Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade np from 7.6.2 to 10.0.6 #18

Open
wants to merge 1 commit into
base: dev
Choose a base branch
from

Conversation

Chere3
Copy link
Contributor

@Chere3 Chere3 commented Jul 10, 2024

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to upgrade np from 7.6.2 to 10.0.6.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

  • The recommended version is 18 versions ahead of your current version.

  • The recommended version was released on 21 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
482 Proof of Concept
high severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
482 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
482 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
482 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
482 Proof of Concept
medium severity Open Redirect
SNYK-JS-GOT-2932019
482 No Known Exploit
medium severity Open Redirect
SNYK-JS-GOT-2932019
482 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
482 Proof of Concept
Release notes
Package name: np from np GitHub release notes

Important

  • Warning: This PR contains a major version upgrade, and may be a breaking change.
  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade np from 7.6.2 to 10.0.6.

See this package in npm:
np

See this project in Snyk:
https://app.snyk.io/org/chere3/project/a89e8a75-4f80-4ef9-a3ba-727fc1a20520?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@sindresorhus/is@5.6.0 None 0 61.3 kB sindresorhus
npm/@szmarczak/http-timer@5.0.1 None 0 10.2 kB szmarczak
npm/@types/http-cache-semantics@4.0.4 None 0 9.28 kB types
npm/@types/normalize-package-data@2.4.4 None 0 5.81 kB types
npm/aggregate-error@4.0.1 None +1 11.2 kB sindresorhus
npm/boxen@7.1.1 None +6 279 kB sindresorhus
npm/cacheable-lookup@7.0.0 None 0 25.2 kB sindresorhus
npm/cacheable-request@10.2.14 None +1 81.3 kB jaredwray
npm/camelcase@7.0.1 None 0 11.7 kB sindresorhus
npm/chalk@5.3.0 None 0 43.7 kB sindresorhus
npm/clean-stack@4.2.0 None 0 6.76 kB sindresorhus
npm/cli-boxes@3.0.0 None 0 6.62 kB sindresorhus
npm/configstore@6.0.0 None 0 7.58 kB sindresorhus
npm/cosmiconfig@8.3.6 filesystem Transitive: environment +3 660 kB d-fischer
npm/crypto-random-string@4.0.0 None +1 157 kB sindresorhus
npm/decompress-response@6.0.0 None +1 11.5 kB sindresorhus
npm/del@7.1.0 Transitive: environment, filesystem +10 168 kB sindresorhus
npm/escape-goat@4.0.0 None 0 6.28 kB sindresorhus
npm/escape-string-regexp@5.0.0 None 0 3.66 kB sindresorhus
npm/execa@8.0.1 environment Transitive: filesystem, shell +7 138 kB ehmicky
npm/fast-glob@3.3.2 filesystem +13 464 kB mrmlnc
npm/get-stream@8.0.1 None 0 25.2 kB ehmicky
npm/globby@13.2.2 Transitive: filesystem +2 36 kB sindresorhus
npm/got@12.6.1 Transitive: network +4 375 kB sindresorhus
npm/graceful-fs@4.2.11 environment, filesystem 0 32.5 kB isaacs
npm/hosted-git-info@7.0.2 None 0 26.6 kB npm-cli-ops
npm/http-cache-semantics@4.1.1 None 0 35.9 kB kornel
npm/human-signals@5.0.0 None 0 26 kB ehmicky
npm/ignore-walk@6.0.5 filesystem 0 13.2 kB npm-cli-ops
npm/ignore@5.3.1 None 0 51.5 kB kael
npm/import-lazy@4.0.0 None 0 4.9 kB sindresorhus
npm/ini@4.1.1 None 0 12.7 kB npm-cli-ops
npm/inquirer@9.3.5 Transitive: environment +26 669 kB sboudrias
npm/is-docker@3.0.0 None 0 3.15 kB sindresorhus
npm/is-installed-globally@1.0.0 Transitive: environment +1 12 kB sindresorhus
npm/is-npm@6.0.0 environment 0 5.04 kB sindresorhus
npm/is-path-cwd@3.0.0 None 0 3.16 kB sindresorhus
npm/is-path-inside@4.0.0 None 0 4.2 kB sindresorhus
npm/is-scoped@3.0.0 None 0 2.7 kB sindresorhus
npm/is-stream@3.0.0 None 0 6.23 kB sindresorhus
npm/is-url-superb@6.1.0 None 0 3.25 kB sindresorhus
npm/is-wsl@3.1.0 environment +1 6.93 kB sindresorhus
npm/issue-regex@4.1.0 None 0 3.51 kB sindresorhus
npm/keyv@4.5.4 None 0 27.8 kB jaredwray
npm/latest-version@7.0.0 None 0 4.13 kB sindresorhus
npm/log-symbols@6.0.0 Transitive: environment +1 8.13 kB sindresorhus
npm/lowercase-keys@3.0.0 None 0 3.32 kB sindresorhus
npm/lru-cache@10.4.3 None 0 804 kB isaacs
npm/meow@13.2.0 None 0 419 kB sindresorhus
npm/mimic-fn@4.0.0 None 0 8.18 kB sindresorhus
npm/mimic-response@4.0.0 None 0 6.2 kB sindresorhus
npm/minimatch@9.0.5 environment +2 453 kB isaacs
npm/new-github-release-url@2.0.0 None 0 6.17 kB sindresorhus
npm/normalize-package-data@6.0.2 None 0 28.2 kB npm-cli-ops
npm/normalize-url@8.0.1 None 0 25.9 kB sindresorhus
npm/np@10.0.6 Transitive: environment, eval +81 7.14 MB sindresorhus
npm/npm-name@8.0.0 None +4 196 kB sindresorhus
npm/npm-run-path@5.3.0 environment +1 12.5 kB sindresorhus
npm/onetime@7.0.0 None +1 13.5 kB sindresorhus
npm/open@10.1.0 environment +6 80.1 kB sindresorhus
npm/p-cancelable@3.0.0 None 0 13.4 kB sindresorhus
npm/p-map@5.5.0 None 0 16.7 kB sindresorhus
npm/p-memoize@7.1.1 None +1 290 kB sindresorhus
npm/p-timeout@6.1.2 None 0 12 kB sindresorhus
npm/package-json@8.1.1 None 0 12.9 kB sindresorhus
npm/pkg-dir@8.0.0 None +1 12.1 kB sindresorhus
npm/pupa@3.1.0 None 0 6.92 kB sindresorhus
npm/registry-auth-token@5.0.2 environment Transitive: filesystem, network +6 124 kB rexxars
npm/registry-url@6.0.1 None 0 4.29 kB sindresorhus
npm/responselike@3.0.0 None 0 5.55 kB sindresorhus
npm/rxjs@7.8.1 None +1 4.59 MB blesh
npm/scoped-regex@3.0.0 None 0 3.52 kB sindresorhus
npm/semver-diff@4.0.0 None 0 5.17 kB sindresorhus
npm/semver@7.6.2 None 0 95.4 kB npm-cli-ops
npm/signal-exit@4.1.0 None 0 77 kB isaacs
npm/slash@4.0.0 None 0 3.83 kB sindresorhus
npm/strip-final-newline@3.0.0 None 0 3.36 kB sindresorhus
npm/symbol-observable@4.0.0 eval 0 16.8 kB blesh
npm/terminal-link@3.0.0 None +1 22.6 kB sindresorhus
npm/unique-string@3.0.0 None 0 2.79 kB sindresorhus
npm/update-notifier@7.0.0 environment Transitive: filesystem +3 26.5 kB sindresorhus
npm/validate-npm-package-name@5.0.1 unsafe 0 7.77 kB npm-cli-ops
npm/widest-line@4.0.1 None +3 121 kB sindresorhus
npm/wrap-ansi@6.2.0 None 0 9.5 kB sindresorhus
npm/xdg-basedir@5.1.0 None 0 6.81 kB sindresorhus

🚮 Removed packages: npm/ini@1.3.7, npm/mimic-response@2.1.0, npm/np@7.6.2, npm/registry-url@5.1.0

View full report↗︎

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants