Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade npm from 6.2.0 to 6.13.6 #102

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade npm from 6.2.0 to 6.13.6.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
  • The recommended version is 46 versions ahead of your current version.
  • The recommended version was released 8 days ago, on 2020-01-09.

The recommended version fixes:

Severity Issue
Arbitrary File Overwrite
SNYK-JS-TAR-174125
Arbitrary File Write
SNYK-JS-NPM-537606
Arbitrary File Overwrite
SNYK-JS-NPM-537603
Arbitrary File Overwrite
SNYK-JS-FSTREAM-174725
Arbitrary File Write
SNYK-JS-BINLINKS-537610
Arbitrary File Overwrite
SNYK-JS-BINLINKS-537608
Man-in-the-Middle (MitM)
SNYK-JS-HTTPSPROXYAGENT-469131
Unauthorized File Access
SNYK-JS-NPM-537604
Unauthorized File Access
SNYK-JS-BINLINKS-537609
Release notes
Package name: npm from npm GitHub release notes
Commit messages
Package name: npm
  • ac3739f 6.13.6
  • c56c847 docs: changelog for 6.13.6
  • 6dba897 pacote@9.5.12
  • 787bb66 6.13.5
  • e099866 update AUTHORS
  • 4812866 docs: changelog for 6.13.5
  • 6fb5dbb npm-link: clarify usage of global prefix
  • 4b30f3c feat(version): using 'allow-same-version', git commit --allow-empty and git tag -f
  • e0a7a2f chore: ci cleanup
  • 3f009fb Fix bin-overwriting test on Windows
  • 9295046 CI: switch to `actions/checkout@v2`
  • 4a669be Remove the unused appveyor.yml
  • 43ae079 CI: add `fail-fast: false`
  • fd0a802 Fix cache location for `npm ci`
  • e16f68d test(ci): add failing cache config test
  • f2d770a chore: fix netlify publish path config
  • 462cf09 docs: update gatsby dependencies
  • 797a597 test: fix lint error
  • fd29398 6.13.4
  • f2aca36 docs: changelog for 6.13.4
  • 320ac9a Do not remove global bin/man links inappropriately
  • d06f5c0 bin-links@1.1.6
  • 52fd210 gentle-fs@2.3.0
  • 45482c2 6.13.3

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant