Skip to content

Conversation

@mtrezza
Copy link
Member

@mtrezza mtrezza commented Nov 9, 2022

Fixes security vulnerability GHSA-xprv-wvh7-qqqx

@parse-github-assistant
Copy link

I will reformat the title to use the proper commit message syntax.

@parse-github-assistant parse-github-assistant bot changed the title fix: release 4.x.x qqqx fix: Release 4.x.x qqqx Nov 9, 2022
@parse-github-assistant
Copy link

parse-github-assistant bot commented Nov 9, 2022

Thanks for opening this pull request!

  • ❌ Please edit your post and use the provided template when creating a new pull request. This helps everyone to understand your post better and asks for essential information to quicker review the pull request.

@mtrezza mtrezza changed the base branch from alpha to release-4.x.x November 9, 2022 18:21
@mtrezza mtrezza closed this Nov 9, 2022
@mtrezza mtrezza reopened this Nov 9, 2022
@codecov
Copy link

codecov bot commented Nov 9, 2022

Codecov Report

Base: 93.82% // Head: 84.31% // Decreases project coverage by -9.50% ⚠️

Coverage data is based on head (0b84155) compared to base (8580a52).
Patch coverage: 95.57% of modified lines in pull request are covered.

Additional details and impacted files
@@                Coverage Diff                @@
##           release-4.x.x    #8301      +/-   ##
=================================================
- Coverage          93.82%   84.31%   -9.51%     
=================================================
  Files                170      170              
  Lines              12502    12556      +54     
=================================================
- Hits               11730    10587    -1143     
- Misses               772     1969    +1197     
Impacted Files Coverage Δ
src/Adapters/Auth/spotify.js 62.50% <60.00%> (-17.50%) ⬇️
src/Adapters/Auth/facebook.js 83.33% <80.00%> (-3.63%) ⬇️
src/Adapters/Files/GridFSBucketAdapter.js 93.43% <90.00%> (+13.92%) ⬆️
src/Controllers/DatabaseController.js 95.17% <100.00%> (-0.04%) ⬇️
src/LiveQuery/ParseCloudCodePublisher.js 100.00% <100.00%> (ø)
src/LiveQuery/ParseLiveQueryServer.js 95.18% <100.00%> (+0.14%) ⬆️
src/RestQuery.js 95.60% <100.00%> (+0.08%) ⬆️
src/RestWrite.js 93.80% <100.00%> (+0.04%) ⬆️
src/Routers/FilesRouter.js 91.60% <100.00%> (+4.53%) ⬆️
...dapters/Storage/Postgres/PostgresStorageAdapter.js 2.42% <0.00%> (-93.52%) ⬇️
... and 12 more

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

☔ View full report at Codecov.
📢 Do you have feedback about the report comment? Let us know in this issue.

@mtrezza mtrezza changed the title fix: Release 4.x.x qqqx fix: Parse Server option requestKeywordDenylist can be bypassed via Cloud Code Webhooks or Triggers Nov 9, 2022
@mtrezza mtrezza merged commit 0a2d412 into parse-community:release-4.x.x Nov 9, 2022
parseplatformorg pushed a commit that referenced this pull request Nov 9, 2022
## [4.10.19](4.10.18...4.10.19) (2022-11-09)

### Bug Fixes

* Parse Server option `requestKeywordDenylist` can be bypassed via Cloud Code Webhooks or Triggers; fixes security vulnerability [GHSA-xprv-wvh7-qqqx](GHSA-xprv-wvh7-qqqx) ([#8301](#8301)) ([0a2d412](0a2d412))
@parseplatformorg
Copy link
Contributor

🎉 This change has been released in version 4.10.19

@parseplatformorg parseplatformorg added the state:released-4.x.x Released as LTS version label Nov 9, 2022
@mtrezza mtrezza deleted the fix-release-4.x.x-qqqx branch November 9, 2022 19:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state:released-4.x.x Released as LTS version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants