Skip to content

[Snyk] Upgrade nylas from 7.7.1 to 7.13.1 - #78

Open
LuisAPI wants to merge 1 commit into
mainfrom
snyk-upgrade-31d0bd275713736f00b8242aa8c05f71
Open

[Snyk] Upgrade nylas from 7.7.1 to 7.13.1#78
LuisAPI wants to merge 1 commit into
mainfrom
snyk-upgrade-31d0bd275713736f00b8242aa8c05f71

Conversation

@LuisAPI

@LuisAPI LuisAPI commented Oct 22, 2025

Copy link
Copy Markdown
Collaborator

snyk-top-banner

Snyk has created this PR to upgrade nylas from 7.7.1 to 7.13.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 12 versions ahead of your current version.

  • The recommended version was released a month ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-9292519
631 Proof of Concept
medium severity Improper Handling of Unexpected Data Type
SNYK-JS-ONHEADERS-10773729
631 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-8482416
631 Proof of Concept
Release notes
Package name: nylas
  • 7.13.1 - 2025-09-23

    What's Changed

    • chore: added an esm-only example by @ AaronDDM in #664
    • fix: resolve CJS build issue causing "TypeError: Nylas is not a constructor" error by @ AaronDDM in #665

    Full Changelog: v7.13.0...v7.13.1

  • 7.13.0 - 2025-09-02

    What's Changed

    • feat(api): expose raw response headers on all responses via non-enumerable rawHeader by @ AaronDDM in #660
    • feat(messages,drafts): support isPlaintext for messages.send and drafts.create by @ AaronDDM in #661

    Full Changelog: v7.12.0...v7.13.0

  • 7.12.0 - 2025-08-01

    What's Changed

    • replaced: form-data with form-data-node; fixed support for >3MB buffer type; added new examples by @ AaronDDM in #653
    • Bump esbuild and wrangler in /examples/edge-environment by @ dependabot[bot] in #655

    Full Changelog: v7.11.0...v7.12.0

  • 7.11.0 - 2025-06-23

    Added

    • Support for new message fields query parameter values: include_tracking_options and raw_mime
    • Support for trackingOptions property in Message responses when using fields=include_tracking_options
    • Support for rawMime property in Message responses when using fields=raw_mime
    • MessageTrackingOptions interface for tracking message opens, thread replies, link clicks, and custom labels
    • Support for includeHiddenFolders query parameter in folders list endpoint for Microsoft accounts
    • Support for singleLevel query parameter in ListFolderQueryParams for Microsoft accounts to control folder hierarchy traversal

    Fixed

    • Fixed 3MB payload size limit to consider total request size (message body + attachments) instead of just attachment size when determining whether to use multipart/form-data encoding
  • 7.10.0 - 2025-05-27

    What's Changed

    • [Node SDK] consistent handling of timeout values for constructor and overrides by @ ajay-k in #634
    • fix: Add missing /cancel suffix in Notetaker API endpoint by @ AaronDDM in #639
    • feat: add zoom as a supported provider type in Auth module by @ AaronDDM in #640
    • fix: update event status type to use 'maybe' instead of 'tentative' by @ AaronDDM in #641
    • refactor(resources): use makePathParams utility for path construction in all resource classes by @ AaronDDM in #642
    • feat(freeBusy): Add tentativeAsBusy parameter to FreeBusy requests by @ AaronDDM in #643

    New Contributors

    Full Changelog: v7.9.0...v7.10.0

  • 7.9.0 - 2025-04-30

    What's Changed

    • feat: Add Notetaker API support by @ AaronDDM in #629
    • fix: update notetaker media endpoint to support media download by @ AaronDDM in #632
    • Add tentative_as_busy parameter by @ kraju3 in #631
    • Updated to support the latest changes in the GET notetakers endpoint by @ AaronDDM in #636

    Full Changelog: v7.8.0...v7.9.0

  • 7.8.0 - 2025-03-03

    What's Changed

    • fix(grants): Support queryParams in list method first parameter by @ AaronDDM in #624
    • Add support for listImportEvents method to import events from calendars by @ AaronDDM in #623
    • Add support for returning all response headers in node sdk for error responses by @ AaronDDM in #625

    Full Changelog: v7.7.4...v7.8.0

  • 7.8.0-canary.2 - 2025-02-28
  • 7.8.0-canary.1 - 2025-02-28
  • 7.7.4 - 2025-01-23

    What's Changed

    • Fix: any_email was not transformed to a comma delimited list for messages.list (#620)

    Full Changelog: v7.7.3...v7.7.4

  • 7.7.3 - 2025-01-23

    What's Changed

    • Remove createdAt field from message model. (#612)
    • Change latestMessageReceivedDate & latestMessageSentDate to be optional on threads model. (#612)
    • Fix issue where timeout was not being respected when overriding the timeout in the request options. (#617)
    • Fix issue where query params with array values were not being transformed into comma-delimited strings (#618)
    • Fix: transform anyEmail array into comma-delimited any_email parameter in threads list (#618)

    Full Changelog: v7.7.2...v7.7.3

  • 7.7.2 - 2024-12-02

    Changelog

    Changed

    • Fix Credentials endpoint (#610) (#605)
  • 7.7.1 - 2024-11-25
from nylas GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade nylas from 7.7.1 to 7.13.1.

See this package in npm:
nylas

See this project in Snyk:
https://app.snyk.io/org/luisapi/project/29e4d13e-2983-42aa-a7c8-f23989b41384?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants