Skip to content

Conversation

@taeb3
Copy link
Owner

@taeb3 taeb3 commented Jun 18, 2025

snyk-top-banner

Snyk has created this PR to upgrade thrift from 0.13.0 to 0.22.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 12 versions ahead of your current version.

  • The recommended version was released a month ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Internal Property Tampering
SNYK-JS-TAFFYDB-2992450
479 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-174116
479 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-2342073
479 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-2342082
479 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-451540
479 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-584281
479 No Known Exploit
medium severity Arbitrary Code Injection
SNYK-JS-UNDERSCORE-1080984
479 Proof of Concept
Release notes
Package name: thrift
  • 0.22.0 - 2025-05-23

    Please head over to the official release download source:
    http://thrift.apache.org/download

    The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

  • 0.21.0 - 2024-09-22

    Please head over to the official release download source:
    http://thrift.apache.org/download

    The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

  • 0.20.0 - 2024-03-22

    Please head over to the official release download source:
    http://thrift.apache.org/download

    The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

  • 0.19.0 - 2023-09-02

    Please head over to the official release download source:
    http://thrift.apache.org/download

    The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

  • 0.18.1 - 2023-03-01

    Please head over to the official release download source:
    http://thrift.apache.org/download

    The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

  • 0.18.0 - 2023-02-14

    Please head over to the official release download source:
    http://thrift.apache.org/download

    The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

  • 0.17.0 - 2022-09-18

    Please head over to the official release download source:
    http://thrift.apache.org/download

    The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

  • 0.16.0 - 2022-02-17

    For release 0.16.0 head over to the official release download source:
    http://thrift.apache.org/download

    The assets below are added by Github based on the release tag and they may therefore not match the checkums.

  • 0.15.0 - 2021-09-11

    For release 0.15.0 head over to the official release download source:
    http://thrift.apache.org/download

    The assets below are added by Github based on the release tag and they may therefore not match the checkums.

  • 0.14.2 - 2021-06-17
  • 0.14.1 - 2021-03-08
  • 0.14.0 - 2021-02-12
  • 0.13.0 - 2019-11-18
from thrift GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade thrift from 0.13.0 to 0.22.0.

See this package in npm:
thrift

See this project in Snyk:
https://app.snyk.io/org/taeb3/project/d774ea56-0f4e-4632-b2ec-86818396711a?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants