Skip to content

Update dependency typeorm to v0.3.0 [SECURITY]#709

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-typeorm-vulnerability
Open

Update dependency typeorm to v0.3.0 [SECURITY]#709
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-typeorm-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate bot commented Mar 21, 2024

This PR contains the following updates:

Package Change Age Confidence
typeorm (source) 0.2.410.3.0 age confidence

GitHub Vulnerability Alerts

CVE-2022-33171

The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validation.


Release Notes

typeorm/typeorm (typeorm)

v0.3.0

Compare Source

Bug Fixes
Features
Reverts

v0.2.45

Compare Source

Bug Fixes
Features

v0.2.44

Compare Source

Bug Fixes
Features

v0.2.43

Compare Source

Bug Fixes
  • support require to internal files without explicitly writing .js in the path (#​8660) (96aed8a), closes #​8656
Features
Reverts

v0.2.42

Compare Source

Bug Fixes
Features
Reverts
BREAKING CHANGES
  • update listeners and subscriber no longer triggered by soft-remove and recover

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 353df77 to 25fc518 Compare August 10, 2025 13:45
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 25fc518 to 80f081a Compare September 2, 2025 23:15
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 80f081a to ae35a7a Compare September 25, 2025 14:29
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from ae35a7a to 3be93f0 Compare January 19, 2026 15:44
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch from 3be93f0 to 7133b17 Compare March 5, 2026 19:52
@renovate renovate bot changed the title Update dependency typeorm to v0.3.0 [SECURITY] Update dependency typeorm to v0.3.0 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate bot closed this Mar 27, 2026
@renovate renovate bot deleted the renovate/npm-typeorm-vulnerability branch March 27, 2026 01:32
@renovate renovate bot changed the title Update dependency typeorm to v0.3.0 [SECURITY] - autoclosed Update dependency typeorm to v0.3.0 [SECURITY] Mar 30, 2026
@renovate renovate bot reopened this Mar 30, 2026
@renovate renovate bot force-pushed the renovate/npm-typeorm-vulnerability branch 2 times, most recently from 7133b17 to cf4bd92 Compare March 30, 2026 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants