[Snyk] Security upgrade bullmq from 3.15.8 to 5.3.3 #1183

Closed
opened 2026-04-05 16:25:48 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 2/25/2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • CommonServer/package.json
    • CommonServer/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 631/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.2
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: bullmq The new version differs by 250 commits.
  • e31fe65 chore(release): 5.3.3 [skip ci]
  • 91cf9a9 fix(deps): replaced glob by fast-glob due to security advisory
  • 927d2a5 chore(release): 5.3.2 [skip ci]
  • 7606e36 fix(sandbox): extend SandboxedJob from JobJsonSandbox (#2446) fixes #2439
  • 8f8cb88 test(dragonfly): fix flaky test when getting worker rawnames(#2445)
  • 651d086 chore(release): 5.3.1 [skip ci]
  • 1e9a13f fix(add-job): fix parent job cannot be replaced error message (#2441)
  • 7fc6f91 GITBOOK-192: change request with no subject merged in GitBook
  • bfa1839 chore(release): 5.3.0 [skip ci]
  • 9bf50bc chore(queue-events): add TODO to the comment
  • 7ba2729 feat(worker): add support for naming workers
  • b1432ab GITBOOK-191: change request with no subject merged in GitBook
  • 1a77c16 GITBOOK-190: change request with no subject merged in GitBook
  • 56e578b GITBOOK-189: change request with no subject merged in GitBook
  • 571b417 chore(release): 5.2.1 [skip ci]
  • 8a85207 fix(flow): remove failed children references on auto removal (#2432)
  • 83e8a61 chore(release): 5.2.0 [skip ci]
  • c7559f4 feat(flow): add ignoreDependencyOnFailure option (#2426)
  • 51ef4ae test(flow): do not remove grandparent on regular remove (#2429)
  • 5938664 chore(release): 5.1.12 [skip ci]
  • 1bc26a6 fix(redis-connection): close redis connection even when initializing (#2425) fixes fix backend (#2385)
  • d08cd59 refactor(add-job): remove extra include (#2423)
  • 415f389 docs(guide): fix queueEvents.on failed description (#2420)
  • 4c54873 docs(guide): fix markdown syntax in prioritized jobs (#2421)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

*Originally created by @simlarsen on 2/25/2024* <p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.</h3> #### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - CommonServer/package.json - CommonServer/package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **631/1000** <br/> **Why?** Proof of Concept exploit, Has a fix available, CVSS 6.2 | Missing Release of Resource after Effective Lifetime <br/>[SNYK-JS-INFLIGHT-6095116](https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised. <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>bullmq</b></summary> The new version differs by 250 commits.</br> <ul> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/e31fe65571733e9bce85e3ecdb85f93d0346072c">e31fe65</a> chore(release): 5.3.3 [skip ci]</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/91cf9a9253370ea76df48c27a7e0fcf8d7504c81">91cf9a9</a> fix(deps): replaced glob by fast-glob due to security advisory</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/927d2a5bc08c320b60c8ba0fe38dd04d32aa3771">927d2a5</a> chore(release): 5.3.2 [skip ci]</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/7606e3611f1cc18b1585c08b0f7fd9cb90749c9c">7606e36</a> fix(sandbox): extend SandboxedJob from JobJsonSandbox (#2446) fixes #2439</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/8f8cb88f5c34ace7bcc76f97c7dd97f16a362974">8f8cb88</a> test(dragonfly): fix flaky test when getting worker rawnames(#2445)</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/651d086f41818dd25bd96bdc2c855a9a4b06be13">651d086</a> chore(release): 5.3.1 [skip ci]</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/1e9a13fc0dc9de810ef75a042fbfeeae5b571ffe">1e9a13f</a> fix(add-job): fix parent job cannot be replaced error message (#2441)</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/7fc6f91ccd2be3f2fabc4864bcfcd64fdb0e6986">7fc6f91</a> GITBOOK-192: change request with no subject merged in GitBook</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/bfa18396b4b128a84a99b1ca0e46908cdedad386">bfa1839</a> chore(release): 5.3.0 [skip ci]</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/9bf50bc1af05b49544e8d1b08235355479a7565c">9bf50bc</a> chore(queue-events): add TODO to the comment</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/7ba27293615e443903cfdf7d0ff8be0052d061c4">7ba2729</a> feat(worker): add support for naming workers</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/b1432ab1b494b3377cbb60fc4c847919d32885fe">b1432ab</a> GITBOOK-191: change request with no subject merged in GitBook</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/1a77c169ed1ec96af7c052633510f0148dd19799">1a77c16</a> GITBOOK-190: change request with no subject merged in GitBook</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/56e578be962673e8e5e1f1c4ae65740585af1049">56e578b</a> GITBOOK-189: change request with no subject merged in GitBook</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/571b4172487ee972320d93d81313cd7e88307114">571b417</a> chore(release): 5.2.1 [skip ci]</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/8a85207cf3c552ebab37baca3c395821b9804b37">8a85207</a> fix(flow): remove failed children references on auto removal (#2432)</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/83e8a611b1a758354426244739bcc950e658e1f3">83e8a61</a> chore(release): 5.2.0 [skip ci]</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/c7559f4f0a7fa51764ad43b4f46bb9d55ac42d0d">c7559f4</a> feat(flow): add ignoreDependencyOnFailure option (#2426)</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/51ef4ae19844c29556d1e4c1e35c3a4445cb1dea">51ef4ae</a> test(flow): do not remove grandparent on regular remove (#2429)</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/59386645ebf0d50f96a4d76b1988fc501348dc3e">5938664</a> chore(release): 5.1.12 [skip ci]</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/1bc26a64871b85a2d1f6799a9b73b60f8bf9fa90">1bc26a6</a> fix(redis-connection): close redis connection even when initializing (#2425) fixes #2385</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/d08cd5980e1c4fac4afce79bd46ecf40ecb2cd01">d08cd59</a> refactor(add-job): remove extra include (#2423)</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/415f389e41ae692a6e8c3da90fdb5d58a58985eb">415f389</a> docs(guide): fix queueEvents.on failed description (#2420)</li> <li><a href="https://snyk.io/redirect/github/taskforcesh/bullmq/commit/4c548735d3c2489f2bdc1cfa870703db6f11f752">4c54873</a> docs(guide): fix markdown syntax in prioritized jobs (#2421)</li> </ul> <a href="https://snyk.io/redirect/github/taskforcesh/bullmq/compare/5c36ae318766741a00a07af587255a5e951bd731...e31fe65571733e9bce85e3ecdb85f93d0346072c">See the full diff</a> </details> </details> Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI1MWZmNjZhNy04OGU3LTQzMDAtOGJlMy1jOGRjY2FjZDc2NzUiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjUxZmY2NmE3LTg4ZTctNDMwMC04YmUzLWM4ZGNjYWNkNzY3NSJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/a2fb4fe1-f25f-4ff9-a58c-e78277b0a7fa?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/a2fb4fe1-f25f-4ff9-a58c-e78277b0a7fa?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"51ff66a7-88e7-4300-8be3-c8dccacd7675","prPublicId":"51ff66a7-88e7-4300-8be3-c8dccacd7675","dependencies":[{"name":"bullmq","from":"3.15.8","to":"5.3.3"}],"packageManager":"npm","projectPublicId":"a2fb4fe1-f25f-4ff9-a58c-e78277b0a7fa","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/a2fb4fe1-f25f-4ff9-a58c-e78277b0a7fa?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-INFLIGHT-6095116"],"upgrade":["SNYK-JS-INFLIGHT-6095116"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[631],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc&#x3D;fix-pr)
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#1183