Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Security upgrade mocha from 8.1.3 to 8.2.0 #169

Merged
merged 1 commit into from
Oct 17, 2020

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 514/1000
Why? Has a fix available, CVSS 6
Prototype Pollution
SNYK-JS-FLAT-596927
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: mocha The new version differs by 29 commits.
  • afe8daa Release v8.2.0
  • 20d3d4c update CHANGELOG for v8.2.0 [ci skip]
  • 932c09a fix scripts/linkify-changelog to not blast fenced code blocks
  • 3b333ec chore(deps): chokidar@3.4.3
  • 058b2e7 attempt to force colors in karma config
  • 60e3662 replace promise.allsettled with @ungap/promise-all-settled; closes #4474
  • f132448 remove duplicated/problem reporter tests; closes #4469
  • 31116db fix: remove job count from parallel mode debug log (#4416)
  • 478ca6a add "fixture flowchart" to docs (#4440)
  • 9c28990 support leading dots in --extension
  • 2852505 chore(deps): upgrade to latest stable
  • b216fcd Support multipart extensions like ".test.js" (#4442)
  • 1aa182b refactor: utils.type() (#4457); closes #4306
  • fd9fe95 Change serializer errors to use error codes (#4464)
  • 6ceca82 make guarantees about orphaned processes
  • f24f190 avoid deprecated add-path in GHA workflow
  • ca9bfc7 parallel mode: enable custom worker reporters and object references (#4409); closes #4403
  • df8e9e6 run all node.js tests on GHA (#4459)
  • 238268d cleanup a little bit of eslint config
  • 8f5d6a9 Update eslint version (#4443)
  • bb96de1 implement Open Collective categories for extended filtering
  • 28f970e ci(win): setup GH actions for windows CI (#4402)
  • 738a575 Add speed in -R json option (#4226) (#4434)
  • 5bdc208 remove unused interface tests (#4247)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@snyk-bot snyk-bot requested a review from badsyntax as a code owner October 17, 2020 06:28
@badsyntax badsyntax merged commit 949a4cf into master Oct 17, 2020
@badsyntax badsyntax deleted the snyk-fix-0beb98390a40512ba38575ff82ddd9db branch October 17, 2020 08:38
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants