Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Fix for 1 vulnerabilities #83

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

supermarsx
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: electron-packager The new version differs by 68 commits.
  • b56ea8a 17.0.0
  • 34c3c4e docs: update NEWS.md for v17.0.0
  • 21bb953 refactor: migrate from asar to @ electron/asar (#1431)
  • 274c686 feat!: upgrade electron-osx-sign to @ electron/osx-sign (#1428)
  • c02695f fix: remove ElectronAsarIntegrity when asar is disabled (#1281)
  • f6e353a chore: Revert "chore: bump typedoc from 0.19.2 to 0.23.14 (#1416)" (#1420)
  • 713d425 fix(types): add "universal" as a valid arch (#1407)
  • 18749c7 chore: bump typedoc from 0.19.2 to 0.23.14 (#1416)
  • 9124e28 16.0.0
  • 88e8173 docs: Update NEWS.md
  • 5c0102a fix: properly import info logger (#1405)
  • 0d692d7 feat!: upgrade Node.js to 14 LTS (#1399)
  • a723fa8 build: bump got to 2.0.0 (#1397)
  • 8a86df2 15.5.2
  • c7ecd1c docs: update NEWS.md
  • 1baed70 chore: remove node 10 job (#1403)
  • 7c01d6f revert: "feat!: upgrade Node.js to 14 LTS (#1393)" (#1398)
  • b0f27bc fix: ignore node_gyp_bins if it exists (#1391)
  • a6db65f chore: bump fs-extra from 9.1.0 to 10.1.0 (#1358)
  • 7dcaf44 chore(deps): bump yargs-parser from 20.2.9 to 21.1.1 (#1395)
  • c6b4c78 feat!: upgrade Node.js to 14 LTS (#1393)
  • e147b5e docs: update SUPPORT.md
  • a65eb75 fix: package should not log info on --quiet flag (#1361)
  • 4c6c88f chore: bump sinon from 13.0.2 to 14.0.0 (#1364)

See the full diff

Package name: snyk The new version differs by 250 commits.
  • 4cc1a94 Merge pull request #2105 from snyk/feat/webpack
  • 7737f75 Merge pull request #2181 from snyk/test/migrate-old-snyk-format
  • 418e6ad Merge pull request #2180 from snyk/test/migrate-is-docker
  • 95631e7 test: migrate is-docker to jest
  • babe22a test: migrate old-snyk-format to jest
  • e22e94f feat: Snyk CLI is bundled with Webpack
  • dd46c19 Merge pull request #2175 from snyk/fix/snyk-protect-multiple
  • e7c314f Merge pull request #2178 from snyk/test/server-close
  • 5e824c0 fix(protect): skip previously patched files
  • ca2177a fix(protect): catch and log unexpected errors
  • c9ddb44 chore(protect): move api url warnings to stderr
  • e8fed38 refactor(protect): move stdout logs to top level
  • 55e88f9 Merge pull request #2177 from snyk/test/set-jest-acceptance-timeout
  • 1522c5f test: server.close uses callbacks, not promises
  • 13dce51 test: increase timeout for slow oauth test
  • 65c35be Merge pull request #2172 from snyk/chore/no-run-test-on-master
  • a1e3992 chore: don't run tests on master
  • 20feb67 Merge pull request #2165 from snyk/chore/dont-wait-for-regression-tests
  • f50bca7 Merge pull request #2167 from snyk/refactor/replace-cc-parser-with-split-functions
  • 1ed7d11 refactor: replace cc parser with split functions
  • 707801d Merge pull request #2166 from snyk/fix/support_quotes_in_poetry_toml
  • dc6b784 Merge pull request #2163 from snyk/chore/remove-store-test-results
  • 7973015 fix: support quoted keys in inline tables
  • 18f0d2a Merge pull request #2164 from snyk/chore/upgrade-snyk-nuget-plugin

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants