Skip to content

Conversation

@lydmoon
Copy link
Owner

@lydmoon lydmoon commented Apr 15, 2025

snyk-top-banner

Snyk has created this PR to upgrade mongodb from 6.2.0 to 6.15.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 218 versions ahead of your current version.

  • The recommended version was released a month ago.

Release notes
Package name: mongodb
  • 6.15.0 - 2025-03-18

    6.15.0 (2025-03-18)

    The MongoDB Node.js team is pleased to announce version 6.15.0 of the mongodb package!

    Release Notes

    Support for custom AWS credential providers

    The driver now supports a user supplied custom AWS credentials provider for both authentication and for KMS requests when using client side encryption. The signature for the custom provider must be of () => Promise<AWSCredentials> which matches that of the official AWS SDK provider API. Provider chains from the actual AWS SDK can also be provided, allowing users to customize any of those options.

    Example for authentication with a provider chain from the AWS SDK:

    import { fromNodeProviderChain } from '@ aws-sdk/credential-providers';

    const client = new MongoClient(process.env.MONGODB_URI, {
    authMechanismProperties: {
    AWS_CREDENTIAL_PROVIDER: fromNodeProviderChain()
    }
    });

    Example for using a custom provider for KMS requests only:

    import { fromNodeProviderChain } from '@ aws-sdk/credential-providers';

    const client = new MongoClient(process.env.MONGODB_URI, {
    autoEncryption: {
    keyVaultNamespace: 'keyvault.datakeys',
    kmsProviders: { aws: {} },
    credentialProviders: {
    aws: fromNodeProviderChain()
    }
    }
    }

    Custom providers do not need to come from the AWS SDK, they just need to be an async function that returns credentials:

    const client = new MongoClient(process.env.MONGODB_URI, {
      authMechanismProperties: {
        AWS_CREDENTIAL_PROVIDER: async () => {
          return {
            accessKeyId: process.env.ACCESS_KEY_ID,
            secretAccessKey: process.env.SECRET_ACCESS_KEY
          }
        }
      }
    });

    Fix misc unhandled rejections under special conditions

    We identified an issue with our test suite that suppressed catching unhandled rejections and surfacing them to us so we can ensure the driver handles any possible rejections. Luckily only 3 cases were identified and each was under a flagged or specialized code path that may not have been in use:

    • If the MongoClient was configured to use OIDC and an AbortSignal was aborted on cursor at the same time the client was reauthenticating, if the reauth process was rejected it would have been unhandled.
    • If timeoutMS was used and the timeout expired before an operation reached the server selection step the operation would throw the expected timeout error but a promise representing the timeout would also raise an unhandled rejection.
    • If a change stream was closed while processing a change event it was possible for the "change stream is closed" error to be emitted as an error event and reject an internal promise representing fetching the "next" change.

    Features

    Bug Fixes

    Documentation

    We invite you to try the mongodb library immediately, and report any issues to the NODE project.

  • 6.15.0-dev.20250410.sha.b2511f06 - 2025-04-10
  • 6.15.0-dev.20250409.sha.46cb56de - 2025-04-09
  • 6.15.0-dev.20250408.sha.85124c25 - 2025-04-08
  • 6.15.0-dev.20250405.sha.cb88b05d - 2025-04-05
  • 6.15.0-dev.20250403.sha.9111f98c - 2025-04-03
  • 6.15.0-dev.20250328.sha.32b3e34e - 2025-03-28
  • 6.15.0-dev.20250327.sha.cfdb8ec2 - 2025-03-27
  • 6.15.0-dev.20250326.sha.d01ecc79 - 2025-03-26
  • 6.15.0-dev.20250325.sha.5ce0a4ec - 2025-03-25
  • 6.15.0-dev.20250322.sha.892c14de - 2025-03-22
  • 6.15.0-dev.20250321.sha.20f7db7f - 2025-03-21
  • 6.15.0-dev.20250320.sha.af30db93 - 2025-03-20
  • 6.15.0-dev.20250319.sha.f176de4f - 2025-03-19
  • 6.14.2 - 2025-03-04

    6.14.2 (2025-03-04)

    The MongoDB Node.js team is pleased to announce version 6.14.2 of the mongodb package!

    Release Notes

    KMS Requests can cause unhandled rejection

    When using explicit encryption or automatic encryption, the driver makes requests to a Key Management System when to fetch key encryption keys. The driver supports connecting to a KMS provider through a Socks5 proxy. However, the socket used for the socks5 proxy was created in all circumstances, regardless of proxy configuration. This leads to unhandled rejection errors when closing the socket the driver attempts to clean up the unused socket.

    With the changes in this release, the socket is only created if a proxy is configured and the any promises created for the proxy are properly handled.

    Bug Fixes

    Documentation

    We invite you to try the mongodb library immediately, and report any issues to the NODE project.

  • 6.14.2-dev.20250318.sha.78d951b9 - 2025-03-18
  • 6.14.2-dev.20250315.sha.cd09d435 - 2025-03-15
  • 6.14.2-dev.20250314.sha.6895b258 - 2025-03-14
  • 6.14.2-dev.20250313.sha.54d29e56 - 2025-03-13
  • 6.14.2-dev.20250312.sha.5783db21 - 2025-03-12
  • 6.14.2-dev.20250310.sha.39c76999 - 2025-03-10
  • 6.14.2-dev.20250306.sha.21072009 - 2025-03-06
  • 6.14.2-dev.20250305.sha.398e361f - 2025-03-05
  • 6.14.1 - 2025-03-03

    6.14.1 (2025-03-03)

    The MongoDB Node.js team is pleased to announce version 6.14.1 of the mongodb package!

    Release Notes

    Fixed occasional OIDC reauthentication failure

    Error code 391 is intended to make the driver internally reauthenticate the connection to the server, however, occasionally this was being raised to the user. This was due to a bug in setting the cached access token on newly created connections.

    Bug Fixes

    Documentation

    We invite you to try the mongodb library immediately, and report any issues to the NODE project.

  • 6.14.1-dev.20250304.sha.3cc3a6b2 - 2025-03-04
  • 6.14.0 - 2025-02-28

    6.14.0 (2025-02-28)

    The MongoDB Node.js team is pleased to announce version 6.14.0 of the mongodb package!

    Release Notes

    Add support for $lookup on encrypted collections

    Starting in the upcoming MongoDB server 8.1, the aggregation stage $lookup can now be used with clients configured for automatic encryption after upgrading to mongodb-client-encryption@>=6.3.0! 🔒 🎉

    Use isUint8Array defined in the driver rather than util/types

    Some users of bundlers for next.js and our very own mongosh noticed a new import from "util/types" that would need to be supported in environments that don't have that module. We already have an internal implementation of isUint8Array so we do not need to add an import for "util/types".

    Revert @ aws-sdk/credential-providers compatiblity change

    In v6.13.1 we inadvertantly raised the version compatibility of @ aws-sdk/credential-providers, that change has been reverted.

    Features

    Bug Fixes

    Documentation

    We invite you to try the mongodb library immediately, and report any issues to the NODE project.

  • 6.14.0-dev.20250301.sha.44bc5a88 - 2025-03-01
  • 6.13.1 - 2025-02-20

    6.13.1 (2025-02-20)

    The MongoDB Node.js team is pleased to announce version 6.13.1 of the mongodb package!

    Release Notes

    Remove extraneous Promise<Document> in Collection.replaceOne return type

    The return type signature of the replaceOne method no longer includes the general Promise<Document> type. Thanks to @ arturmuller, the replaceOne type signature is now more accurate! 🎉

    Fix writeConcern omitted when timeoutMS is provided

    When timeoutMS and a write concern were provided, the writeConcern was incorrectly omitted from the final command executed by the driver.

    Thanks @ stepanho for contributing the fix!

    Update BSON version requirement to 6.10.3

    This pulls in fixes made in bson versions 6.10.3 and 6.10.2 into the driver.

    BSON 6.10.2 fixed an issue in calculateObjectSize ignoring the size contributed by BigInt values to a BSON document. This impacted batch splitting logic in bulkWrite operations: if the actual BSON was over the size returned by calculateObjectSize the server would return an error.

    Warning

    BSON 6.10.3 addresses a potential data corruption risk with the use of useBigInt64 flag introduced in BSON 6.4.0, where negative Long values would be deserialized into BigInt as unsigned integers when the useBigInt64 flag was enabled. (Thanks to @ rkistner for reporting this issue!)

    Bug Fixes

    Documentation

    We invite you to try the mongodb library immediately, and report any issues to the NODE project.

  • 6.13.1-dev.20250228.sha.488c4071 - 2025-02-28
  • 6.13.1-dev.20250227.sha.196e08e9 - 2025-02-27
  • 6.13.1-dev.20250226.sha.7800067a - 2025-02-26
  • 6.13.1-dev.20250225.sha.1a6dc9b8 - 2025-02-25
  • 6.13.1-dev.20250222.sha.421ddeb3 - 2025-02-22
  • 6.13.1-dev.20250221.sha.21f2cb91 - 2025-02-21
  • 6.13.0 - 2025-01-30

    6.13.0 (2025-01-30)

    The MongoDB Node.js team is pleased to announce version 6.13.0 of the mongodb package!

    Release Notes

    MongoDB Standardized Logging 📝

    The driver's standardized logger is now available! The primary goal of our driver's logger is to enable insight into database operations without code changes so enabling and configuring the logger are primarily done through our environment variables.

    TL;DR Show me the logs!

    env MONGODB_LOG_ALL=debug node server.mjs

    Tip

    If you are a CLI app developer (or otherwise take great care of your std outputs): The client options constructor argument takes precedence over environment variables, permitting you to disable or otherwise customize the logger so your app does not automatically respond to the current environment.

    Check out the in-depth logging docs here: https://www.mongodb.com/docs/drivers/node/current/fundamentals/logging/

    🚀 Improved command monitoring performance

    Previously, when command monitoring was enabled, the driver would make deep copies of command and reply objects, which have the potential to be very large documents. These copies have been eliminated, providing a speed and memory efficiency bump to command monitoring.

    Warning

    Since we no longer make deep copies of commands/replies in Command Monitoring Events, directly modifying the command/reply objects on CommandStartedEvents and CommandSucceededEvents may lead to undefined behaviour.

    🧪 Experimental AbortSignal support added to Find and Aggregate! 🚥

    A signal argument can now be passed to the following APIs:

    • collection.find() & collection.findOne()
    • collection.aggregate() & collection.countDocuments()

    In order to support field level encryption properly, also:

    • db.listCollections()
    • db.command()

    When aborted, the signal will interrupt the execution of each of each of these APIs. For the cursor-based APIs, this will be observed when attempting to consume from the cursor via toArray(), next(), for-await, etc.

    There is a known limitation: aborting a signal closes a perfectly healthy connection which can cause unnecessary connection reestablishment so we're releasing this as experimental for evaluation in use cases that can tolerate the shortcoming.

    DNS SRV & TXT look up timeouts are retried

    To mitigate the potentially transient DNS timeout error, the driver now catches and retries the DNS lookups upon resolving a mongodb+srv:// style connection string.

    MongoClient.close now closes any outstanding cursors

    Previously, cursors could somewhat live beyond the client they came from. What this meant was that depending on timing you would learn of the client's (and by proxy, the cursor's) demise via an assertion that the associated session had expired. This only occurred if your cursor needed to use the session, which only happens when it is attempting to run a getMore operation to obtain another batch of documents.

    Practically speaking a cursor that lives beyond a client is an exception waiting to happen, the connection pools are closed, the sessions are ended, last call has been served 🍻, it is only a matter of timing and event firing until the cursor learns of its fate and informs you by throwing an error via whatever API is being used (.toArray(), for-await, .next()).

    To make the expected state of cursors clearer in this scenario the MongoClient will now close any associated cursors upon its close()-ing reducing the risk of leaving behind server-side resources.

    MongoClient.close() can be called concurrently

    In the past, concurrent calls to MongoClient.close() had poorly defined behavior depending on the exact timing of the second (or more) calls to close(). In some cases, this could also throw errors.

    With these changes, MongoClient.close() can be called concurrently safely and always returns the same promise.

    Note

    This is intended as a correctness fix - we don't recommend calling MongoClient.close() concurrently if it can be avoided.

    MONGODB-OIDC now properly reauthenticates in speculative auth scenarios

    When using MONGODB-OIDC authentication, if the initial handshake contained speculative authentication, the driver would not properly reauthenticate when the server would raise 391 errors. This is now fixed.

    Features

    Bug Fixes

    Performance Improvements

    Documentation

    We invite you to try the mongodb library immediately, and report any issues to the NODE project.

  • 6.13.0-dev.20250220.sha.0789dff0 - 2025-02-20
  • 6.13.0-dev.20250215.sha.94122fb8 - 2025-02-15
  • 6.13.0-dev.20250214.sha.d18108c5 - 2025-02-14
  • 6.13.0-dev.20250213.sha.ba422064 - 2025-02-13
  • 6.13.0-dev.20250212.sha.5f4500b8 - 2025-02-12
  • 6.13.0-dev.20250211.sha.7bfce01e - 2025-02-11
  • 6.13.0-dev.20250208.sha.a79a13d3 - 2025-02-08
  • 6.13.0-dev.20250207.sha.057693e1 - 2025-02-07
  • 6.13.0-dev.20250206.sha.1d0b2b44 - 2025-02-06
  • 6.13.0-dev.20250205.sha.3a4edd51 - 2025-02-05
  • 6.13.0-dev.20250204.sha.5d99661a - 2025-02-04
  • 6.13.0-dev.20250201.sha.35c703e3 - 2025-02-01
  • 6.13.0-dev.20250131.sha.e7898a4d - 2025-01-31
  • 6.12.0 - 2024-12-10

    6.12.0 (2024-12-10)

    The MongoDB Node.js team is pleased to announce version 6.12.0 of the mongodb package!

    Release Notes

    [email protected] is now supported for zstd compression

    The new @ mongodb-js/[email protected] release can now be used with the driver for zstd compression.

    Populate ServerDescription.error field when primary marked stale

    We now attach an error to the newly created ServerDescription object when marking a primary as stale. This helps with debugging SDAM issues when monitoring SDAM events.

    BSON upgraded to v6.10.1

    See: https://github.com/mongodb/js-bson/releases/tag/v6.10.1

    Socket read stream set to object mode

    Socket data was being read with a stream set to buffer mode when it should be set to object mode to prevent inaccurate data chunking, which may have caused message parsing errors in rare cases.

    SOCKS5: MongoNetworkError wrap fix

    If the driver encounters an error while connecting to a socks5 proxy, the driver wraps the socks5 error in a MongoNetworkError. In some circumstances, this resulted in the driver wrapping MongoNetworkErrors inside MongoNetworkErrors.

    The driver no longer double wraps errors in MongoNetworkErrors.

    Features

    Bug Fixes

    Documentation

    We invite you to try the mongodb library immediately, and report any issues to the NODE project.

  • 6.12.0-dev.20250130.sha.6b15f201 - 2025-01-30
  • 6.12.0-dev.20250129.sha.907aac19 - 2025-01-29
  • 6.12.0-dev.20250128.sha.654069fc - 2025-01-28
  • 6.12.0-dev.20250125.sha.c1bcf0de - 2025-01-25
  • 6.12.0-dev.20250124.sha.70d476aa - 2025-01-24
  • 6.12.0-dev.20250118.sha.41b066b2 - 2025-01-18
  • 6.12.0-dev.20250115.sha.e2aa15c2 - 2025-01-15
  • 6.12.0-dev.20250111.sha.13ca4405 - 2025-01-11
  • 6.12.0-dev.20250109.sha.3216d330 - 2025-01-09
  • 6.12.0-dev.20241221.sha.c392465a - 2024-12-21
  • 6.12.0-dev.20241220.sha.80c4d74a - 2024-12-20
  • 6.12.0-dev.20241218.sha.e972bb8f - 2024-12-18
  • 6.12.0-dev.20241212.sha.f6d7868f - 2024-12-12
  • 6.12.0-dev.20241211.sha.2f9ad4d4 - 2024-12-11
  • 6.11.0 - 2024-11-22

    6.11.0 (2024-11-22)

    The MongoDB Node.js team is pleased to announce version 6.11.0 of the mongodb package!

    Release Notes

    Client Side Operations Timeout (CSOT)

    We've been working hard to try to simplify how setting timeouts works in the driver and are excited to finally put Client Side Operation Timeouts (CSOT) in your hands! We're looking forward to hearing your feedback on this new feature during its trial period in the driver, so feel free to file Improvements, Questions or Bug reports on our Jira Project or leave comments on this community forum thread: Node.js Driver 6.11 Forum Discussion!

    CSOT is the common drivers solution for timing out the execution of an operation at the different stages of an operation's lifetime. At its simplest, CSOT allows you to specify one option,timeoutMS that determines when the driver will interrupt an operation and return a timeout error.

    For example, when executing a potentially long-running query, you would specify timeoutMS as follows:

    await collection.find({}, {timeoutMS: 600_000}).toArray(); // Ensures that the find will throw a timeout error if all documents are not retrieved within 10 minutes
    // Potential Stack trace if this were to time out:
    // Uncaught MongoOperationTimeoutError: Timed out during socket read (600000ms)
    //    at Connection.readMany (mongodb/lib/cmap/connection.js:427:31)
    //    at async Connection.sendWire (mongodb/lib/cmap/connection.js:246:30)
    //    at async Connection.sendCommand (mongodb/lib/cmap/connection.js:281:24)
    //    at async Connection.command (mongodb/lib/cmap/connection.js:323:26)
    //    at async Server.command (mongodb/lib/sdam/server.js:170:29)
    //    at async GetMoreOperation.execute (mongodb/lib/operations/get_more.js:58:16)
    //    at async tryOperation (mongodb/lib/operations/execute_operation.js:203:20)
    //    at async executeOperation (mongodb/lib/operations/execute_operation.js:73:16)
    //    at async FindCursor.getMore (mongodb/lib/cursor/abstract_cursor.js:590:16)

    Warning

    This feature is experimental and subject to change at any time. We do not recommend using this feature in production applications until it is stable.

    What's new?

    timeoutMS

    The main new option introduced with CSOT is the timeoutMS option. This option can be applied directly as a client option, as well as at the database, collection, session, transaction and operation layers, following the same inheritance behaviours as other driver options.

    When the timeoutMS option is specified, it will always take precedence over the following options:

    • socketTimeoutMS
    • waitQueueTimeoutMS
    • wTimeoutMS
    • maxTimeMS
    • maxCommitTimeMS

    Note, however that timeoutMS DOES NOT unconditionally override the serverSelectionTimeoutMS option.

    When timeoutMS is specified, the duration of time allotted to the server selection and connection checkout portions of command execution is defined by min(serverSelectionTimeoutMS, timeoutMS) if both are >0. A zero value for either timeout value represents an infinite timeout. A finite timeout will always be used unless both timeouts are specified as 0. Note also that the driver has a default value for serverSelectionTimeoutMS of 30000.

    After server selection and connection checkout are complete, the time remaining bounds the execution of the remainder of the operation.

    Note

    Specifying timeoutMS is not a hard guarantee that an operation will take exactly the duration specified. In the circumstances identified below, the driver's internal cleanup logic can result in an operation exceeding the duration specified by timeoutMS.

    • AbstractCursor.toArray() - can take up to 2 * timeoutMS in 'cursorLifetimeMode' and (n+1) * timeoutMS when returning n batches in 'iteration' mode
    • AbstractCursor.[Symbol.asyncIterator]() - can take up to 2 * timeoutMS in 'cursorLifetimeMode' and (n+1)*timeoutMS when returning n batches in 'iteration' mode
    • MongoClient.bulkWrite() - can take up to 2 * timeoutMS in error scenarios when the driver must clean up cursors used internally.
    • CSFLE/QE - can take up to 2 * timeoutMS in rare error scenarios when the driver must clean up cursors used internally when fetching keys from the keyvault or listing collections.

    In the AbstractCursor.toArray case and the AbstractCursor.[Symbol.asyncIterator] case, this occurs as these methods close the cursor when they finish returning their documents. As detailed in the following section, this results in a refreshing of the timeout before sending the killCursors command to close the cursor on the server.
    The MongoClient.bulkWrite and autoencryption implementations use cursors under the hood and so inherit this issue.

    Cursors, timeoutMS and timeoutMode

    Cursors require special handling with the new timout paradigm introduced here. Cursors can be configured to interact with CSOT in two ways.
    The first, 'cursorLifetime' mode, uses the timeoutMS to bound the entire lifetime of a cursor and is the default timeout mode for non-tailable cursors (find, aggregate*, listCollections, etc.). This means that the initialization of the cursor and all subsequent getMore calls MUST finish within timeoutMS or a timeout error will be thrown. Note, however that the closing of a cursor, either as part of a toArray() call or manually via the close() method resets the timeout before sending a killCursors operation to the server.

    e.g.

    // This will ensure that the initialization of the cursor and retrieval of all docments will occur within 1000ms, throwing an error if it exceeds this time limit
    const docs = await collection.find({}, {timeoutMS: 1000}).toArray();

    The second, 'iteration' mode, uses timeoutMS to bound each next/hasNext/tryNext call, refreshing the timeout after each call completes. This is the default mode for all tailable cursors (tailable find cursors on capped collections, change streams, etc.). e.g.

    // Each turn of the async iterator will take up to 1000ms before it throws
    for await (const doc of cappedCollection.find({}, {tailable: true, timeoutMS: 1000})) {
        // process document
    }

    Note that timeoutMode is also configurable on a per-cursor basis.

    GridFS and timeoutMS

    GridFS streams interact with timeoutMS in a similar manner to cursors in 'cursorLifeTime' mode in that timeoutMS bounds the entire lifetime of the stream.
    In addition, GridFSBucket.find, GridFSBucket.rename and GridFSBucket.drop all support the timeoutMS option and behave in the same way as other operations.

    Sessions, Transactions, timeoutMS and defaultTimeoutMS

    ClientSessions have a new option: defaultTimeoutMS, which specifies the timeoutMS value to use for:

    • commitTransaction
    • abortTransaction
    • withTransaction
    • endSession

    Note

    If defaultTimeoutMS is not specified, then it will inherit the timeoutMS of the parent MongoClient.

    When using ClientSession.withTransaction, the timeoutMS can be configured either in the options on the withTransaction call or inherited from the session's defaultTimeoutMS. This timeoutMS will apply to the entirety of the withTransaction callback provided that the session is correctly passed into each database operation. If the session is not passed into the operation, it will not respect the configured timeout. Also be aware that trying to override the timeoutMS at the operation level for operations making use of the explicit session inside the withTransaction callback will result in an error being thrown.

    const session = client.startSession({defaultTimeoutMS: 1000});
    const coll = client.db('db').collection('coll');
    // ❌ Incorrect; will throw an error
    await session.withTransaction(async function(session) {
    await coll.insertOne({x:1}, { session, timeoutMS: 600 });
    })

    // ❌ Incorrect; will not respect timeoutMS configured on session
    await session.withTransaction(async function(session) {
    await coll.insertOne({x:1}, {});
    })

    ClientEncryption and timeoutMS

    The ClientEncryption class now supports the timeoutMS option. If timeoutMS is provided when constructing a ClientEncryption instance, it will be used to govern the lifetime of all operations performed on instance, otherwise, it will inherit from the timeoutMS set on the MongoClient provided to the ClientEncryption constructor.
    If timeoutMS is set on both the client and provided to ClientEncryption directly, the option provided to ClientEncryption takes precedence.

Snyk has created this PR to upgrade mongodb from 6.2.0 to 6.15.0.

See this package in npm:
mongodb

See this project in Snyk:
https://app.snyk.io/org/lydiamoon7/project/db315a82-4a35-495f-9f45-8c58e365dfea?utm_source=github&utm_medium=referral&page=upgrade-pr
@lydmoon lydmoon self-assigned this Apr 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants