Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Fix for 1 vulnerabilities #27

Open
wants to merge 1 commit into
base: latest
Choose a base branch
from

Conversation

Bhanditz
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: init-package-json The new version differs by 21 commits.

See the full diff

Package name: node-gyp The new version differs by 169 commits.

See the full diff

Package name: normalize-package-data The new version differs by 20 commits.

See the full diff

Package name: npm-install-checks The new version differs by 15 commits.
  • 9b68df3 4.0.0
  • d498feb allow engine if npm version not specified
  • f9cc89a update travis to only include live nodes
  • 0fc0126 auto-publish scripts
  • ca36bca update changelog for v4
  • a0d38b4 update docs for v4
  • 44b7124 Simplified functionality needed for npm v7
  • 1646fd7 remove unnecessary deps and metadata
  • d74d479 chore: project settings
  • d4463a3 chore(deps): update semver, tap, standard
  • 89937d4 minimal package
  • 893b181 fix: allow pre-release versions of npm and node
  • ab92033 chore: bump version of semver package
  • aafb4ee deps: bump deps
  • f8cc119 chore: update CI for current Node LTS

See the full diff

Package name: npm-package-arg The new version differs by 15 commits.
  • 26ffdd5 chore(release): 8.0.0
  • 17598ad chore: normalize settings, license, and update standard-version
  • ba85e68 drop support for node 6 and 8
  • 2c06e53 update tap
  • 9434f79 chore: update semver to v7
  • bf86221 chore(release): 7.0.0
  • 68a4fc3 deps: bump hosted-git-info to 3.0.2
  • ee44e84 chore: update deps
  • 1da5ca9 chore(release): 6.1.1
  • 84a9569 chore: add node 12 to travis
  • c5da1f4 chore: boost test coverage to 100%
  • 3909203 fix: preserve drive letter on windows git file:// urls
  • a5a18b3 chore: update CI for current Node LTS
  • b2c1e0c deps: bump devDeps
  • db7ca93 deps: bump deps

See the full diff

Package name: npm-pick-manifest The new version differs by 23 commits.
  • 3c8cb5d chore(release): 5.0.0
  • dc2e61c chore: normalize settings, drop old nodes, update deps
  • 661ba9d chore: bump version of semver package
  • 405d00b chore(release): 4.0.0
  • 42c76d8 deps: bump npm-package-arg to v7
  • 8e66272 chore(release): 3.0.2
  • 420fb8c chore: update repo links
  • 543da7c chore(release): 3.0.1
  • 003286e fix: throw 403 for forbidden major/minor versions
  • ed0fc29 chore(release): 3.0.0
  • 6ab64fd chore: remove node 4.0 from travis
  • ad2a962 feat: throw forbidden error when package is blocked by policy
  • cf0c612 chore(release): 2.2.3
  • 5e89b62 fix(enjoyBy): rework semantics for enjoyBy again
  • dcef9cd chore(release): 2.2.2
  • 5684f45 fix(enjoyBy): rework semantics for enjoyBy
  • 3ed20c0 chore(release): 2.2.1
  • 96410c4 test: improve error messaging and add more tests to enjoyBy feature
  • b0ea20a chore(release): 2.2.0
  • 0b8a790 feat(enjoyBy): add opts.enjoyBy option to filter versions by date
  • 6effde4 opts: use figgy-pudding for opts
  • d5ae6c4 fix(audit): npm audit fix --force
  • 7c9e986 deps: add figgy-pudding

See the full diff

Package name: npm-registry-fetch The new version differs by 73 commits.
  • d370dba chore(release): 6.0.0
  • 8c6622f chore: make-fetch-happen 7.1.0
  • 5813da6 fix: detect CI so our tests don't fail in CI
  • 3de1695 chore: replace nyc config with tap config
  • e18ed22 chore: bump make-fetch-happen to v7
  • 62f81a2 chore: bump ssri to v7
  • 8ccfa8a fix: Use WhatWG URLs instead of url.parse
  • 510b125 chore: normalize settings, drop old nodes, update deps
  • 622afb4 chore(release): 5.0.1
  • 7aa14fd deps: update all deps
  • 5764c15 deps: npm-package-arg@7
  • 786f092 chore(release): 5.0.0
  • 41ff216 chore: update travis config
  • 39e5cfe doc: fix badge url
  • 97c1208 chore: update tap, improve offline/prefer-offline tests
  • 82abf26 chore: Add missing tests and clean up dead code
  • 90ac7b1 fix: prefer const in getAuth function
  • e64702e fix: use minizlib instead of core zlib
  • 5cfe30b test: add string query example to test
  • e7286f7 fix!: Use native Promises
  • bb37f20 feat: refactor to use Minipass streams
  • b758555 chore(release): 4.0.2
  • e3a0186 fix: Add null check on body on 401 errors
  • ff5f990 test(check-response): Added missing tests

See the full diff

Package name: pacote The new version differs by 186 commits.
  • e88f844 10.3.0
  • b21dd92 update semver
  • d8ab8cf update npm-packlist
  • 361f0b3 update tap
  • c4bbf23 test: make the remote timeout test time out forever
  • b4ea91f npm-registry-fetch 6.0.0
  • 591edd8 @ npmcli/installed-package-contents@1.0.5
  • 5ce1093 test: make remote timeout test more reliably time out
  • 48fc9b8 use WhatWG URL instead of url.parse
  • e515bce Update deps, float patch for npm-registry-fetch
  • cf50f54 update @ npmcli/installed-package-contents, require node >=10
  • 698e996 Extract: rimraf dir contents, not dir itself
  • e568305 add @ npmcli/installed-package-contents module
  • e8a80d7 upgrade all deps
  • dfccb4f remove extraneous isNaN checking in git opts
  • e33c9ce 10.2.1
  • bad55cd fix: Do not drop perms in git when not root
  • ccc9e20 bin: only add log listener once
  • 8a8cd6a 10.2.0
  • e8c274c registry: verify integrity when loading manifest
  • f28888e bin: Only JSON.stringify by default if an object
  • 0018eda 10.1.6
  • fc1053f git: prefer git+https over git+ssh for hosted repo
  • 9d2ce90 10.1.5

See the full diff

Package name: read-package-json The new version differs by 17 commits.
  • 9f7049d chore(release): 3.0.0
  • 19d9fbe fix: check-in updated lockfile
  • eef46fa chore: add engines definition
  • 36b7ef7 chore: remove old .travis.yml envs
  • b3a8831 globa@7.1.6
  • fb3ceae json-parse-even-better-errors@2.3.1
  • 78add03 npm-normalize-package-bin@1.0.1
  • 7595d70 normalize-package-data@3.0.0
  • 10175d8 chore(release): 2.1.2
  • fdbf082 fix: even better json errors, remove graceful-fs
  • e78afd6 chore(release): 2.1.1
  • b8cb5fa fix: normalize and sanitize pkg bin entries
  • 55382c2 chore(release): 2.1.0
  • 0a176cc Add some tests and clean up error handling for non-string bins
  • 76f6f42 feat: support bundleDependencies: true
  • 4e1e4d2 some tests for index.js parsing
  • 67f2d8d chore: update CI for current Node LTS

See the full diff

Package name: semver The new version differs by 202 commits.

See the full diff

Package name: update-notifier The new version differs by 42 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants