[Snyk] Upgrade @slack/bolt from 3.10.0 to 3.19.0#2
Open
mohammad-84 wants to merge 1 commit intomainfrom
Open
Conversation
Snyk has created this PR to upgrade @slack/bolt from 3.10.0 to 3.19.0. See this package in npm: @slack/bolt See this project in Snyk: https://app.snyk.io/org/mohammad-84/project/5fe6585a-3743-4c7c-833e-e04173c4dd84?utm_source=github&utm_medium=referral&page=upgrade-pr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.

Snyk has created this PR to upgrade @slack/bolt from 3.10.0 to 3.19.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 20 versions ahead of your current version.
The recommended version was released on 21 days ago.
Issues fixed by the recommended upgrade:
SNYK-JS-AXIOS-6032459
SNYK-JS-AXIOS-6032459
SNYK-JS-FOLLOWREDIRECTS-6141137
SNYK-JS-SEMVER-3247795
SNYK-JS-WS-7266574
SNYK-JS-AXIOS-6124857
SNYK-JS-AXIOS-6124857
SNYK-JS-FOLLOWREDIRECTS-6444610
SNYK-JS-JSONWEBTOKEN-3180022
SNYK-JS-JSONWEBTOKEN-3180024
SNYK-JS-JSONWEBTOKEN-3180026
Release notes
Package name: @slack/bolt
-
3.19.0 - 2024-06-19
const { App, AwsLambdaReceiver } = require('@ slack/bolt');
- Add flag to
- Add a type predicate for
- ButtonAction value field not required in #2134 - thanks @ srajiang!
- fix(types): return void promises from the express receiver middleware parser in #2141 - thanks @ zimeg!
- docs: fixed duplicative header links in reference in #2120 - thanks @ lukegalbraithrussell!
- docs: deprecate Steps from Apps docs in #2130 - thanks @ filmaj!
- docs: add JSDoc to and list out all available builtin middleware functions in the docs in #2136 - thanks @ filmaj!
- ci(test): perform unit testing against node version 22 in #2140 - thanks @ zimeg!
- chore(release): tag version @ slack/bolt@3.19.0 in #2142 - thanks @ zimeg!
- Bump @ types/node from 20.12.7 to 20.12.10 in #2111 - thanks @ dependabot!
- Bump @ types/node from 20.12.10 to 20.12.11 in #2114 - thanks @ dependabot!
- Bump @ types/node from 20.12.11 to 20.12.12 in #2117 - thanks @ dependabot!
- Bump @ types/node from 20.12.12 to 20.14.0 in #2125 - thanks @ dependabot!
- Bump @ types/node from 20.14.0 to 20.14.2 in #2132 - thanks @ dependabot!
- @ noah-guillory made their first contribution in #2107
- @ lukegalbraithrussell made their first contribution in #2120
-
3.18.0 - 2024-04-25
- Fix #2056 by adding
- Update acknowledging_requests.md by @ technically-tracy in #2086
- @ technically-tracy made their first contribution in #2086
-
3.17.2-rc.1 - 2024-04-17
-
3.17.1 - 2024-01-11
- chore(3.17.1): Publish v3.17.1 by @ rafael-fecha, including dependency updates to address an Axios security vulnerability in #2029
- @ rafael-fecha made their first contribution in #2029
-
3.17.1-customFunctionBeta.0 - 2024-01-26
-
3.17.0 - 2023-12-20
- Support for
-
3.16.0 - 2023-12-01
- Close HTTP response on unhandled request timeout - Thank you @ suhailgupta03 in #2007
- Prevent sending response headers if already sent in default error han… - Thanks! @ suhailgupta03 in #2006
- Complete every matrix test regardless of adjacent failures - Thank you @ zimeg in #2004
- Bump @ types/node from 20.9.0 to 20.9.2 by @ dependabot in #2000
- Bump @ types/node from 20.9.2 to 20.10.0 by @ dependabot in #2003
- @ suhailgupta03 made their first contribution in #2006 🎉
-
3.15.0 - 2023-11-15
- Add
- Add
- Allow a custom
- Include an example of using middleware with the
- fix: options constraint has wrong type definition by @ nemanjastanic in #1940
- Bump @ types/node from 20.6.2 to 20.9.0
- Upgrade axios by @ wannfq in #1986
- Update mocha and web-api dependencies by @ filmaj in #1994
- Remove beta documentation by @ zimeg in #1961
- Fix link in docs by @ mkly in #1992
- @ nemanjastanic made their first contribution in #1940
- @ wannfq made their first contribution in #1986
- @ mkly made their first contribution in #1992
-
3.14.0 - 2023-09-21
- Add typings for timepicker by @ YussufElarif in #1928
- Upload code coverage reports using the Codecov GitHub Action by @ zimeg in #1937
- Expose useful functions by @ WilliamBergamin in #1955
- Update ci-build.yml - add codecov upload token by @ srajiang in #1952
- Bump @ types/node from 20.4.5 to 20.4.8 by @ dependabot in #1922
- Bump @ types/node from 20.4.8 to 20.5.0 by @ dependabot in #1923
- Bump @ types/node from 20.5.0 to 20.5.1 by @ dependabot in #1929
- Bump @ types/node from 20.5.1 to 20.5.7 by @ dependabot in #1934
- Bump @ slack/logger from 3.0.0 to 4.0.0 by @ dependabot in #1935
- Bump @ types/node from 20.5.7 to 20.5.9 by @ dependabot in #1938
- Bump @ types/node from 20.5.9 to 20.6.0 by @ dependabot in #1945
- Bump @ types/node from 20.6.0 to 20.6.2 by @ dependabot in #1951
- Release: @ slack/bolt@3.14.0 by @ WilliamBergamin in #1956
- @ YussufElarif made their first contribution in #1928
-
3.13.3 - 2023-08-04
-
3.13.2 - 2023-07-13
-
3.13.1 - 2023-04-28
-
3.13.0 - 2023-04-04
-
3.12.2 - 2022-11-02
-
3.12.1 - 2022-07-26
-
3.12.0 - 2022-07-14
-
3.11.3 - 2022-06-17
-
3.11.2 - 2022-06-14
-
3.11.1 - 2022-05-13
-
3.11.0 - 2022-03-30
-
3.10.0 - 2022-02-23
from @slack/bolt GitHub release notesWhat's Changed
More customizations for the
AwsLambdaReceiverhave landed as well as a few touchups to typings and documented details!With this release, the signature verification for
AwsLambdaReceivercan now be turned off if that's something you're interested in! Perhaps you have your own stylish way of verifying these signatures. The following can be added to your receiver to unlock this:const app = new App({
...
receiver: new AwsLambdaReceiver({
signatureVerification: false,
}),
});
Read on and browse around for more details on all of the changes included!
🎁 Enhancments
AwsLambdaReceiverto enable/disable signature verification in #2107 - thanks @ noah-guillory!🐛 Fixes
CodedErrorin #2110 - thanks @ filmaj!📚 Documentation
🧰 Maintenance
📦 Dependencies
New Contributors
Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.18.0...@ slack/bolt@3.19.0
What's Changed
filestoapp_mentionevent payload by @ seratch in #2057New Contributors
Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.17.1...@ slack/bolt@3.18.0
…nts.
What's Changed
New Contributors
Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.17.0...@ slack/bolt@3.17.1
v3.17.1-customFunctionBeta.0
What's Changed
style.codeproperties on rich text elements (updates@ slack/typesto 2.11 and@ slack/web-apito 6.11) by @ filmaj in #2017Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.16.0...@ slack/bolt@3.17.0
What's Changed
Enhancements 🎁
Maintainers
New Contributors 👋
Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.15.0...@ slack/bolt@3.16.0
What's Changed
This minor release includes support for the new File Input Block Kit Element, which allows for users to submit files using Block Kit. It also removes all traces of vulnerable versions of the
axiosdependency.Enhancements
file_inputblock element payload support in TS by @ seratch in #1995rich_text_inputblock element payload support in TS by @ seratch in #1963SocketModeReceiverto be used with Socket Mode by @ zimeg in #1972ExpressReceiverby @ zimeg in #1973Bug Fixes
Dependencies
Other
New Contributors
Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.14.0...@ slack/bolt@3.15.0
What's Changed
Important Notice
Since this version, we've dropped Node 16 support as the version is EOLed on September 11th, 2023. Please upgrade to a newer Node.js version from now on.
Enhancements
Bug Fixes
Dependencies
New Contributors
Full Changelog: https://github.com/slackapi/bolt-js/compare/@ slack/bolt@3.13.3...@ slack/bolt@3.14.0
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: