forked from snyk-labs/nodejs-goof
-
Notifications
You must be signed in to change notification settings - Fork 3
Pull requests: COG-GTM/nodejs-goof
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Fix NoSQL/SQL injection, prototype pollution and vulnerable dependencies
#283
opened Sep 14, 2026 by
devin-ai-integration
Bot
Loading…
fix: [ejs] Upgrade ejs from 1.0.0 to 3.1.10 to resolve CVE-2022-29078
#282
opened Sep 14, 2026 by
hannahhuh-cog
Loading…
fix: [form-data] Upgrade form-data from 2.3.3 to 2.5.4 to resolve CVE-2025-7783
#281
opened Sep 14, 2026 by
hannahhuh-cog
Loading…
fix: [sha.js] Upgrade sha.js from 2.4.11 to 2.4.12 to resolve CVE-2025-9288
#280
opened Sep 14, 2026 by
hannahhuh-cog
Loading…
fix: [hbs] Upgrade hbs from 4.0.4 to 4.3.0 (handlebars 4.0.14 to 4.7.9) to resolve CVE-2026-33938
#279
opened Sep 14, 2026 by
hannahhuh-cog
Loading…
fix: [adm-zip] Upgrade adm-zip from 0.4.7 to 0.5.18 to resolve CVE-2018-1002204
#278
opened Sep 14, 2026 by
hannahhuh-cog
Loading…
fix(security): remediate jssecurity:S5147 NoSQL injection in routes/index.js loginHandler (SonarQube AZhSVLrd4wErqc9Ey1Y3)
#277
opened Sep 11, 2026 by
devin-ai-integration
Bot
Loading…
fix(S5146): remediate SonarQube AZhSVLrd4wErqc9Ey1Y4 - validate admin login redirect target
#276
opened Sep 11, 2026 by
devin-ai-integration
Bot
Loading…
fix(deps): pin transitive elliptic to ^6.6.1 via npm override — CVE-2024-48948 (ECDSA signature verification bypass)
#275
opened Sep 10, 2026 by
devin-ai-integration
Bot
Loading…
fix(deps): upgrade snyk devDependency to ^1.1307.0 to remove parse-url 5.0.1 — CVE-2022-2216 (SSRF)
#274
opened Sep 10, 2026 by
devin-ai-integration
Bot
Loading…
fix(deps): upgrade tap to ^18.8.0 to remove form-data 2.3.3 — CVE-2025-7783 (predictable multipart boundary)
#273
opened Sep 10, 2026 by
devin-ai-integration
Bot
Loading…
fix(deps): upgrade adm-zip 0.4.7 → 0.5.18 — Zip Slip arbitrary file write CVE-2018-1002204
#272
opened Sep 10, 2026 by
devin-ai-integration
Bot
Loading…
fix(deps): upgrade hbs to ^4.2.1 — handlebars Prototype Pollution SNYK-JS-HANDLEBARS-534988 (+ CVE-2026-33937/33938/33940)
#271
opened Sep 10, 2026 by
devin-ai-integration
Bot
Loading…
fix: [npm] Upgrade form-data from 2.3.3 to 2.5.5 to resolve CVE-2025-7783
#270
opened Sep 7, 2026 by
hannahhuh-cog
Loading…
fix: [npm] Upgrade sha.js from 2.4.11 to 2.4.12 to resolve CVE-2025-9288
#269
opened Sep 7, 2026 by
hannahhuh-cog
Loading…
fix: [npm] Upgrade typeorm from 0.2.24 to 0.2.25 to resolve CVE-2020-8158
#268
opened Sep 7, 2026 by
hannahhuh-cog
Loading…
fix: [npm] Upgrade hbs from 4.0.4 to 4.3.0 (handlebars 4.0.14 → 4.7.9) to resolve CVE-2026-33938
#267
opened Sep 7, 2026 by
hannahhuh-cog
Loading…
fix: [npm] Upgrade adm-zip from 0.4.7 to 0.5.18 to resolve CVE-2018-1002204
#266
opened Sep 7, 2026 by
hannahhuh-cog
Loading…
bug: upgrade Dockerfile base image to node:18.20.5-alpine3.19 (CVE-2024-5171)
#262
opened Sep 1, 2026 by
Shubhrakanti
Loading…
bug: fix SNYK-DEBIAN11-LIBXML2-10350669 (CVE-2025-49796) by moving the Docker base image to node:22.23.2-bookworm
#261
opened Sep 1, 2026 by
devin-ai-integration
Bot
Loading…
bug: move Dockerfile base image to node:22.23.2-bookworm (fixes imagemagick CVE-2026-25987)
#260
opened Sep 1, 2026 by
devin-ai-integration
Bot
Loading…
bug: move Docker base image to node:22.23.2-bookworm (libxml2 CVE-2025-49794)
#259
opened Sep 1, 2026 by
devin-ai-integration
Bot
Loading…
bug: bump Docker base image to node:22.23.2-trixie (zlib CVE-2023-45853)
#258
opened Sep 1, 2026 by
devin-ai-integration
Bot
Loading…
bug: move Docker base image off node:18.13.0 (openexr CVE-2026-42217)
#257
opened Sep 1, 2026 by
devin-ai-integration
Bot
Loading…
bug: upgrade Docker base image to node:22.23.2-bookworm (CVE-2025-55131)
#256
opened Sep 1, 2026 by
devin-ai-integration
Bot
Loading…
Previous Next
ProTip!
Exclude everything labeled
bug with -label:bug.