Skip to content

[Snyk] Security upgrade moralis from 1.11.0 to 2.0.0 - #2

Open
GeminiWolf wants to merge 1 commit into
masterfrom
snyk-fix-425584bf4a682474382861a2c6d995c2
Open

[Snyk] Security upgrade moralis from 1.11.0 to 2.0.0#2
GeminiWolf wants to merge 1 commit into
masterfrom
snyk-fix-425584bf4a682474382861a2c6d995c2

Conversation

@GeminiWolf

Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 748/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.1
Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: moralis The new version differs by 250 commits.
  • dd67d4a Merge pull request #578 from MoralisWeb3/changeset-release/main
  • 1599284 Version Packages
  • 639053e docs: add 2.0 realse changeset
  • 1e2e354 ci: remove outdated changesets
  • fedebd2 ci: remove outdated changesets
  • b2326cc ci: include release action in main
  • fdf9fd0 ci: exit changeset pre-release
  • 4e80123 docs: remove beta warning
  • 16837be Merge pull request #572 from MoralisWeb3/beta
  • c2ac39d Merge remote-tracking branch 'origin/main' into beta
  • 9c910e7 Merge pull request #571 from MoralisWeb3/changeset-release/beta
  • a67a7d4 Version Packages (beta)
  • 9d762be Merge pull request #570 from MoralisWeb3/fix-evm-api-arrays
  • 284205d docs: fix changelog typo
  • fa082b6 docs: add changeset
  • 55a5650 fix: equality check of decimals
  • 08e7f7c fix: evmApi arrays
  • a50c2b4 Merge pull request #569 from MoralisWeb3/changeset-release/beta
  • 79dd992 Version Packages (beta)
  • c76336d Merge pull request #568 from MoralisWeb3/improve-datatypes
  • f30f8ca refactor: consistent getters for constants
  • e4765cb fix: Erc20Transfer rename
  • f42f0d7 ci: force clean build
  • abf88ad ci: fix ci

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Request Forgery (CSRF)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-AXIOS-6032459
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants