Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade twilio from 3.55.1 to 3.66.0 #1

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade twilio from 3.55.1 to 3.66.0.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 12 versions ahead of your current version.
  • The recommended version was released a month ago, on 2021-07-14.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Command Injection
SNYK-JS-LODASH-1040724
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept
Open Redirect
SNYK-JS-URLPARSE-1533425
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept
Improper Input Validation
SNYK-JS-URLPARSE-1078283
467/1000
Why? Proof of Concept exploit, CVSS 7.2
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: twilio
  • 3.66.0 - 2021-07-14

    Release Notes

    Conversations

    • Changed last_read_message_index and unread_messages_count type in User Conversation's resource (breaking change)
    • Expose UserConversations resource

    Messaging

    • Add brand_score field to brand registration responses

    Docs

  • 3.65.0 - 2021-06-30

    Release Notes

    Conversations

    • Read-only Conversation Email Binding property binding

    Supersim

    • Add Billing Period resource for the Super Sim Pilot
    • Add List endpoint to Billing Period resource for Super Sim Pilot
    • Add Fetch endpoint to Billing Period resource for Super Sim Pilot

    Taskrouter

    • Update transcribe & transcription_configuration form params in Reservation update endpoint to have private visibility (breaking change)
    • Add transcribe & transcription_configuration form params to Reservation update endpoint

    Twiml

    • Add modify event to statusCallbackEvent for <Conference>.

    Docs

  • 3.64.0 - 2021-06-16

    Release Notes

    Library - Chore

    Api

    • Update status enum for Messages to include 'canceled'
    • Update update_status enum for Messages to include 'canceled'

    Trusthub

    • Corrected the sid for policy sid in customer_profile_evaluation.json and trust_product_evaluation.json (breaking change)

    Docs

  • 3.63.1 - 2021-06-02

    Release Notes

    Library - Fix

    Events

    • join Sinks and Subscriptions service

    Verify

    • Improved the documentation of challenge adding the maximum and minimum expected lengths of some fields.
    • Improve documentation regarding notification by updating the documentation of the field ttl.

    Docs

  • 3.63.0 - 2021-05-19

    Release Notes

    Library - Chore

    Events

    • add query param to return types filtered by Schema Id
    • Add query param to return sinks filtered by status
    • Add query param to return sinks used/not used by a subscription

    Messaging

    • Add fetch and delete instance endpoints to us_app_to_person api (breaking change)
    • Remove delete list endpoint from us_app_to_person api (breaking change)
    • Update read list endpoint to return a list of us_app_to_person compliance objects (breaking change)
    • Add sid field to Preregistered US App To Person response

    Supersim

    • Mark unique_name in Sim, Fleet, NAP resources as not PII

    Video

    • [Composer] GA maturity level

    Docs

  • 3.62.0 - 2021-05-05

    Release Notes

    Library - Chore

    Api

    • Corrected the data types for feedback summary fields (breaking change)
    • Update the conference participant create from and to param to be endpoint type for supporting client identifier and sip address

    Bulkexports

    • promoting API maturity to GA

    Events

    • Add endpoint to update description in sink
    • Remove beta-feature account flag

    Messaging

    • Update status field in us_app_to_person api to campaign_status (breaking change)

    Verify

    • Improve documentation regarding push factor and include extra information about totp factor.

    Docs

  • 3.61.0 - 2021-04-21

    Release Notes

    Library - Fix

    Api

    • Revert Update the conference participant create from and to param to be endpoint type for supporting client identifier and sip address
    • Update the conference participant create from and to param to be endpoint type for supporting client identifier and sip address

    Bulkexports

    • moving enum to doc root for auto generating documentation
    • adding status enum and default output properties

    Events

    • Change schema_versions prop and key to versions (breaking change)

    Messaging

    • Add use_inbound_webhook_on_number field in Service API for fetch, create, update, read

    Taskrouter

    • Add If-Match Header based on ETag for Task Delete

    Verify

    • Add AuthPayload parameter to support verifying a Challenge upon creation. This is only supported for totp factors.
    • Add support to resend the notifications of a Challenge. This is only supported for push factors.

    Twiml

    • Add Polly Neural voices.

    Docs

  • 3.60.0 - 2021-04-07

    Release Notes

    Library - Chore

    Api

    • Added announcement event to conference status callback events
    • Removed optional property time_limit in the call create request. (breaking change)

    Messaging

    • Add rate_limits field to Messaging Services US App To Person API
    • Add usecase field in Service API for fetch, create, update, read
    • Add us app to person api and us app to person usecase api as dependents in service
    • Add us_app_to_person_registered field in service api for fetch, read, create, update
    • Add us app to person api
    • Add us app to person usecase api
    • Add A2P external campaign api
    • Add Usecases API

    Supersim

    • Add Create endpoint to Sims resource

    Verify

    • The Binding field is now returned when creating a Factor. This value won't be returned for other endpoints.

    Video

    • [Rooms] max_concurrent_published_tracks has got GA maturity

    Twiml

    • Add announcement event to statusCallbackEvent for <Conference>.

    Docs

  • 3.59.0 - 2021-03-24
  • 3.58.0 - 2021-03-15
  • 3.57.0 - 2021-02-24
  • 3.56.0 - 2021-02-10
  • 3.55.1 - 2021-01-27
from twilio GitHub release notes
Commit messages
Package name: twilio
  • 76cc8da Release 3.66.0
  • 5966227 [Librarian] Regenerated @ 7987bc34448d66e36aaa4f7174e25f3d57ccccef
  • 1af382d Release 3.65.0
  • 68ec830 [Librarian] Regenerated @ 4e75c7be2507558854a659be2e05b171bcf7512b
  • 043dd65 chore: add docker credentials to travis
  • 624e804 Release 3.64.0
  • 7fb0be8 [Librarian] Regenerated @ e1d98e904674be752473dcb1f0e54c720a5d0754
  • dcfd1fa chore: bump lodash and eslint per npm audit (#677)
  • e2a83c1 update slack on change from build success to fail
  • 3618278 always notify on failure
  • 51c08a7 update slack token
  • aceecf5 Release 3.63.1
  • ad05e72 [Librarian] Regenerated @ ace337a1be26cdd69f455a9a0f82789cd255d3a1
  • 2b5365b fix: remove @ type/express (#675)
  • 1ecd18f Release 3.63.0
  • c827ef8 [Librarian] Regenerated @ 277e53a232b830747a98a7b463b89f7d9a99ce03
  • 6986ba9 chore: resolves jsdoc / underscore security vulnerability (#673)
  • 8b91200 Release 3.62.0
  • b9af8d0 [Librarian] Regenerated @ c95de69ef589811189089c789616f1b139c1ae3e
  • e800898 chore: integrate with SonarCloud (#672)
  • e088d33 chore: update slack notification token
  • fb827cb Release 3.61.0
  • a642d8c [Librarian] Regenerated @ 13a590a5017846bb40a46a0722d90a15ca591b2d
  • 0018eca fix: remove type definition from peerDeps (#667)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant