Skip to content
This repository was archived by the owner on Jun 24, 2025. It is now read-only.

dependencies updated#18

Open
punund wants to merge 2 commits intofloatdrop:masterfrom
punund:master
Open

dependencies updated#18
punund wants to merge 2 commits intofloatdrop:masterfrom
punund:master

Conversation

@punund
Copy link

@punund punund commented Apr 13, 2020

No description provided.

@emcniece
Copy link

emcniece commented May 8, 2020

This pull request resolves a high-severity DDOS vulnerability: https://npmjs.com/advisories/1203

Please merge!

npm audit

                       === npm audit security report ===

┌──────────────────────────────────────────────────────────────────────────────┐
│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit https://go.npm.me/audit-guide for additional guidance          │
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High          │ Denial of Service                                            │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ mongodb                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=3.1.13                                                     │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ express-mongo-db                                             │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ express-mongo-db > mongodb                                   │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/1203                            │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 high severity vulnerability in 630 scanned packages
  1 vulnerability requires manual review. See the full report for details.

@devksingh4
Copy link

I would also be interested in seeing this updated. If the owner can't update it, I'll publish a new version of this package myself and post it here so others can use it

@devksingh4
Copy link

Actually, seeing that it's under the MIT license, I decided to go ahead and implement these changes here: https://www.npmjs.com/package/mongo-express-req

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants