Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Fix for 1 vulnerabilities #68

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

ryan-ally
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: metalsmith The new version differs by 196 commits.
  • ba18d85 Release 2.6.0
  • d5ce2c8 Prepare changelog for 2.6.0
  • baee1de Removes stray cross-spawn dependency & use --no-package-lock for CI
  • 17e421b test: migrate from nyc to c8 for coverage reports
  • 2ef473b types: fix source code link line numbers
  • e12537f feat/add v0.12.8 announcement post nodejs/nodejs.org#379 - use lodash.clonedeepwith instead, document watch type, fix issues in CLI
  • 9d40674 Resolves add v0.12.8 announcement post nodejs/nodejs.org#379: add metalsmith.watch option setter and watcher
  • 48a0167 fix: package.json node version, type docs, readme formatting
  • 3a93270 test: fix FS race condition in #build should return a promise only when callback omitted
  • dbfe32a docs: Updates readme examples to ESM & Gitter link to Matrix Element
  • 4469020 CLI: Fix ESM dynamic import issue with absolute paths on Windows
  • 58217a5 Adds CLI support & tests for loading ESM configs or Metalsmith instances
  • c272b8b ci: remove Node 12, add Node 20
  • 0810728 Updates commander from 8.3.0 -> 10.0.1
  • ae05945 Removes rimraf dependency, refactors helpers using fs/promises and upgrades @ types/node
  • 80d8508 Drops support for Node < 14
  • 3754a6a chore: Remove stray console.error log in bin
  • acb363e Trims whitespace from parsed front-matter excerpt and adds test for dynamic front-matter lang
  • 2bfe800 Fix: don't keep gray-matter excerpt at the start of file contents
  • 7ec31d0 Adds a matter member object to metalsmith instance with stringify & parse methods
  • 424e6ec Support 'module.exports = Metalsmith()'-style configs in CLI
  • 82969ef dev: update devDependencies & fix security warnings
  • 58db90c ci: remove obsolete Gitter notification flow
  • 58d22a3 Resolves Be consistent with quotes in examples. nodejs/nodejs.org#356: adds Typescript support to Metalsmith package

See the full diff

Package name: standard The new version differs by 82 commits.
  • fa0c1e4 update authors
  • 81de719 16.0.0
  • 9f94f98 prep changelog for 16.0.0
  • f5b298a standard-engine@14
  • 9f73bf2 eslint-config-standard-jsx@10
  • 0ce671d eslint-config-standard@16
  • dfea036 changelog
  • c167c0a disable failing repos for 'no-var' rule
  • 24ddf3f changelog
  • 258ee48 disable no-var rule for cmd since it needs to run on all node versions
  • 59dc70e remove eslint-plugin-standard
  • 7c7dbec changelog
  • 6fbe538 test: fix logs
  • e5e0b37 test: disable failing repos
  • a98eba7 test: re-enable disabled repos which now pass!
  • 0bfd793 test: disable non-existent repo
  • 6f9f2f1 test: add script to detect non-existent repos
  • 0d429d0 test: remove non-existant repo
  • 0b64eb3 test: add --write option to save changes to "disable" prop
  • 8b97b72 test: add test packages into same repo
  • e1b0466 changelog
  • 692c0fe changelog
  • c30a584 remove mkdirp dependency
  • d1f9de1 remove broken eslint-index package

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants