Skip to content

feat: security vulnerability patches for version 4#16390

Closed
hbrysiewicz wants to merge 6 commits into
sequelize:v4from
soxhub:v6-patch-replacement
Closed

feat: security vulnerability patches for version 4#16390
hbrysiewicz wants to merge 6 commits into
sequelize:v4from
soxhub:v6-patch-replacement

Conversation

@hbrysiewicz
Copy link
Copy Markdown

Pull Request Checklist

  • Have you added new tests to prevent regressions?
  • If a documentation update is necessary, have you opened a PR to the documentation repository?
  • Did you update the typescript typings accordingly (if applicable)?
  • Does the description below contain a link to an existing issue (Closes #[issue]) or a description of the issue you are solving?
  • Does the name of your PR follow our conventions?

Description Of Change

This backports some critical security fixes that were applied to v6+ into v4. While I know its probably better to upgrade (and we are working towards it), I thought this might also be useful to anyone else still for some insane reason running v4 😬 .

The following are the fixes applied and their relevant PR for v6:

@WikiRik
Copy link
Copy Markdown
Member

WikiRik commented Aug 15, 2023

I think it's better to publish your own fork of v4 with these changes. We do not have enough knowledge or the ability to run proper testing that we would be comfortable with merging this. And if we would backport this to v4, we should do this for v5 as well.

@WikiRik WikiRik closed this Sep 23, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants