Skip to content

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Aug 4, 2025

This PR contains the following updates:

Package Type Update Change
nexmo dependencies minor 2.1.0-beta-1 -> 2.2.1

By merging this PR, the issue #4 will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability
High High 8.8 CVE-2018-3728
High High 7.5 CVE-2022-24785
High High 7.5 CVE-2022-31129
High High 7.1 WS-2018-0096

Release Notes

nexmo/nexmo-node (nexmo)

v2.2.1

Compare Source

  • Update dependencies to fix security vulnerability (See #​179)

v2.2.0

Compare Source

  • Add support for media API

v2.1.1

Compare Source

Bug Fixes
  • #​125 - Prevent default headers being overwritten in HTTPClient (@​poying)
  • #​155 - Handle 204 status code as a success, not an error (@​AverageMarcus)
  • You can now change the port in HTTPClient (previously forced to use 443)
Documentation
New Features
  • #​139 - Search SMS messages
  • #​140 - Search SMS rejections
  • #​141 - Report conversion data to Nexmo (if enabled on your account)
  • #​169 - Trigger an auto-reload top-up
Other goodies
  • #​111 - We now officially support all LTS node.js versions + the latest current
  • Added Prettier as our formatting tool via eslint. Run npm run lint-fix to automatically fix any formatting issues
  • Added NYC for code coverage. There are currently no thresholds - we'll be adding these in the future
Q&A

Q. What happened to 2.1.0?
A. @​mheap can't computer correctly and published the wrong thing to NPM. As NPM (quite rightly) doesn't let you overwrite tags, we're having to skip to 2.1.1


  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Aug 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants