-
Notifications
You must be signed in to change notification settings - Fork 5
chore(deps): update dependency @nestjs/core to v9 [security] #127
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/npm-nestjs-core-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
3aba3f3 to
b735526
Compare
b735526 to
9ea916f
Compare
9ea916f to
324af65
Compare
324af65 to
5c07672
Compare
5c07672 to
6f21f7d
Compare
6f21f7d to
373cf1d
Compare
373cf1d to
ccde57c
Compare
ccde57c to
e8261d8
Compare
e8261d8 to
50bff74
Compare
50bff74 to
7aa66f9
Compare
7aa66f9 to
309cdd6
Compare
309cdd6 to
eb1b087
Compare
eb1b087 to
9c9bbbf
Compare
9c9bbbf to
5487299
Compare
5487299 to
1ae51d6
Compare
7d74dcf to
30f4b83
Compare
30f4b83 to
80a0886
Compare
188ee37 to
c640e86
Compare
c640e86 to
3ab7831
Compare
3ab7831 to
4549bbc
Compare
4549bbc to
2b65551
Compare
2b65551 to
ffe7144
Compare
ffe7144 to
5bd1779
Compare
5bd1779 to
b94797f
Compare
b94797f to
9a55312
Compare
9a55312 to
d2c70e9
Compare
d2c70e9 to
8d38194
Compare
8d38194 to
36fef8f
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
>=8 <9→>=9.0.5 <108.4.1→9.0.5GitHub Vulnerability Alerts
CVE-2023-26108
Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client cancels a request while it is streaming a StreamableFile, the stream wrapped by the StreamableFile will be kept open.
Release Notes
nestjs/nest (@nestjs/core)
v9.0.5Compare Source
v9.0.5 (2022-07-20)
Bug fixes
common,platform-expressEnhancements
microservicesplatform-express,platform-fastifyDependencies
platform-fastifyCommitters: 4
v9.0.4Compare Source
v9.0.3Compare Source
v9.0.2Compare Source
v9.0.2
Bug fixes
commonEnhancements
coreDependencies
Committers: 3
v9.0.1Compare Source
v9.0.0Compare Source
v9.0.0 (2022-07-08)
Article: https://trilon.io/blog/nestjs-9-is-now-available
Migration guide: https://docs.nestjs.com/migration-guide
Features
commoncommon,coreBug fixes
microservicesEnhancements
common,core,platform-express,platform-fastifyHttpServer#applyVersionFiltermandatory (@micalevisk)commoninjecton class and value providers at type level (@micalevisk)microservicespostfixIdonKafkaOptionsto be an empty string (@micalevisk)corecommon,core,microservicescore,websocketsDependencies
platform-fastifymicroservices,testingplatform-wsCommitters: 13
v8.4.7Compare Source
v8.4.7 (2022-06-14)
Enhancements
microservicescommonDependencies
Committers: 5
v8.4.6Compare Source
v8.4.5Compare Source
v8.4.5 (2022-05-13)
Bug fixes
coreEnhancements
commoncoreDependencies
platform-fastifyplatform-socket.ioplatform-expresscommoncommon,core,microservices,platform-express,platform-fastify,platform-socket.io,platform-ws,testing,websocketsCommitters: 6
v8.4.4Compare Source
v8.4.4 (2022-04-07)
Bug fixes
microservicesEnhancements
commonprivatemodifer on built-in pipes toprotected(@micalevisk)Dependencies
platform-fastifyplatform-expressCommitters: 5
v8.4.3Compare Source
v8.4.2Compare Source
v8.4.1Compare Source
v8.4.1 (2022-03-14)
Bug fixes
coremicroservicesEnhancements
commonDependencies
commonplatform-fastifyCommitters: 6
v8.4.0Compare Source
v8.4.0 (2022-03-01)
Features
common,coreBug fixes
microservicesConfiguration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.