-
Notifications
You must be signed in to change notification settings - Fork 0
chore(deps): update dependency mongodb to v4.17.0 [security] #32
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/npm-mongodb-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
0cb88c3 to
7a6eaf6
Compare
3c73974 to
8512216
Compare
8cb06fb to
ceabbc0
Compare
ceabbc0 to
1df2266
Compare
1df2266 to
8244159
Compare
8244159 to
e6b0bbe
Compare
e6b0bbe to
64074c4
Compare
64074c4 to
340a937
Compare
340a937 to
f00e3e0
Compare
f00e3e0 to
4f6aee8
Compare
4f6aee8 to
8e558b9
Compare
8e558b9 to
08b384d
Compare
3855449 to
0668726
Compare
0668726 to
54b7d3f
Compare
54b7d3f to
68e376b
Compare
68e376b to
bd6e643
Compare
bd6e643 to
06adbfc
Compare
06adbfc to
d5e3be2
Compare
d5e3be2 to
0b775a4
Compare
0b775a4 to
ced4772
Compare
ced4772 to
fe5ec38
Compare
fe5ec38 to
0138283
Compare
88c9593 to
451a843
Compare
451a843 to
28654df
Compare
28654df to
1126f0d
Compare
555bd0d to
fb05851
Compare
fb05851 to
ed6fe2e
Compare
ed6fe2e to
ecc79c9
Compare
ecc79c9 to
590dfff
Compare
590dfff to
7c693f9
Compare
7c693f9 to
b20be90
Compare
b20be90 to
4d691b9
Compare
4d691b9 to
ce2fa02
Compare
ce2fa02 to
97d4dcb
Compare
4011aae to
79dba09
Compare
79dba09 to
a8328f7
Compare
a8328f7 to
092a7bb
Compare
092a7bb to
85ab79e
Compare
85ab79e to
3e6f6ce
Compare
3e6f6ce to
f74fdf0
Compare
60c4137 to
f997734
Compare
f997734 to
1f4989a
Compare
1f4989a to
e802e8c
Compare
e802e8c to
e8e6f82
Compare
c0a0e8e to
86fbd3e
Compare
86fbd3e to
30a3220
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.1.3→4.17.0GitHub Vulnerability Alerts
CVE-2021-32050
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.
Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).
This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).
Release Notes
mongodb/node-mongodb-native (mongodb)
v4.17.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.17.0 of the
mongodbpackage!Release Notes
mongodb-js/saslprepis now installed by defaultUntil v6, the driver included the
saslpreppackage as an optional dependency for SCRAM-SHA-256 authentication.saslprepbreaks when bundled with webpack because it attempted to read a file relative to the package location and consequently the driver would throw errors when using SCRAM-SHA-256 if it were bundled.The driver now depends on
mongodb-js/saslprep, a fork ofsaslprepthat can be bundled with webpack because it includes the necessary saslprep data in memory upon loading. This will be installed by default but will only be used if SCRAM-SHA-256 authentication is used.Remove credential availability on
ConnectionPoolCreatedEventIn order to avoid mistakenly printing credentials the
ConnectionPoolCreatedEventwill replace the credentials option with an empty object. The credentials are still accessble via MongoClient options:client.options.credentials.Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.16.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.16.0 of the
mongodbpackage!Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.15.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.15.0 of the mongodb package!
Features
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.14.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.14.0 of the mongodb package!
Deprecations
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.13.0Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.12.1Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.12.0Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.11.0Compare Source
Features
Bug Fixes
v4.10.0Compare Source
Features
Bug Fixes
v4.9.1Compare Source
The MongoDB Node.js team is pleased to announce version 4.9.1 of the mongodb package!
Release Highlights
This is a bug fix release as noted below.
Bug Fixes
v4.9.0Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.8.1Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.8.0Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.7.0Compare Source
Features
Bug Fixes
v4.6.0Compare Source
Features
Bug Fixes
v4.5.0Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.4.1Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.4.0Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.3.1Compare Source
Features
Bug Fixes
4.3.1 (2022-01-18)
Bug Fixes
v4.3.0[Compare Source](https://redirect.github.com/mongodb/
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.