Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade @google-cloud/firestore from 2.2.7 to 2.6.1 #4

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade @google-cloud/firestore from 2.2.7 to 2.6.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 7 versions ahead of your current version.
  • The recommended version was released 3 years ago, on 2019-12-05.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-PROTOBUFJS-2441248
517/1000
Why? Proof of Concept exploit, CVSS 8.2
Proof of Concept
Prototype Pollution
SNYK-JS-GRPCGRPCJS-1038818
517/1000
Why? Proof of Concept exploit, CVSS 8.2
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @google-cloud/firestore from @google-cloud/firestore GitHub release notes
Commit messages
Package name: @google-cloud/firestore
  • 1f4eb0a chore: release 2.6.1 (#796)
  • 0d4e558 fix(deps): pin TypeScript below 3.7.0
  • a0b3da8 chore: update license headers
  • f842e9b chore: add gitattributes to kokoro
  • 396bebb fix(docs): snippets are now replaced in jsdoc comments (#795)
  • bacef9b refactor: run prettier (#794)
  • 2876f62 chore(deps): update dependency typescript to ~3.7.0 (#792)
  • 4b56815 chore: release 2.6.0 (#790)
  • 00bdf8f feat: add IN queries support (#715)
  • 6568a47 test: collect coverage in src/ folder
  • 37853f0 chore: release 2.5.0 (#782)
  • e5763ba fix(deps): bump google-gax to 1.7.5 (#786)
  • 6fa9270 chore: update protos and generated js files (#784)
  • 2c8869d feat: introduces ARRAY_CONTAINS_ANY and IN to operator enum
  • 76a879d chore: update CONTRIBUTING.md and make releaseType node (#780)
  • c3654c1 chore: release 2.4.0 (#770)
  • 29c3e9b fix: provide custom error for FieldValue subclasses (#771)
  • 39adabb docs: update docs for system test (#772)
  • b0c89c5 fix: use compatible version of google-gax
  • b16cd40 feat: ability to specify the Collection Group query scope in the V1 Admin API (#762)
  • a425b8b chore: update pull request template
  • a13afe2 chore: add protos/ to .eslintignore
  • 484b06e build: switch to repo-automation-bots for releases
  • 48a9a38 build: switch to GitHub app for releases (#758)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant