Skip to content

Conversation

parseplatformorg
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 601/1000
Why? Recently disclosed, Has a fix available, CVSS 6.3
Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: express The new version differs by 2 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)

Copy link

I will reformat the title to use the proper commit message syntax.

@parse-github-assistant parse-github-assistant bot changed the title [Snyk] Security upgrade express from 4.21.0 to 4.21.1 refactor: Security upgrade express from 4.21.0 to 4.21.1 Oct 9, 2024
Copy link

parse-github-assistant bot commented Oct 9, 2024

Thanks for opening this pull request!

  • ❌ Please link an issue that describes the reason for this pull request, otherwise your pull request will be closed. Make sure to write it as Closes: #123 in the PR description, so I can recognize it.

Copy link

uffizzi-cloud bot commented Oct 9, 2024

Uffizzi Ephemeral Environment deployment-57064

⌚ Updated Oct 09, 2024, 07:42 UTC

☁️ https://app.uffizzi.com/github.com/parse-community/parse-dashboard/pull/2607

📄 View Application Logs etc.

What is Uffizzi? Learn more

@mtrezza mtrezza changed the title refactor: Security upgrade express from 4.21.0 to 4.21.1 fix: Security upgrade express from 4.21.0 to 4.21.1 Oct 9, 2024
@mtrezza mtrezza merged commit 54bf0af into alpha Oct 9, 2024
10 checks passed
@mtrezza mtrezza deleted the snyk-fix-db6cb276d86a6de531e435ed515c9fde branch October 9, 2024 09:52
parseplatformorg pushed a commit that referenced this pull request Oct 9, 2024
# [6.0.0-alpha.17](6.0.0-alpha.16...6.0.0-alpha.17) (2024-10-09)

### Bug Fixes

* Security upgrade express from 4.21.0 to 4.21.1 ([#2607](#2607)) ([54bf0af](54bf0af))
@parseplatformorg
Copy link
Contributor Author

🎉 This change has been released in version 6.0.0-alpha.17

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Oct 9, 2024
vardhan0604 pushed a commit to vardhan0604/parse-dashboard that referenced this pull request Oct 22, 2024
vardhan0604 pushed a commit to vardhan0604/parse-dashboard that referenced this pull request Oct 22, 2024
parseplatformorg pushed a commit that referenced this pull request Mar 4, 2025
# [6.1.0](6.0.0...6.1.0) (2025-03-04)

### Bug Fixes

* Info panel Cloud Code call is unauthenticated without using master key ([#2641](#2641)) ([e879e4f](e879e4f))
* Info panel Cloud Code call sends `objectId` instead of `Parse.Object` ([#2643](#2643)) ([a4bcabc](a4bcabc))
* Info panel item `panel` calls Cloud Code with parameter `objectId` instead of `Parse.Object` and without `masterKey` ([#2649](#2649)) ([884ff70](884ff70))
* Info panel not configurable via `new ParseDashboard()` when running as express middleware ([#2639](#2639)) ([a9b8cd4](a9b8cd4))
* Info panel not showing when some apps miss infoPanel config ([#2627](#2627)) ([539e883](539e883))
* Node 22 support missing in package.json ([#2617](#2617)) ([8c07284](8c07284))
* Security upgrade cross-spawn from 7.0.3 to 7.0.6 ([#2629](#2629)) ([47a43e0](47a43e0))
* Security upgrade express from 4.21.0 to 4.21.1 ([#2607](#2607)) ([54bf0af](54bf0af))
* Security upgrade node from 20.17.0-alpine3.20 to 20.18.2-alpine3.20 ([#2647](#2647)) ([44df723](44df723))
* Security upgrade ws, parse and puppeteer ([#2618](#2618)) ([bab71dc](bab71dc))

### Features

* Add cell selection in data browser on space bar touch down ([#2661](#2661)) ([9d623a9](9d623a9))
* Add dynamic master key by allowing to set option `masterKey` to a function ([#2655](#2655)) ([9025ed0](9025ed0))
* Add info panel `keyValue` item parameter `isRelativeUrl` to link to dashboard pages ([#2646](#2646)) ([6389fc6](6389fc6))
* Add info panel item `panel` to load and display data on demand ([#2622](#2622)) ([8e5741d](8e5741d))
@parseplatformorg
Copy link
Contributor Author

🎉 This change has been released in version 6.1.0

@parseplatformorg parseplatformorg added the state:released Released as stable version label Mar 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
state:released Released as stable version state:released-alpha Released as alpha version
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants