-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update dependency mongodb to v3 [security] #14
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-mongodb-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
changed the title
fix(deps): pin dependency mongodb to v2.2.36 [security]
fix(deps): pin dependency mongodb to 2.2.36 [security]
May 9, 2021
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
May 15, 2021 20:03
85d8b3c
to
a72a8b8
Compare
renovate
bot
changed the title
fix(deps): pin dependency mongodb to 2.2.36 [security]
fix(deps): update dependency mongodb to v3 [security]
May 15, 2021
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 6, 2021 22:45
a72a8b8
to
24fba29
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): pin dependency mongodb to v2.2.36 [security]
Jun 6, 2021
renovate
bot
changed the title
fix(deps): pin dependency mongodb to v2.2.36 [security]
fix(deps): pin dependency mongodb to v [security]
Mar 7, 2022
renovate
bot
changed the title
fix(deps): pin dependency mongodb to v [security]
fix(deps): pin dependency mongodb to v2.2.36 [security]
Sep 25, 2022
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
November 20, 2022 08:52
24fba29
to
81d0280
Compare
renovate
bot
changed the title
fix(deps): pin dependency mongodb to v2.2.36 [security]
fix(deps): update dependency mongodb to v4 [security]
Nov 20, 2022
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
March 18, 2023 17:55
81d0280
to
eababbb
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v4 [security]
fix(deps): update dependency mongodb to v5 [security]
Mar 18, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
March 27, 2023 17:14
eababbb
to
56f55ec
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v5 [security]
fix(deps): update dependency mongodb to v3 [security]
Mar 27, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 1, 2023 16:14
56f55ec
to
50e6db7
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v5 [security]
Jun 1, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 2, 2023 02:22
50e6db7
to
330b23a
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v5 [security]
fix(deps): update dependency mongodb to v3 [security]
Jun 2, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 9, 2023 05:47
330b23a
to
d944f7c
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v5 [security]
Jun 9, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 10, 2023 11:49
d944f7c
to
451f029
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v5 [security]
fix(deps): update dependency mongodb to v3 [security]
Jun 10, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 13, 2023 20:59
451f029
to
7c4ad62
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v5 [security]
Jun 13, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 16, 2023 02:50
7c4ad62
to
d6affe0
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v5 [security]
fix(deps): update dependency mongodb to v3 [security]
Jun 16, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 18, 2023 11:50
d6affe0
to
530f9fd
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v5 [security]
Jun 18, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 22, 2023 23:33
530f9fd
to
62aebcb
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v5 [security]
fix(deps): update dependency mongodb to v3 [security]
Jun 22, 2023
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 29, 2023 23:36
62aebcb
to
b656799
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v6 [security]
fix(deps): update dependency mongodb to v3 [security]
May 25, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 6, 2024 02:30
6242e27
to
68a856f
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v6 [security]
Jun 6, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 7, 2024 05:19
68a856f
to
52730f7
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v6 [security]
fix(deps): update dependency mongodb to v3 [security]
Jun 7, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 28, 2024 05:38
52730f7
to
fb46f8e
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v6 [security]
Jun 28, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
June 29, 2024 11:46
fb46f8e
to
68a186c
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v6 [security]
fix(deps): update dependency mongodb to v3 [security]
Jun 29, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
July 15, 2024 17:46
68a186c
to
446256c
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v6 [security]
Jul 15, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
July 17, 2024 23:51
446256c
to
aa92c48
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v6 [security]
fix(deps): update dependency mongodb to v3 [security]
Jul 17, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
July 21, 2024 17:54
aa92c48
to
7988b0f
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v6 [security]
Jul 21, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
July 24, 2024 02:35
7988b0f
to
e26ae8c
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v6 [security]
fix(deps): update dependency mongodb to v3 [security]
Jul 24, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
July 29, 2024 05:25
e26ae8c
to
1fc8151
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v6 [security]
Jul 29, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
July 30, 2024 02:02
1fc8151
to
768214d
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v6 [security]
fix(deps): update dependency mongodb to v3 [security]
Jul 30, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
October 10, 2024 05:27
768214d
to
bd9e881
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v6 [security]
Oct 10, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
October 13, 2024 10:52
bd9e881
to
c31ac57
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v6 [security]
fix(deps): update dependency mongodb to v3 [security]
Oct 13, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
October 30, 2024 08:44
c31ac57
to
009fd56
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v3 [security]
fix(deps): update dependency mongodb to v6 [security]
Oct 30, 2024
renovate
bot
force-pushed
the
renovate/npm-mongodb-vulnerability
branch
from
October 31, 2024 20:52
009fd56
to
800c601
Compare
renovate
bot
changed the title
fix(deps): update dependency mongodb to v6 [security]
fix(deps): update dependency mongodb to v3 [security]
Oct 31, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.0.39
->^3.1.13
GitHub Vulnerability Alerts
GHSA-mh5c-679w-hh4r
Versions of
mongodb
prior to 3.1.13 are vulnerable to Denial of Service. The package fails to properly catch an exception when a collection name is invalid and the DB does not exist, crashing the application.Recommendation
Upgrade to version 3.1.13 or later.
Release Notes
mongodb/node-mongodb-native (mongodb)
v3.1.13
Compare Source
Bug Fixes
makeLazyLoader
(050267d)v3.1.12
Compare Source
Features
v3.1.11
Compare Source
Bug Fixes
v3.1.10
Compare Source
Bug Fixes
Features
v3.1.9
Compare Source
Bug Fixes
Features
v3.1.8
Compare Source
Bug Fixes
Features
v3.1.7
Compare Source
Features
v3.1.6
Compare Source
Features
v3.1.5
Compare Source
Bug Fixes
$meta
based sort when passing an array tosort()
(f93a8c3)Features
v3.1.4
Compare Source
Bug Fixes
Features
newClient
(1dac18f)v3.1.3
Compare Source
Features
v3.1.2
Compare Source
Bug Fixes
batchSize
(ad10dee)resolveReadPreference
for inheritance (a649e35)_id
with background: true (b3ff3ed)endSessions
is always skipped now (a276cbe)Features
Reverts
v3.1.1
Compare Source
Bug Fixes
makeLazyLoader
(050267d)v3.1.0
Compare Source
Bug Fixes
batchSize
(ad10dee)resolveReadPreference
for inheritance (a649e35)_id
with background: true (b3ff3ed)endSessions
is always skipped now (a276cbe)Features
Reverts
3.0.6 (2018-04-09)
Bug Fixes
dropDatabase
always uses primary read preference (e62e5c9)Features
3.0.5 (2018-03-23)
Bug Fixes
Features
3.0.4 (2018-03-05)
Bug Fixes
Features
3.0.3 (2018-02-23)
Bug Fixes
3.0.2 (2018-01-29)
Bug Fixes
db
is wrapped in parentheses (efa78f0)Features
dbName
property of collection (6fd05c1)3.0.1 (2017-12-24)
v3.0.11
Compare Source
v3.0.10
Compare Source
v3.0.9
Compare Source
v3.0.8
Compare Source
v3.0.7
Compare Source
v3.0.6
Compare Source
Bug Fixes
dropDatabase
always uses primary read preference (e62e5c9)Features
v3.0.5
Compare Source
Bug Fixes
Features
v3.0.4
Compare Source
Bug Fixes
Features
v3.0.3
Compare Source
Bug Fixes
v3.0.2
Compare Source
Bug Fixes
db
is wrapped in parentheses (efa78f0)Features
dbName
property of collection (6fd05c1)v3.0.1
Compare Source
v3.0.0
Compare Source
Bug Fixes
Features
BREAKING CHANGES
.connect
method on replset and mongos has changed. You shouldn't have been using this anyway, but if you were, you only should passoptions
andcallback
.Part of NODE-1089
keepAlive
is now split into booleankeepAlive
andnumber
keepAliveInitialDelay
Fixes NODE-998
v2.2.36
Compare Source
v2.2.35
Compare Source
v2.2.34
Compare Source
v2.2.33
Compare Source
v2.2.32
Compare Source
v2.2.31
Compare Source
promoteLongs
from MongoClient'sconnect
v2.2.30
Compare Source
appname
to list of valid option namesv2.2.29
Compare Source
v2.2.28
Compare Source
v2.2.27
Compare Source
_id
(Issue #1517, https://github.com/vkarpov15).v2.2.26
Compare Source
v2.2.25
Compare Source
v2.2.24
Compare Source
v2.2.23
Compare Source
v2.2.22
Compare Source
v2.2.21
Compare Source
v2.2.20
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.