Skip to content

[Snyk] Security upgrade prebuild-install from 2.5.1 to 7.1.1 #70

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

piranna
Copy link
Member

@piranna piranna commented Jun 9, 2022

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: prebuild-install The new version differs by 101 commits.
  • 8250adf 7.1.1
  • 4e2284c Replace use of npmlog dependency with console.error (#182)
  • d1853cb Ensure script output can be captured by tests (#181)
  • 5065bce 7.1.0
  • f729abb Allow setting libc to glibc on non-glibc platform (#176)
  • 4a1ed43 7.0.1
  • f71c6b9 Upgrade to the latest version of `detect-libc` (#166)
  • 8ee70f9 Clarify usage in README
  • d8a8c0e Bump hallmark devDependency
  • 542788b 7.0.0
  • 8ebc076 Add release workflow
  • ff4a4d8 Update badges in README
  • 7468c14 Bump simple-get
  • 1d53607 Bump tape devDependency
  • 734ae27 Bump standard devDependency
  • 477f347 Breaking: bump node-abi so that Electron 14+ gets correct ABI (#161)
  • c96c526 6.1.4
  • b3fad76 Move auth token to header instead of query param (#160)
  • a964e5b Remove _ prefix as it isn't allowed by npm config (#153)
  • 57bcc06 Make 'rc.path' absolute (#158)
  • cca87fb 6.1.3
  • e08d75a Fixes #154: Inline no longer maintained `noop-logger` (#155)
  • 5ee1a2f Point users towards prebuildify (#150)
  • 97ff071 6.1.2

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants