fix(deps): update dependency @google-cloud/firestore to v6 [security]#429
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency @google-cloud/firestore to v6 [security]#429renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
54f8bf7 to
217c07f
Compare
217c07f to
0c4f374
Compare
0c4f374 to
76e4164
Compare
76e4164 to
0d196fe
Compare
0d196fe to
0752c4f
Compare
0752c4f to
bbc370a
Compare
bbc370a to
d64ca15
Compare
d64ca15 to
59c5ebf
Compare
59c5ebf to
9bf7a0e
Compare
9bf7a0e to
f045d61
Compare
6f61eaf to
310f99e
Compare
310f99e to
658fcfc
Compare
658fcfc to
0069aaf
Compare
0069aaf to
653b4ab
Compare
653b4ab to
c1c389d
Compare
c1c389d to
24a0d6b
Compare
24a0d6b to
5cbcaaf
Compare
5cbcaaf to
f7a7ad6
Compare
f7a7ad6 to
bebe7c7
Compare
bebe7c7 to
7d20dd5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^5.0.0→^6.0.0Logging of the firestore key within nodejs-firestore
CVE-2023-6460 / GHSA-4g6q-77j7-vvjc
More information
Details
A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We recommend upgrading to version 6.1.0 to avoid this issue
Severity
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
googleapis/google-cloud-node (@google-cloud/firestore)
v6.2.0Compare Source
Features
Bug Fixes
v6.0.0Compare Source
⚠ BREAKING CHANGES
Features
Bug Fixes
Build System
5.0.2 (2022-01-07)
Bug Fixes
5.0.1 (2021-12-02)
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.