-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Upgrade ipfs-http-server from 0.1.4 to 0.15.1 #374
base: develop
Are you sure you want to change the base?
Conversation
Snyk has created this PR to upgrade ipfs-http-server from 0.1.4 to 0.15.1. See this package in npm: https://www.npmjs.com/package/ipfs-http-server See this project in Snyk: https://app.snyk.io/org/sammyfilly/project/0778148f-8a59-4afb-bcbf-e9bdb110ac13?utm_source=github&utm_medium=referral&page=upgrade-pr
Run & review this pull request in StackBlitz Codeflow. |
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
PR Type: Enhancement
PR Summary: This pull request upgrades the ipfs-http-server dependency from version 0.1.4 to 0.15.1. The upgrade addresses a medium severity security vulnerability related to Information Exposure in the node-fetch package, which is a dependency of ipfs-http-server. By updating to version 0.15.1, the project mitigates the risk associated with this vulnerability. Additionally, the upgrade brings the project's ipfs-http-server dependency 231 versions forward, incorporating numerous bug fixes, dependency updates, and improvements made over the 9 months since the previous version was released.
Decision: Comment
📝 Type: 'Enhancement' - not supported yet.
- Sourcery currently only approves 'Typo fix' PRs.
✅ Issue addressed: this change correctly addresses the issue or implements the desired feature.
No details provided.
📝 Complexity: the changes are too large or complex for Sourcery to approve.
- Unsupported files: the diff contains files that Sourcery does not currently support during reviews.
General suggestions:
- Ensure thorough testing of the integration with ipfs-http-server version 0.15.1 to confirm that the upgrade does not introduce any regressions or compatibility issues.
- Review the release notes and commit messages associated with the ipfs-http-server upgrade to understand the changes and improvements that come with this version. This can help in identifying any adjustments needed in the project to leverage new features or changes.
- Consider setting up a process for more regular dependency updates to avoid large jumps in versions, which can make upgrades more challenging and increase the risk of missing out on important fixes or improvements.
Thanks for using Sourcery. We offer it for free for open source projects and would be very grateful if you could help us grow. If you like it, would you consider sharing Sourcery on your favourite social media? ✨
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade ipfs-http-server from 0.1.4 to 0.15.1.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-NODEFETCH-2342118
Why? Has a fix available, CVSS 6.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: ipfs-http-server
Bug Fixes
Dependencies
Bug Fixes
Dependencies
Bug Fixes
Dependencies
Bug Fixes
Commit messages
Package name: ipfs-http-server
--flavor
feature (ganache chain plugins) trufflesuite/ganache#4362)export {/*magic*/};\n
hack trufflesuite/ganache#4294)Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs