for-github-com mend-for-github-com bot reopened this Nov 29, 2022
@mend-for-github-com mend-for-github-com bot restored the whitesource-remediate/body-parser-1.x-lockfile branch November 29, 2022 02:09
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.18.2 Update dependency body-parser to v1.18.0 Nov 29, 2022
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch from c9d2907 to 7cbe25e Compare November 29, 2022 14:31
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch from 7cbe25e to 7b98875 Compare November 30, 2022 06:17
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.18.0 Update dependency body-parser to v1.18.2 Nov 30, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
security fix Security fix generated by Mend
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants