Skip to content

[Snyk] Security upgrade typeorm from 0.2.24 to 0.3.21#247

Open
Omrisnyk wants to merge 1 commit intomasterfrom
snyk-fix-9f52add5707b4c10d8f39678f1a4e53a
Open

[Snyk] Security upgrade typeorm from 0.2.24 to 0.3.21#247
Omrisnyk wants to merge 1 commit intomasterfrom
snyk-fix-9f52add5707b4c10d8f39678f1a4e53a

Conversation

@Omrisnyk
Copy link
Owner

@Omrisnyk Omrisnyk commented Mar 3, 2025

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Prototype Pollution
SNYK-JS-Y18N-1021887
  160  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
  159  
Release notes
Package name: typeorm

@Omrisnyk
Copy link
Owner Author

Omrisnyk commented Mar 3, 2025

Snyk checks have failed. 117 issues have been found so far.

Icon Severity Issues
Critical 3
High 52
Medium 53
Low 9

security/snyk check is complete. 117 issues have been found. (View Details)

license/snyk check is complete. No issues have been found. (View Details)

@Omrisnyk
Copy link
Owner Author

Omrisnyk commented Mar 3, 2025

🎉 Snyk checks have passed. No issues have been found so far.

security/snyk check is complete. No issues have been found. (View Details)

license/snyk check is complete. No issues have been found. (View Details)

code/snyk check is complete. No issues have been found. (View Details)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants