Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade knex from 0.14.4 to 0.95.15 #49

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade knex from 0.14.4 to 0.95.15.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 111 versions ahead of your current version.
  • The recommended version was released 3 months ago, on 2021-12-21.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
375/1000
Why? CVSS 7.5
No Known Exploit
Prototype Pollution
SNYK-JS-MINIMIST-559764
375/1000
Why? CVSS 7.5
Proof of Concept
SQL Injection
SNYK-JS-KNEX-471962
375/1000
Why? CVSS 7.5
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: knex
  • 0.95.15 - 2021-12-21
  • 0.95.14 - 2021-11-08

    0.95.14 - 09 November, 2021

    Bug fixes:

    • MySQL: mysql2 dialect validate connection fix #4794

    0.95.13 - 02 November, 2021

    Bug fixes:

    • PostgreSQL: Support zero precision in timestamp/datetime #4784

    Typings:

    • Allow string indexType in index creation #4791
  • 0.95.13 - 2021-11-02
  • 0.95.12 - 2021-10-27

    0.95.12 - 28 October, 2021

    New features:

    • New dialect: CockroachDB #4742
    • New dialect: pg-native #4327
    • CockroachDB: add support for upsert #4767
    • PostgreSQL: Support SELECT .. FOR NO KEY UPDATE / KEY SHARE row level locking clauses #4755
    • PostgreSQL: Add support for 'CASCADE' in PostgreSQL 'DROP SCHEMA' queries #4713
    • MySQL: Add storage engine index Type support to index() and unique() schema #4756
    • MSSQL: Support table.primary, table.unique variant with options object #4710
    • SQLite: Add setNullable support to SQLite #4684
    • Add geometry column building #4776
    • Add support for creating table copies #1373
    • Implement support for views and materialized views #1626
    • Implement partial index support #4768
    • Support for 'is null' in 'order by' #3667

    Bug fixes:

    • Fix support for Oracle connections passed via knex.connection() #4757
    • Avoid inserting multiple locks if a migration lock already exists #4694

    Typings:

    • Some TableBuilder methods return wrong types #4764
    • Update JoinRaw bindings type to accept arrays #4752
    • fix onDelete/onUpdate for ColumnBuilder #4656
  • 0.95.12-rc6 - 2021-10-27
  • 0.95.12-rc5 - 2021-10-25
  • 0.95.12-rc4 - 2021-10-20
  • 0.95.12-rc3 - 2021-10-16
  • 0.95.12-rc2 - 2021-10-15
  • 0.95.12-rc1 - 2021-10-15
  • 0.95.11 - 2021-09-03

    0.95.11 - 03 September, 2021

    New features:

    • Add support for nullability modification via schema builder (table.setNullable() and table.dropNullable()) #4657
    • MySQL: Add support for mysql/mariadb-client JSON parameters in connectionURIs #4629
    • MSSQL: Support comments as MS_Description properties #4632

    Bug fixes:

    • Fix Analytic orderBy and partitionBy to follow the SQL documentation #4602
    • CLI: fix migrate:up for migrations disabling transactions #4550
    • SQLite: Fix adding a column with a foreign key constraint in SQLite #4649
    • MSSQL: columnInfo() support case-sensitive database collations #4633
    • MSSQL: Generate valid SQL for withRecursive() #4514
    • Oracle: withRecursive: omit invalid RECURSIVE keyword, include column list #4514

    Improvements:

    • Add .mjs migration and seed stubs #4631
    • SQLite: Clean up DDL handling and move all operations to the parser-based approach #4648
  • 0.95.10 - 2021-08-20

    Improvements:

    • Use sys info function instead of connection db name #4623

    Typings:

    • Deferrable and withkeyName should not be in ColumnBuilder #4600
    • Add TypeScript support for deferrable, new Primary/Unique syntax #4589

    New features:

    • Oracle: support specifying schema for dropTable and dropSequence #4596
    • Oracle: support specifying schema for autoincrement #4594
  • 0.95.9 - 2021-07-31
  • 0.95.8 - 2021-07-25

    New features:

    • Add deferrable support for constraint #4584
    • Implement delete with join #4568
    • Add DPI error codes for Oracle #4536

    Bug fixes:

    • Fixing PostgreSQL datetime and timestamp column created with wrong format #4578

    Typings:

    • Improve analytic types #4576
    • MSSQL: Add trustServerCertificate option #4500
  • 0.95.7 - 2021-07-10
  • 0.95.6 - 2021-05-17
  • 0.95.5 - 2021-05-11

    New features:

    • SQLite: Add support for file open flags #4446
    • Add .cjs extension to Seeder.js to support Node ESM #4381 #4382

    Bug fixes:

    • Remove peerDependencies to avoid auto-install on npm 7 #4480

    Typings:

    • Fix typing for increments and bigIncrements #4406
    • Add typings for on JoinClause for onVal #4436
    • Adding Type Definition for isTransaction #4418
    • Export client class from knex namespace #4479
  • 0.95.4 - 2021-03-26
  • 0.95.3 - 2021-03-25

    New features:

    • PostgreSQL: Add "same" as operator #4372
    • MSSQL: Improve an estimate of the max comment length #4362
    • Throw an error if negative offset is provided #4361

    Bug fixes:

    • Fix timeout method #4324
    • SQLite: prevent dropForeign from being silently ignored #4376

    Typings:

    • Allow config.client to be non-client instance #4367
    • Add dropForeign arg type for single column #4363
    • Update typings for TypePreservingAggregation and stream #4377
  • 0.95.2 - 2021-03-11
  • 0.95.1 - 2021-03-04
  • 0.95.0 - 2021-03-03
  • 0.95.0-next3 - 2021-02-18
  • 0.95.0-next2 - 2021-02-15
  • 0.95.0-next1 - 2021-02-08
  • 0.21.21 - 2021-08-10
  • 0.21.20 - 2021-08-07
  • 0.21.19 - 2021-03-02
  • 0.21.18 - 2021-02-22
  • 0.21.17 - 2021-01-30
  • 0.21.16 - 2021-01-17
  • 0.21.15 - 2020-12-26
  • 0.21.14 - 2020-12-18
  • 0.21.13 - 2020-12-11
  • 0.21.12 - 2020-11-02
  • 0.21.11 - 2020-11-01
  • 0.21.10 - 2020-10-31
  • 0.21.9 - 2020-10-29
  • 0.21.8 - 2020-10-27
  • 0.21.7 - 2020-10-25
  • 0.21.6 - 2020-09-27
  • 0.21.5 - 2020-08-17
  • 0.21.5-next2 - 2020-08-16
  • 0.21.5-next1 - 2020-08-15
  • 0.21.4 - 2020-08-10
  • 0.21.3 - 2020-08-08
  • 0.21.2 - 2020-07-09
  • 0.21.1 - 2020-04-27
  • 0.21.0 - 2020-04-18
  • 0.20.15 - 2020-04-15
  • 0.20.14 - 2020-04-14
  • 0.20.13 - 2020-03-23
  • 0.20.12 - 2020-03-19
  • 0.20.11 - 2020-03-05
  • 0.20.10 - 2020-02-16
  • 0.20.9 - 2020-02-08
  • 0.20.8 - 2020-01-14
  • 0.20.7 - 2020-01-07
  • 0.20.6 - 2019-12-29
  • 0.20.4 - 2019-12-07
  • 0.20.3 - 2019-11-27
  • 0.20.2 - 2019-11-14
  • 0.20.1 - 2019-10-29
  • 0.20.0 - 2019-10-25
  • 0.19.5 - 2019-10-06
  • 0.19.4 - 2019-09-09
  • 0.19.3 - 2019-08-28
  • 0.19.2 - 2019-08-17
  • 0.19.1 - 2019-07-23
  • 0.19.0 - 2019-07-11
  • 0.18.4 - 2019-07-10
  • 0.18.3 - 2019-07-04
  • 0.18.2 - 2019-07-02
  • 0.18.1 - 2019-06-30
  • 0.18.0 - 2019-06-26
  • 0.18.0-next4 - 2019-06-23
  • 0.18.0-next2 - 2019-06-19
  • 0.18.0-next1 - 2019-06-17
  • 0.17.6 - 2019-06-13
  • 0.17.5 - 2019-06-08
  • 0.17.4 - 2019-06-08
  • 0.17.3 - 2019-06-02
  • 0.17.2 - 2019-06-01
  • 0.17.1 - 2019-05-31
  • 0.17.1-next - 2019-05-30
  • 0.17.0 - 2019-05-28
  • 0.17.0-next6 - 2019-05-27
  • 0.17.0-next5 - 2019-05-22
  • 0.17.0-next4 - 2019-05-19
  • 0.17.0-next2 - 2019-05-16
  • 0.17.0-next - 2019-05-13
  • 0.16.6-oracle-fix - 2019-04-12
  • 0.16.5 - 2019-04-11
  • 0.16.4 - 2019-04-11
  • 0.16.4-next2 - 2019-03-13
  • 0.16.4-next1 - 2019-01-31
  • 0.16.3 - 2018-12-19
  • 0.16.2 - 2018-12-10
  • 0.16.1 - 2018-12-09
  • 0.16.1-next2 - 2018-12-05
  • 0.16.1-next1 - 2018-12-03
  • 0.16.0-next5 - 2018-11-23
  • 0.16.0-next4 - 2018-11-21
  • 0.16.0-next3 - 2018-09-26
  • 0.16.0-next2 - 2018-09-26
  • 0.16.0-next1 - 2018-09-18
  • 0.15.2 - 2018-07-19
  • 0.15.1 - 2018-07-13
  • 0.15.0 - 2018-07-01
  • 0.14.6 - 2018-04-12
  • 0.14.5 - 2018-04-08
  • 0.14.4 - 2018-02-19
from knex GitHub release notes
Commit messages
Package name: knex
  • 380cebe Prepare to release 0.95.15
  • 6ef4645 Insert lock row fix during migration (#4865)
  • 54934ba Prepare to release 0.95.14
  • 337178f Mysql2 validate connection fix #4794 (#4812)
  • 29ac476 Prepare to release 0.95.13
  • 0f4356a Allow string indexType in index creation (#4791) (#4792)
  • 4e2bbe8 Zero precision in timestamp/datetime #4784 (#4788)
  • 89d3c69 Prepare to release 0.95.12
  • 63dbd65 Prepare to release 0.95.12-rc6
  • 50cfa5f Add geometry column building (#4776)
  • 994cbcb Bump typescript from 4.4.3 to 4.4.4 (#4731)
  • 3331e38 Bump tsd from 0.17.0 to 0.18.0 (#4732)
  • 336691f Prepare to release rc5
  • ace439d Implement partial index support (#4768)
  • 821e849 Merge remote-tracking branch 'origin/master'
  • f49b093 Bump dtslint from 4.1.6 to 4.2.0 (#4763)
  • ac5a619 Move migration tests to integration2
  • 33cea90 Try to fix coverage task
  • 6840d3f feat(cockroachdb): add support upsert (#4767)
  • a17cc32 Support SELECT .. FOR NO KEY UPDATE / KEY SHARE row level locking clauses in Postgres (#4755)
  • 58de7a9 fix(typings): table builder some methods return wrong types (#4764)
  • e991090 Bump eslint from 7.32.0 to 8.0.1 (#4736)
  • d463284 Add storage engine index Type support to MySQL index() and unique() schema (#4756)
  • 792d3be Bump version to rc4

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant