Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade stripe from 10.15.0 to 10.17.0 #556

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

ciaran-finnegan
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to upgrade stripe from 10.15.0 to 10.17.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 4 versions ahead of your current version.

  • The recommended version was released on 2 years ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Directory Traversal
SNYK-JS-ADMZIP-1065796
529 No Known Exploit
high severity Prototype Pollution
SNYK-JS-ASYNC-2441827
529 Proof of Concept
high severity Improper Input Validation
SNYK-JS-FOLLOWREDIRECTS-6141137
529 Proof of Concept
high severity Prototype Pollution
SNYK-JS-ASYNC-2441827
529 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-1579269
529 Proof of Concept
high severity Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
529 No Known Exploit
high severity Improper Input Validation
SNYK-JS-FOLLOWREDIRECTS-6141137
529 Proof of Concept
high severity Prototype Pollution
SNYK-JS-JSONATA-6371513
529 No Known Exploit
high severity Prototype Pollution
SNYK-JS-JSONSCHEMA-1920922
529 No Known Exploit
high severity Directory Traversal
SNYK-JS-MOMENT-2440688
529 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
529 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NORMALIZEURL-1296539
529 No Known Exploit
high severity Prototype Pollution
SNYK-JS-PROTOBUFJS-2441248
529 Proof of Concept
high severity Prototype Pollution
SNYK-JS-PROTOBUFJS-5756498
529 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
529 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ES5EXT-6095076
529 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVERREGEX-1584358
529 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVERREGEX-1585624
529 Proof of Concept
high severity Command Injection
SNYK-JS-SIMPLEGIT-2421199
529 Proof of Concept
high severity Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
SNYK-JS-SIMPLEGIT-2434306
529 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-SIMPLEGIT-3112221
529 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-SIMPLEGIT-3177391
529 Proof of Concept
medium severity Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JS-JSZIP-3188562
529 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
529 Proof of Concept
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2332181
529 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
529 Proof of Concept
medium severity Open Redirect
SNYK-JS-GOT-2932019
529 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
529 Proof of Concept
medium severity Open Redirect
SNYK-JS-GOT-2932019
529 No Known Exploit
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-AXIOS-1038255
529 Proof of Concept
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
529 Proof of Concept
medium severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
529 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-XML2JS-5414874
529 Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JS-JSZIP-1251497
529 Proof of Concept
medium severity Information Exposure
SNYK-JS-NODEFETCH-2342118
529 No Known Exploit
medium severity Information Exposure
SNYK-JS-NODEFETCH-2342118
529 No Known Exploit
medium severity Information Exposure
SNYK-JS-NODEFETCH-2342118
529 No Known Exploit
medium severity Denial of Service
SNYK-JS-NODEFETCH-674311
529 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-RAMDA-1582370
529 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-RAMDA-1582370
529 No Known Exploit
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
529 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVERREGEX-1047770
529 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVERREGEX-2824151
529 Proof of Concept
low severity Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
529 No Known Exploit
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
529 Proof of Concept
critical severity Improper Input Validation
SNYK-JS-SOCKETIOPARSER-3091012
529 No Known Exploit
Release notes
Package name: stripe
  • 10.17.0 - 2022-11-08
    • #1610 API Updates
      • Add support for new values eg_tin, ph_tin, and tr_tin on enums Checkout.Session.customer_details.tax_ids[].type, Invoice.customer_tax_ids[].type, Order.tax_details.tax_ids[].type, and TaxId.type
      • Add support for new values eg_tin, ph_tin, and tr_tin on enums CustomerCreateParams.tax_id_data[].type, InvoiceUpcomingLinesParams.customer_details.tax_ids[].type, InvoiceUpcomingParams.customer_details.tax_ids[].type, OrderCreateParams.tax_details.tax_ids[].type, OrderUpdateParams.tax_details.tax_ids[].type, and TaxIdCreateParams.type
      • Add support for reason_message on Issuing.Authorization.request_history[]
      • Add support for new value webhook_error on enum Issuing.Authorization.request_history[].reason

    See the changelog for more details.

  • 10.16.0 - 2022-11-03
    • #1596 API Updates
      • Add support for on_behalf_of on CheckoutSessionCreateParams.subscription_data, SubscriptionCreateParams, SubscriptionSchedule.default_settings, SubscriptionSchedule.phases[], SubscriptionScheduleCreateParams.default_settings, SubscriptionScheduleCreateParams.phases[], SubscriptionScheduleUpdateParams.default_settings, SubscriptionScheduleUpdateParams.phases[], SubscriptionUpdateParams, and Subscription
      • Add support for tax_behavior and tax_code on InvoiceItemCreateParams, InvoiceItemUpdateParams, InvoiceUpcomingLinesParams.invoice_items[], and InvoiceUpcomingParams.invoice_items[]

    See the changelog for more details.

  • 10.16.0-beta.2 - 2022-11-02
    • #1598 API Updates for beta branch
      • Updated beta APIs to the latest stable version
      • Add support for cashappPayments and zipPayments on Account.
      • Add support for cashapp and zip on Charge, PaymentMethod.
      • Add support for trialSettings on SubscriptionSchedule.

    See the changelog for more details.

  • 10.16.0-beta.1 - 2022-10-22
    • #1589 API Updates for beta branch
      • Updated stable APIs to the latest version
      • Add support for new value revoked on enum CapitalFinancingOfferListParams.status
      • Add support for paypal on Charge.payment_method_details and Source
      • Add support for network_data on Issuing.Transaction
      • Add support for new value paypal on enum Source.type
      • Add support for billing_cycle_anchor on SubscriptionScheduleAmendParams.amendments[]

    See the changelog for more details.

  • 10.15.0 - 2022-10-20
    • #1588 API Updates
      • Add support for new values jp_trn and ke_pin on enums Checkout.Session.customer_details.tax_ids[].type, Invoice.customer_tax_ids[].type, Order.tax_details.tax_ids[].type, and TaxId.type
      • Add support for new values jp_trn and ke_pin on enums CustomerCreateParams.tax_id_data[].type, InvoiceUpcomingLinesParams.customer_details.tax_ids[].type, InvoiceUpcomingParams.customer_details.tax_ids[].type, OrderCreateParams.tax_details.tax_ids[].type, OrderUpdateParams.tax_details.tax_ids[].type, and TaxIdCreateParams.type
      • Add support for tipping on Terminal.Reader.action.process_payment_intent.process_config and TerminalReaderProcessPaymentIntentParams.process_config
    • #1585 use native UUID method if available

    See the changelog for more details.

from stripe GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade stripe from 10.15.0 to 10.17.0.

See this package in npm:
stripe

See this project in Snyk:
https://app.snyk.io/org/slartibastfast/project/f6a4ab73-335c-4fc2-9f5c-19adde11595f?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants