Update dependency mongodb to v4 [SECURITY] - autoclosed#271
Closed
renovate[bot] wants to merge 1 commit intomainfrom
Closed
Update dependency mongodb to v4 [SECURITY] - autoclosed#271renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
95c8784 to
2189523
Compare
2189523 to
d7abee6
Compare
d7abee6 to
ab769bc
Compare
ab769bc to
5fa041f
Compare
5fa041f to
c5b8ea5
Compare
c5b8ea5 to
fa847ef
Compare
fa847ef to
b51e4d9
Compare
7d481c2 to
890c9e5
Compare
890c9e5 to
87478f4
Compare
234d498 to
d5889ff
Compare
d5889ff to
e497a6d
Compare
e497a6d to
1bb9fad
Compare
1bb9fad to
f96dd5d
Compare
f96dd5d to
6fcb602
Compare
392b07f to
3c4c731
Compare
3c4c731 to
cddb6f7
Compare
8fc2003 to
7453faf
Compare
7453faf to
0901e5c
Compare
0901e5c to
8a358c8
Compare
8a358c8 to
f7299aa
Compare
f7299aa to
cf4398c
Compare
cf4398c to
86ad3f5
Compare
86ad3f5 to
806b4b3
Compare
806b4b3 to
bf5c50d
Compare
bf5c50d to
2938d5e
Compare
2938d5e to
b552e05
Compare
b552e05 to
6d29065
Compare
6d29065 to
b5b8c68
Compare
b5b8c68 to
3a9fa38
Compare
3a9fa38 to
e2235b6
Compare
e2235b6 to
997f3f9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^3.6.0→^4.17.0^3.5.9→^4.17.0GitHub Vulnerability Alerts
CVE-2021-32050
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.
Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).
This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).
Release Notes
mongodb/node-mongodb-native (mongodb)
v4.17.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.17.0 of the
mongodbpackage!Release Notes
mongodb-js/saslprepis now installed by defaultUntil v6, the driver included the
saslpreppackage as an optional dependency for SCRAM-SHA-256 authentication.saslprepbreaks when bundled with webpack because it attempted to read a file relative to the package location and consequently the driver would throw errors when using SCRAM-SHA-256 if it were bundled.The driver now depends on
mongodb-js/saslprep, a fork ofsaslprepthat can be bundled with webpack because it includes the necessary saslprep data in memory upon loading. This will be installed by default but will only be used if SCRAM-SHA-256 authentication is used.Remove credential availability on
ConnectionPoolCreatedEventIn order to avoid mistakenly printing credentials the
ConnectionPoolCreatedEventwill replace the credentials option with an empty object. The credentials are still accessble via MongoClient options:client.options.credentials.Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.16.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.16.0 of the
mongodbpackage!Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.15.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.15.0 of the mongodb package!
Features
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.14.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.14.0 of the mongodb package!
Deprecations
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.13.0Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.12.1Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.12.0Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.11.0Compare Source
Features
Bug Fixes
v4.10.0Compare Source
Features
Bug Fixes
v4.9.1Compare Source
The MongoDB Node.js team is pleased to announce version 4.9.1 of the mongodb package!
Release Highlights
This is a bug fix release as noted below.
Bug Fixes
v4.9.0Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.8.1Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.8.0Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.7.0Compare Source
Features
Bug Fixes
v4.6.0Compare Source
Features
Bug Fixes
v4.5.0Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.4.1Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.4.0Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.3.1Compare Source
Features
Bug Fixes
4.3.1 (2022-01-18)
Bug Fixes
v4.3.0Compare Source
Features