Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade npm from 6.11.2 to 6.14.2 #4

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade npm from 6.11.2 to 6.14.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
  • The recommended version is 15 versions ahead of your current version.
  • The recommended version was released 6 days ago, on 2020-03-03.

The recommended version fixes:

Severity Issue Exploit Maturity
Arbitrary File Write
SNYK-JS-NPM-537606
Proof of Concept
Arbitrary File Overwrite
SNYK-JS-NPM-537603
Proof of Concept
Unauthorized File Access
SNYK-JS-NPM-537604
Proof of Concept
Release notes
Package name: npm from npm GitHub release notes
Commit messages
Package name: npm
  • d9a7b30 6.14.2
  • ec5e45d docs: changelog for 6.14.2
  • f924929 node-gyp@5.1.0
  • 9204ffa npm-profile@4.0.4
  • 0365d39 glob@7.1.6
  • 909cc39 hosted-git-info@2.8.8
  • f9248c0 chore(docs): update unpublish docs with both commands, removing policy info from cli docs, and added reference to unpublish policy docs
  • 3b9c135 6.14.1
  • 1de223b docs: changelog for 6.14.1
  • 303e5c1 hosted-git-info@2.8.7
  • 83293c4 6.14.0
  • e01f338 update AUTHORS
  • 31ca3a8 docs: changelog for 6.14.0
  • 7602146 hosted-git-info@2.8.6
  • 3d48893 readable-stream@3.6.0
  • ea0ff56 npm-registry-fetch@4.0.3
  • 89ce4cc npm-packlist@1.4.8
  • a6789b1 chownr@1.1.4
  • d383adb fix: supported version implementation update linting & test coverage
  • 28c3d40 Use a package.json engines field to specify support
  • 0769c5b allow new majors of node to be automatically considered supported
  • 30f1708 fund: support multiple funding sources
  • 373224b Update npm-publish.md
  • f6ff417 updated script to say postinstall to show intention

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant