Update dependency mongodb to v4.17.0 [SECURITY]#1384
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
Update dependency mongodb to v4.17.0 [SECURITY]#1384renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
8f6e8e8 to
2815e14
Compare
7842605 to
295f28b
Compare
fa8e862 to
7979c37
Compare
7979c37 to
948d2e1
Compare
948d2e1 to
331643d
Compare
331643d to
cf82452
Compare
cf82452 to
a179498
Compare
68dbd37 to
633488a
Compare
633488a to
2ef5666
Compare
2ef5666 to
d6b0e61
Compare
b78e5be to
64e1a7e
Compare
64e1a7e to
9ec4851
Compare
9ec4851 to
e2456ad
Compare
e2456ad to
ddcf6e9
Compare
ddcf6e9 to
0dc31ac
Compare
0dc31ac to
eadde7d
Compare
eadde7d to
bd9e75e
Compare
bd9e75e to
9ac1f93
Compare
9ac1f93 to
139b624
Compare
139b624 to
d611bd7
Compare
4a69545 to
b1a13ce
Compare
b1a13ce to
f1c6a15
Compare
f1c6a15 to
2d38e5e
Compare
2d38e5e to
1baedb6
Compare
1baedb6 to
fdd324e
Compare
74f41d5 to
e00bb32
Compare
e00bb32 to
1aab0ca
Compare
1aab0ca to
893c8af
Compare
c8d0be8 to
d4c767f
Compare
d4c767f to
669f895
Compare
669f895 to
5d2df14
Compare
5d2df14 to
c10cde5
Compare
c10cde5 to
a602404
Compare
a602404 to
fe0b07b
Compare
fe0b07b to
443c491
Compare
443c491 to
11f1420
Compare
11f1420 to
8e544db
Compare
8e544db to
df48b45
Compare
44b821e to
25ec934
Compare
25ec934 to
cd2ff55
Compare
8c95c85 to
d85db90
Compare
d85db90 to
ae8874a
Compare
ae8874a to
f6e6bfa
Compare
f6e6bfa to
0da88d0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.3.0→4.17.0GitHub Vulnerability Alerts
CVE-2021-32050
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.
Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).
This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).
Release Notes
mongodb/node-mongodb-native (mongodb)
v4.17.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.17.0 of the
mongodbpackage!Release Notes
mongodb-js/saslprepis now installed by defaultUntil v6, the driver included the
saslpreppackage as an optional dependency for SCRAM-SHA-256 authentication.saslprepbreaks when bundled with webpack because it attempted to read a file relative to the package location and consequently the driver would throw errors when using SCRAM-SHA-256 if it were bundled.The driver now depends on
mongodb-js/saslprep, a fork ofsaslprepthat can be bundled with webpack because it includes the necessary saslprep data in memory upon loading. This will be installed by default but will only be used if SCRAM-SHA-256 authentication is used.Remove credential availability on
ConnectionPoolCreatedEventIn order to avoid mistakenly printing credentials the
ConnectionPoolCreatedEventwill replace the credentials option with an empty object. The credentials are still accessble via MongoClient options:client.options.credentials.Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.16.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.16.0 of the
mongodbpackage!Features
Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v4.15.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.15.0 of the mongodb package!
Features
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.14.0Compare Source
The MongoDB Node.js team is pleased to announce version 4.14.0 of the mongodb package!
Deprecations
Bug Fixes
Documentation
We invite you to try the mongodb library immediately, and report any issues to the NODE project.
v4.13.0Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.12.1Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.12.0Compare Source
Features
Bug Fixes
4.12.1 (2022-11-23)
Bug Fixes
v4.11.0Compare Source
Features
Bug Fixes
v4.10.0Compare Source
Features
Bug Fixes
v4.9.1Compare Source
The MongoDB Node.js team is pleased to announce version 4.9.1 of the mongodb package!
Release Highlights
This is a bug fix release as noted below.
Bug Fixes
v4.9.0Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.8.1Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.8.0Compare Source
Features
Bug Fixes
oplogReplayoption as deprecated (#3337) (6c69b7d)4.8.1 (2022-07-26)
Bug Fixes
v4.7.0Compare Source
Features
Bug Fixes
v4.6.0Compare Source
Features
Bug Fixes
v4.5.0Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.4.1Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.4.0Compare Source
Features
commentfield (#3167) (4e2f9bf)Bug Fixes
watchtype parameter to extendChangeStreamtype parameter (#3183) (43ba9fc)4.4.1 (2022-03-03)
Features
Bug Fixes
v4.3.1Compare Source
Features
Bug Fixes
4.3.1 (2022-01-18)
Bug Fixes
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.