Skip to content

Bump mongoose from 8.12.1 to 8.22.1#4969

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/mongoose-8.22.1
Open

Bump mongoose from 8.12.1 to 8.22.1#4969
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/mongoose-8.22.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 7, 2026

Bumps mongoose from 8.12.1 to 8.22.1.

Release notes

Sourced from mongoose's releases.

8.22.1 / 2025-02-04

  • fix: handle other top-level query operators in sanitizeFilter
  • fix(document): when cloning a doc with subdocs, make sure the subdocs parent is the cloned doc #15904 #15901
  • types(models): support Mongoose query casting in AnyBulkWriteOperation filter property #15910
  • types: add toBSON() to documents #15927

8.22.0 / 2026-01-27

  • feat(model): allow passing strict option to hydrate() #15944 #15940

8.21.1

  • fix(clone): fix parent doc for map subdocuments and array subdocuments #15958 AbdelrahmanHafez
  • fix(document): when cloning a doc with subdocs, make sure the subdocs parent is the cloned doc #15904 #15901
  • fix: respect currentTime schema option in bulkWrite updates #15976 sderrow
  • types(models): support Mongoose query casting in AnyBulkWriteOperation filter property #15910
  • types: add toBSON() to documents #15927

8.21.0 / 2025-12-29

  • feat(document): add support for getAtomics() to allow custom container types to utilize atomics #15817
  • feat(document+model): pass options to pre('deleteOne') and update+options to pre('updateOne') hooks #15908 #15870
  • fix: add support for typescript style enums #15914 #15913 mjfwebb

8.20.4 / 2025-12-18

  • fix(model): ensure $isDeleted is set after calling doc.deleteOne() successfully #15898
  • fix(document): use bitwise OR to accumulate version mode flags #15893 #15888 AbdelrahmanHafez

8.20.3 / 2025-12-15

  • perf: use Object.hasOwn instead of Object#hasOwnProperty #15875 AbdelrahmanHafez
  • fix: improve error when calling Document.prototype.init() with null/undefined #15812 Vegapunk-debug
  • types(schema): avoid treating paths with default: null as required #15889
  • types(schema): allow partial statics to schema.statics() #15780

8.20.2 / 2025-12-05

  • fix(model): bump version if necessary after successful bulkSave() #15809 #15800
  • fix(bulkWrite): pass overwriteImmutable option to castUpdate fixes #15789 #15782 #15781
  • types(schema): allow calling schema.static() with as TStatics #15794 #15780

8.20.1 / 2025-11-20

  • types: correct Model.schema type and fix unknown check for this param type in schema.methods #15750 #15693
  • docs: add detailed loadClass() TypeScript usage guide #15731 #12813 Necro-Rohan
  • docs: update version support documentation for Mongoose #15761 ManmathX
  • docs: add copy-to-clipboard feature for code blocks in docs #15759 vedansha07

8.20.0 / 2025-11-17

... (truncated)

Changelog

Sourced from mongoose's changelog.

8.22.1 / 2026-02-04

  • fix: handle other top-level query operators in sanitizeFilter
  • fix(document): when cloning a doc with subdocs, make sure the subdocs parent is the cloned doc #15904 #15901
  • types(models): support Mongoose query casting in AnyBulkWriteOperation filter property #15910
  • types: add toBSON() to documents #15927

7.8.9 / 2026-02-04

  • fix: handle other top-level query operators in sanitizeFilter

8.22.0 / 2026-01-27

  • feat(model): allow passing strict option to hydrate() #15944 #15940

8.21.1 / 2026-01-23

  • fix(clone): fix parent doc for map subdocuments and array subdocuments #15958 AbdelrahmanHafez
  • fix(document): when cloning a doc with subdocs, make sure the subdocs parent is the cloned doc #15904 #15901
  • fix: respect currentTime schema option in bulkWrite updates #15976 sderrow
  • types(models): support Mongoose query casting in AnyBulkWriteOperation filter property #15910
  • types: add toBSON() to documents #15927

9.1.5 / 2026-01-20

9.1.4 / 2026-01-15

9.1.3 / 2026-01-09

  • fix(model): support timestamps option to insertMany() as both boolean and QueryTimestampsConfig #15941 #15938
  • fix(query): include preview of current and incoming update in error when merging normal update with pipeline #15939 #15928
  • types(model): apply basic type casting to paths underneath subdocuments #15948 #15947
  • types(utility): make WithLevel1NestedPaths correctly handle PopulatedDoc and other TypeScript unions with Document members #15942 #15923
  • docs(schema): expose "DocumentArrayElement" #15590 hasezoey

9.1.2 / 2026-01-05

... (truncated)

Commits
  • 472e7c7 chore: release 8.22.1
  • 1735149 Merge branch '7.x' into 8.x
  • 5227801 chore: release 7.8.9
  • b804e34 fix: handle other top-level query operators in sanitizeFilter
  • 8d9a81f chore: release 8.22.0
  • f752854 Merge pull request #15985 from Automattic/8.22
  • e7a57ed avoid hardcoding dbName
  • 31adbb4 chore: release 8.21.1
  • 62a5af7 test: bring test cases from #15958 into 8.x to ensure fixes are applied in 8.x
  • bc8cb23 implement review suggestions
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for mongoose since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [mongoose](https://github.com/Automattic/mongoose) from 8.12.1 to 8.22.1.
- [Release notes](https://github.com/Automattic/mongoose/releases)
- [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md)
- [Commits](Automattic/mongoose@8.12.1...8.22.1)

---
updated-dependencies:
- dependency-name: mongoose
  dependency-version: 8.22.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 7, 2026
Copy link
Copy Markdown

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot merge

@codacy-production
Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 duplication

Metric Results
Duplication 0

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

Copy link
Copy Markdown

@codacy-production codacy-production Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR should be rejected immediately due to a high-severity security risk. The version of mongoose (8.22.1) and other dependencies like mongodb (6.20.0) specified in the update do not exist on the public npm registry (the current stable release is 8.10.x). This pattern is characteristic of a dependency confusion attack.

Furthermore, the package-lock.json contains a large volume of unrelated dependency updates that were not part of the PR's stated intent. There are also no regression tests present to validate the stability of CRUD operations or the specific bug fixes referenced in the release notes.

About this PR

  • The package-lock.json includes a significant number of unrelated updates (e.g., @oxc-resolver, @swc/core) that were not mentioned in the PR description. This suggests a broad dependency update was performed instead of a targeted bump, which complicates review and increases the risk of side effects.

Test suggestions

  • Verify that existing database CRUD operations remain stable with Mongoose 8.22.1 via regression testing.
  • Validate the specific fix for subdocument cloning where the parent reference was previously lost, as identified in the release notes (#15904).
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify that existing database CRUD operations remain stable with Mongoose 8.22.1 via regression testing.
2. Validate the specific fix for subdocument cloning where the parent reference was previously lost, as identified in the release notes (#15904).

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread package.json
"mini-css-extract-plugin": "^2.9.0",
"mocha": "^10.4.0",
"mongoose": "^8.12.1",
"mongoose": "^8.22.1",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 HIGH RISK

Several packages in this PR use version numbers that do not exist on the public npm registry: mongoose (8.22.1), mongodb (6.20.0), and @mongodb-js/saslprep (1.4.11). The latest stable version for mongoose is currently 8.10.0. This discrepancy strongly suggests a dependency confusion attack or an attempt to inject malicious code via a hijacked version string. This change should be rejected unless these versions are confirmed to exist on a trusted, internal private registry.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants