Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Fix for 4 vulnerabilities #47

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

gregswindle
Copy link
Collaborator

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
No Proof of Concept
high severity 654/1000
Why? Has a fix available, CVSS 8.8
Authentication Bypass by Spoofing
SNYK-JS-AUTOLINKER-2438289
Yes No Known Exploit
medium severity 551/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.6
Cross-site Scripting (XSS)
SNYK-JS-AUTOLINKER-564438
Yes Proof of Concept
medium severity 459/1000
Why? Has a fix available, CVSS 4.9
Denial of Service (DoS)
SNYK-JS-AUTOLINKER-73494
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: generator-license The new version differs by 9 commits.
  • 353820c 5.2.0
  • 61bee83 Update to yeoman-generator 2.0 + latest generator scaffolding (prettier & cie)
  • ca1494b Update jest to version 19.0.1 🚀 (#67)
  • 83679de chore(package): update yeoman-assert to version 3.0.0 (#63)
  • dd9ce93 add a link to Creative Commons generator (self-plug ;) (#62)
  • d1ef27b add GNU LGPL-3.0 License (#61)
  • 38bc9eb Eslint and nsp (#58)
  • 8de2d27 Update Travis test matrix
  • e2473fb Run test with jest and send coverage results to coveralls

See the full diff

Package name: generator-node The new version differs by 13 commits.
  • ddd83c8 v2.4.0
  • d6ad8eb Update Yarn lockfile
  • c7c85e3 Update dependencies (#278)
  • 129c233 Add support for scoped package (Fix #272) (#275)
  • fd50d93 Setup coverage output in the terminal
  • 4fec892 Replace deprecated prepublish by prepublishOnly (#271)
  • 32f1c96 Correct opencollective badge
  • 80e7e9c Update README.md (#270)
  • e1260dc Bump dependencies
  • a791156 Update the generator/git to ES6 Class (#269)
  • ad88f00 Bump dependencies
  • ad67e66 2.3.0
  • 5c4e722 [Feature] Adding Pre-commit hook and Prettier (#267)

See the full diff

Package name: markdown-magic The new version differs by 67 commits.

See the full diff

Package name: update-notifier The new version differs by 7 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Cross-site Scripting (XSS)

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants