[security] chore(deps): Bump mongoose from 5.3.7 to 5.7.6#91
[security] chore(deps): Bump mongoose from 5.3.7 to 5.7.6#91dependabot-preview[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps [mongoose](https://github.com/Automattic/mongoose) from 5.3.7 to 5.7.6. - [Release notes](https://github.com/Automattic/mongoose/releases) - [Changelog](https://github.com/Automattic/mongoose/blob/master/History.md) - [Commits](Automattic/mongoose@5.3.7...5.7.6) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Codecov Report
@@ Coverage Diff @@
## master #91 +/- ##
======================================
Coverage 62.5% 62.5%
======================================
Files 2 2
Lines 16 16
Branches 2 2
======================================
Hits 10 10
Misses 5 5
Partials 1 1Continue to review full report at Codecov.
|
|
We've just been alerted that this update fixes a security vulnerability: Sourced from The GitHub Security Advisory Database.
|
Bumps mongoose from 5.3.7 to 5.7.6.
Changelog
Sourced from mongoose's changelog.
Commits
5656b4echore: release 5.7.6fab4f5dtest(schema): fix tests on node v4 and v529c5f1afix(options): add missing minlength and maxlength to SchemaStringOptionsa81211dfix(populate): add document array subpaths to parent docpopulated()when c...4e900ebtest(populate): repro #8247d69ab22fix(document): support callingDocumentconstructor directly in Node.js9b986f5test(document): repro #8237e5f8875chore: add bonus.ca to opencollective sponsors25b6798fix(populate): makeArraySubdocument#populated()return a value when the pa...8ddfc0atest(populate): repro #8247Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readmeAdditionally, you can set the following in your Dependabot dashboard: