Skip to content

[Snyk] Security upgrade googleapis from 34.0.0 to 37.0.0#205

Closed
aravindbuilt wants to merge 1 commit intomasterfrom
snyk-fix-15679c128a6dc66eaee66c1d6043f2a6
Closed

[Snyk] Security upgrade googleapis from 34.0.0 to 37.0.0#205
aravindbuilt wants to merge 1 commit intomasterfrom
snyk-fix-15679c128a6dc66eaee66c1d6043f2a6

Conversation

@aravindbuilt
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • google-analytics/lambda/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 616/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Server-Side Request Forgery (SSRF)
SNYK-JS-AXIOS-1038255
Yes Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-1579269
Yes Proof of Concept
high severity 676/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.1
Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2332181
Yes Proof of Concept
low severity 344/1000
Why? Has a fix available, CVSS 2.6
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: googleapis The new version differs by 75 commits.
  • 7e3d978 Release v37.0.0 (#1568)
  • ecb2c28 build: check for 404s in the docs (#1562)
  • d49aa49 docs: run the docs command (#1566)
  • d1af168 feat: run the generator (#1564)
  • 9ccda50 chore(deps): update dependency eslint-config-prettier to v4 (#1565)
  • 73f8f9c docs: specify gaxios over axios (#1558)
  • 7f7f3cf fix(deps): update dependency googleapis-common to ^0.7.0 (#1560)
  • c62efb1 docs(samples): add people samples for get & create contacts (#1543)
  • 2ad63f6 feat: webpack support for all APIs (#1554)
  • d8ba2ac fix(deps): update googleapis-common and google-auth-library (#1556)
  • 9742db3 feat: generating webpackable packages (#1547)
  • e70272c fix(generator): convert method names to camelCase (#1552)
  • 8d9c5d9 docs: fix typo in README.md (#1549)
  • de464c0 feat: run the generator (#1541)
  • 7e07d11 docs: improve the compute sample in the README (#1537)
  • 47056e9 docs(samples): rework the compute list vms sample (#1534)
  • 3b612fc fix(test): fix the revoke token test (#1532)
  • 4115c0f chore(deps): update dependency typedoc to ^0.14.0 (#1527)
  • c61e14d docs: correct the README (#1522)
  • 438979a docs: use blogger to demonstrate key authentication (#1519)
  • f6edb8e chore: update license file and metadata (#1504)
  • 230bb64 chore(build): inject yoshi automation key (#1503)
  • 443662e chore: update nyc and eslint configs (#1502)
  • 413d9ca chore: fix publish.sh permission +x (#1499)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Server-Side Request Forgery (SSRF)
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Cross-site Request Forgery (CSRF)

@aravindbuilt aravindbuilt requested a review from a team as a code owner November 28, 2023 18:13
@rahul-contentstack rahul-contentstack force-pushed the snyk-fix-15679c128a6dc66eaee66c1d6043f2a6 branch from 320dacb to e95f45c Compare November 27, 2025 16:12
@rahul-contentstack rahul-contentstack requested a review from a team as a code owner November 27, 2025 16:12
@aravindbuilt aravindbuilt deleted the snyk-fix-15679c128a6dc66eaee66c1d6043f2a6 branch December 23, 2025 12:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants