Skip to content

[Snyk] Security upgrade applicationinsights from 2.1.4 to 2.4.0#80

Open
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-58936d84b12fd942e5fc386a57387a3f
Open

[Snyk] Security upgrade applicationinsights from 2.1.4 to 2.4.0#80
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-58936d84b12fd942e5fc386a57387a3f

Conversation

@snyk-bot
Copy link
Copy Markdown
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Prototype Pollution
SNYK-JS-XML2JS-5414874
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: applicationinsights The new version differs by 137 commits.
  • dd7c195 2.4.0 release (#1060)
  • 2617f05 Update automatic creation of incoming request in Azure functions config (#1059)
  • c59867a Add Azure Functions correlation properties (#1047)
  • f20cea0 Update readme to reflect support for node.js 17 and 18 (#1056)
  • 8d2fbfe Update unsecure dependencies (#1057)
  • b6dfcb8 Add Azure Functions Agent initialization (#1048)
  • a4b6f71 Fixing issue with status in auto generated request in Azure Fn (#1046)
  • 9909cbd Automatically handle request/dependency correlation in Azure Functions (#1044)
  • 39213a3 Address Negative Average Duration (#1039)
  • 358fbce Migrate from @ azure/core-http to @ azure/core-rest-pipeline (#1040)
  • 2f626c2 Remove deprecated URL in readme (#1035)
  • 5e1cbcb Add beta reference in README (#1034)
  • cf5a142 2.3.6 release (#1030)
  • 7314a97 Update the comment for the default DistributedTracingModes to be accurate (#1027)
  • 5b7f145 Avoid duplication of telemetry when abort event is triggered (#1026)
  • 9c9e0b3 File write error handling (#1024)
  • 4c65638 [Task]15209420: add web snippet prefix and config (#1012)
  • 34a9932 add prefix class (#1020)
  • cb09875 Release 2.3.5 (#1011)
  • 225fad5 Add statusCode and exceptionType Fields to Network Statsbeat (#1007)
  • b5317d4 Add msgId property in Diagnostic Logs (#1010)
  • c507448 Add error when ikey/connection string not present in TelemetryClient (#1008)
  • ab79844 Only retry errors if 429, 500 or 503 response codes during Partial Accept (#1005)
  • e0d2ad4 Add 500 retry codes and associated unit tests. (#1003)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant