Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Bump sequelize-cli from 2.8.0 to 5.5.0 #103

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot-preview[bot]
Copy link

@dependabot-preview dependabot-preview bot commented Sep 4, 2020

Bumps sequelize-cli from 2.8.0 to 5.5.0. This update includes a security fix.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

Sensitive Data Exposure in sequelize-cli Versions of sequelize-cli prior to 5.5.0 are vulnerable to Sensitive Data Exposure. The function filteredURL() does not properly sanitize the config.password value which may cause passwords with special characters to be logged in plain text.

Recommendation

Upgrade to version 5.5.0 or later.

Affected versions: <= 5.4.0

Release notes

Sourced from sequelize-cli's releases.

v4.0.0

Changed

  • Removed warning about v4
  • Support for v4 #620 #441

v3.2.0

Fixed

  • Better messages when files/folders already exists #569
  • Specify ARRAY type with model:create #155

Changed

  • Revert: safer configuration using environment variables for production #594

v3.1.0

Fixed

  • Pass full config to sequelize constructor #584

Added

  • db:migrate support for from / to arguments #581

Changed

  • Safer configuration using environment variables for production #579

  • Updated dependencies

v3.0.0

Fixed

  • db:create/drop should properly quote database name #545

Added

  • --debug support, print full stack for errors, when available #552

Changed

  • All errors are now properly formatted and outputted to console.error #552

Internal

  • Refactor to use centralized log/error/warn methods #552

v3.0.0-3

Fixed

  • Error when creating nested config path #534

Added

  • db:create and db:drop for MySQL, Postgres and MSSQL #70

v3.0.0-2

Fixed

  • .sequelizerc is not properly read #536

v3.0.0-1

Changelog

Sourced from sequelize-cli's changelog.

v5.5.0 - 11th, June 2019

Fixed

  • fix: special characters in password are not escaped #722
  • change: default config for operator aliases #743

v5.4.0 - 1st, Dec 2018

Fixed

  • fix: show commands with --help #719

v5.3.0 - 4th, Nov 2018

Fixed

  • fix(db:create): syntax errors with mssql create statement #711
  • style: grammar mistake in seeder skeleton #705

Feature

  • feat(mode:generate) add enum support #704

v5.2.0 - 20th, Oct 2018

Feature

  • feat(db:create): support options on db:create with sequelize@4 #700

v5.1.0 - 14th, Oct 2018

Feature

  • feat(postgres): migrationStorageTableSchema #635

v5.0.0 - 13th, Oct 2018

Fixed

  • fix(init): relative config path for windows #648
  • fix(mode:generate): use force arg correctly #691
  • updated dependencies

Breaking

  • Node 6 or up is supported

v4.1.0 - 19th, Aug 2018

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [sequelize-cli](https://github.com/sequelize/cli) from 2.8.0 to 5.5.0. **This update includes a security fix.**
- [Release notes](https://github.com/sequelize/cli/releases)
- [Changelog](https://github.com/sequelize/cli/blob/master/CHANGELOG.md)
- [Commits](sequelize/cli@v2.8.0...v5.5.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Sep 4, 2020
@dependabot-preview
Copy link
Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
0 participants