Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade npm from 6.0.0 to 6.11.1 #1

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk have raised this PR to upgrade npm from 6.0.0 to 6.11.1.

  • The recommended version is 43 versions ahead of your current version.
  • The recommended version was released 9 days ago, on 2019-08-21.

The recommended version fixes:

Severity Title Issue ID
Arbitrary File Overwrite SNYK-JS-FSTREAM-174725
Arbitrary File Overwrite SNYK-JS-TAR-174125
Arbitrary File Overwrite SNYK-JS-TAR-174125
Prototype Pollution npm:deep-extend:20180409
Prototype Pollution npm:extend:20180424
Uninitialized Memory Exposure npm:https-proxy-agent:20180402
Time of Check Time of Use (TOCTOU) npm:chownr:20180731
Insecure Randomness npm:cryptiles:20180710
Prototype Pollution npm:lodash:20180130
Uninitialized Memory Exposure npm:stringstream:20180511
Release notes

from npm GitHub Release Notes


🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant