Skip to content

[Snyk] Security upgrade npm from 4.6.1 to 5.0.1 #283

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NPMUSERVALIDATE-1019352
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: npm The new version differs by 241 commits.
  • 19397ad 5.0.1
  • 45b13d9 update AUTHORS
  • 25ebbb1 doc: update changelog for npm@5.0.1
  • 7e5ce87 pacote@2.7.26
  • f3cb84b docs: update cli usage for test command (#16771)
  • acbe85b view: wait until write completes to call cb (#16791)
  • dc2823a docs: package-lock.json is never allowed in tarballs (#16799)
  • 80ab521 deps: pull in dependency updates with bugfixes
  • e61e68d publish: adapt config for publish RegClient (#16762)
  • 9aac984 finalize: Guard against being unable to compute _requested source
  • 3cb8432 standard: minor linter fix
  • 9f81483 error-handler: remove unused argument (#16757)
  • c3e0b42 docs: preserve same name convention for command (#16296)
  • 6612623 ls: remove unused argument (#16756)
  • 923fd58 utils: Remove slow assertion from module-name util (#16749)
  • ebafe48 hamilton: Talk less, complete more (#16750)
  • 39495d0 5.0.0
  • 0d91907 doc: update changelog for npm@5.0.0
  • 8a173da docs: END OF AN ERA OF CHANGELOGS 😭
  • 794c10e pkglock: remove packageIntegrity field of doom
  • 674004c lifecycle: added prepack and postpack (#16725)
  • db76632 cacache@9.2.5
  • 0d35975 preinstall: Runs in the final dest, not the staging folder
  • a976fa1 pacote: more alwaysAuth logic

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant