This repository was archived by the owner on Mar 13, 2025. It is now read-only.
[Snyk] Upgrade dynamoose from 2.3.0 to 2.8.2 #59
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade dynamoose from 2.3.0 to 2.8.2.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-AWSSDK-1059424
Why? Proof of Concept exploit, CVSS 7.3
SNYK-JS-DYNAMOOSE-1070792
Why? Proof of Concept exploit, CVSS 7.3
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: dynamoose
-
2.8.2 - 2021-09-21
- Fixed bug where Model initialization would fail if
- Fixing multiple bugs where objects passed into Dynamoose functions would be mutated
- Added FAQ about empty arrays or objects
- Improved schema index documentation
- Improving
- Fixing issue where
-
2.8.1 - 2021-08-21
- Fix issue where query would fail with
- Resolve issue where Model.update would fail if beginning of attribute was identical to another attribute and marked as required
- Fix issue in TypeScript where you couldn't pass a number value in for a key parameter
- Resolved bug where passing a string or number in for Model.update key parameter would throw error
-
2.8.0 - 2021-08-14
- New
- Allowing
- Improvements to index selection when querying without
- Including
- Allowing for strings to be passed into
- Removing internal cache to improve memory usage
- Improving performance when working with Buffers
- Model default settings documentation fixes
-
2.7.3 - 2021-03-17
- Moving internal object utilities to different package
-
2.7.2 - 2021-03-14
- Type messages now display
- Added some more TypeScript tests
-
2.7.1 - 2021-03-11
- Fixing issue where with required check failing for non updating properties when using
- Prioritizing indexes with range key when querying
- Improvements to type and schema matching for nested properties
- Fixing issue where retrieving previously created model would ignore prefix and suffix
- Fixing TypeScript issues with nested models
- Fixing issue where nested models would auto-populate
- Fixing issues with nested models within nested elements
- Making
- Added warning when passing in
-
2.7.0 - 2021-02-06
- Patch for Prototype Pollution (GHSA-rrqm-p222-8ph2)
- Added
- Fixed a bug related to
-
2.6.0 - 2021-01-31
-
2.5.0 - 2020-12-13
-
2.4.1 - 2020-11-26
-
2.4.0 - 2020-11-22
-
2.3.0 - 2020-07-28
from dynamoose GitHub release notesVersion 2.8.2
This release fixes a few major bugs.
Please comment or contact me if you have any questions about this release.
Bug Fixes
waitForActive: trueDocumentation
Scan.startAt&Query.startAtexample in documentation\nappeared in schema attribute type documentation appeared instead of new lineVersion 2.8.1
This release includes a few critical bug fixes.
Please comment or contact me if you have any questions about this release.
Bug Fixes
Index can't be found for queryerror when querying table itselfVersion 2.8.0
This release contains general stability improvements to Dynamoose.
Please comment or contact me if you have any questions about this release.
General
returnValuessettings property forModel.updatewaitForActivemodel setting to be a booleanBug Fixes
usingmethodsaveUnknownproperties when usingModel.updateQuery.sortmethod when using TypeScriptDocumentation
Version 2.7.3
This release moves internal Dynamoose object utilities to a different package.
Please comment or contact me if you have any questions about this release.
Other
Version 2.7.2
This release fixes a bug related to the return value of
document.saveandModel.create, and more.Please comment or contact me if you have any questions about this release.
Bug Fixes
document.save&Model.createnow return the document saved to DynamoDBnullwhen passing in a invalid typenullvalue as opposed to the previousobjectOther
Version 2.7.1
This release has a lot of bug fixes for Dynamoose.
Please comment or contact me if you have any questions about this release.
Bug Fixes
$DELETEinModel.deleteDocumentation
saveUnknownmore clear in documentationOther
undefinedinto ConditionalVersion 2.7.0
This release patches a 🚨 security vulnerability 🚨.
Please comment or contact me if you have any questions about this release.
General
$DELETEoption forModel.updateBug Fixes
updatesetting being true for model with indexCommit messages
Package name: dynamoose
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs