[Snyk] Upgrade mongodb from 5.5.0 to 5.9.2 #413
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade mongodb from 5.5.0 to 5.9.2.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-MONGODB-5871303
Why? Has a fix available, CVSS 4.2
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: mongodb
5.9.2 (2023-11-16)
The MongoDB Node.js team is pleased to announce version 5.9.2 of the
mongodb
package!Release Notes
Fix connection leak when serverApi is enabled
When enabling serverApi the driver's RTT mesurment logic (used to determine the closest node) still sent the legacy hello command "isMaster" causing the server to return an error. Unfortunately, the error handling logic did not correctly destroy the socket which would cause a leak.
Both sending the correct hello command and the error handling connection clean up logic are fixed in this change.
Bug Fixes
Documentation
We invite you to try the
mongodb
library immediately, and report any issues to the NODE project.5.9.1 (2023-10-18)
The MongoDB Node.js team is pleased to announce version 5.9.1 of the
mongodb
package!Release Notes
insertedIds
in bulk write now contain only successful insertionsPrior to this fix, the bulk write error's
result.insertedIds
property contained the_id
of each attempted insert in a bulk operation.Now, when a
bulkwrite()
or aninsertMany()
operation rejects one or more inserts, throwing an error, the error'sresult.insertedIds
property will only contain the_id
fields of successfully inserted documents.Fixed edge case leak in
findOne()
When running a
findOne
against a time series collection, the driver left the implicit session for the cursor un-ended due to the way the server returns the resulting cursor information. Now the cursor will always be cleaned up regardless of the outcome of the find operation.Bug Fixes
Documentation
We invite you to try the
mongodb
library immediately, and report any issues to the NODE project.Commit messages
Package name: mongodb
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs