Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade prismjs from 1.18.0 to 1.23.0 #10

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

@snyk-bot snyk-bot commented Jun 1, 2021

Snyk has created this PR to upgrade prismjs from 1.18.0 to 1.23.0.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 5 versions ahead of your current version.
  • The recommended version was released 5 months ago, on 2020-12-31.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Cross-site Scripting (XSS)
SNYK-JS-PRISMJS-597628
629/1000
Why? Has a fix available, CVSS 8.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PRISMJS-1076581
629/1000
Why? Has a fix available, CVSS 8.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: prismjs from prismjs GitHub release notes
Commit messages
Package name: prismjs

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@guardrails
Copy link

guardrails bot commented Jun 1, 2021

⚠️ We detected 25 security issues in this pull request:

Vulnerable Libraries (25)
Severity Details
Medium acorn@7.1.0 upgrade to `>5.7.3
High axios@0.19.0 - no patch available
High bl@3.0.0 upgrade to `>1.2.2
Medium browserslist@3.2.8 upgrade to >4.16.4
High decompress@4.2.0 upgrade to >=4.2.1
High dns-packet@1.3.1 upgrade to `>=1.3.2
High dot-prop@4.2.0 upgrade to `>=4.2.1
High elliptic@6.5.2 upgrade to >6.5.3
Medium hosted-git-info@2.8.5 upgrade to `>=2.8.9
High http-proxy@1.18.0 upgrade to >=1.18.1
High lodash@4.17.15 upgrade to >4.17.20
High node-forge@0.9.0 upgrade to >0.9.2
High object-path@0.11.4 upgrade to 0.11.5
Medium postcss@7.0.26 - no patch available
Medium sanitize-html@1.20.1 - no patch available
High serialize-javascript@2.1.2 upgrade to >=3.1.0
Critical socket.io@2.3.0 upgrade to `>2.3.0
Medium ssri@6.0.1 upgrade to `>6.0.1
High trim@0.0.1 - no patch available
High ua-parser-js@0.7.21 upgrade to >0.7.23
High url-parse@1.4.7 upgrade to >=1.5.0
High url-regex@4.1.1 upgrade to *
Medium websocket-extensions@0.1.3 upgrade to >=0.1.4
Critical xmlhttprequest-ssl@1.5.5 upgrade to >1.6.1
High y18n@4.0.0 upgrade to >=5.0.5

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant