Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Fix for 1 vulnerabilities #34

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

fishbar
Copy link
Owner

@fishbar fishbar commented Jun 21, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • deps/npm/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: init-package-json The new version differs by 39 commits.

See the full diff

Package name: node-gyp The new version differs by 250 commits.

See the full diff

Package name: normalize-package-data The new version differs by 23 commits.

See the full diff

Package name: npm-install-checks The new version differs by 25 commits.
  • 9b68df3 4.0.0
  • d498feb allow engine if npm version not specified
  • f9cc89a update travis to only include live nodes
  • 0fc0126 auto-publish scripts
  • ca36bca update changelog for v4
  • a0d38b4 update docs for v4
  • 44b7124 Simplified functionality needed for npm v7
  • 1646fd7 remove unnecessary deps and metadata
  • d74d479 chore: project settings
  • d4463a3 chore(deps): update semver, tap, standard
  • 89937d4 minimal package
  • 893b181 fix: allow pre-release versions of npm and node
  • ab92033 chore: bump version of semver package
  • aafb4ee deps: bump deps
  • f8cc119 chore: update CI for current Node LTS
  • 49d3ea3 3.0.0
  • d119860 doc: Add changelog to track what broke in breaking changes
  • a0310d9 tests: Push out to 100% coverage for existing tests
  • 0ee0512 src: Eliminate logging side effects, return warnings instead
  • 723b227 gitignore: Ignore coverage data dir
  • 7cf37bc travis: install newer npm before we start
  • 6a72c1d travis: move to container builds
  • 4c238a1 tap@5.0.1
  • 7aeaa31 src: switch formatting to standard

See the full diff

Package name: npm-package-arg The new version differs by 62 commits.

See the full diff

Package name: read-package-json The new version differs by 17 commits.
  • 9f7049d chore(release): 3.0.0
  • 19d9fbe fix: check-in updated lockfile
  • eef46fa chore: add engines definition
  • 36b7ef7 chore: remove old .travis.yml envs
  • b3a8831 globa@7.1.6
  • fb3ceae json-parse-even-better-errors@2.3.1
  • 78add03 npm-normalize-package-bin@1.0.1
  • 7595d70 normalize-package-data@3.0.0
  • 10175d8 chore(release): 2.1.2
  • fdbf082 fix: even better json errors, remove graceful-fs
  • e78afd6 chore(release): 2.1.1
  • b8cb5fa fix: normalize and sanitize pkg bin entries
  • 55382c2 chore(release): 2.1.0
  • 0a176cc Add some tests and clean up error handling for non-string bins
  • 76f6f42 feat: support bundleDependencies: true
  • 4e1e4d2 some tests for index.js parsing
  • 67f2d8d chore: update CI for current Node LTS

See the full diff

Package name: semver The new version differs by 250 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants