Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade chai from 4.2.0 to 4.3.10 #7

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

tiff-es
Copy link
Owner

@tiff-es tiff-es commented Oct 19, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade chai from 4.2.0 to 4.3.10.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 11 versions ahead of your current version.
  • The recommended version was released 22 days ago, on 2023-09-28.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GETFUNCNAME-5923417
609/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 8.6
Proof of Concept
Prototype Pollution
SNYK-JS-PATHVAL-596926
609/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 8.6
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: chai from chai GitHub release notes
Commit messages
Package name: chai
  • 744a16e 4.3.10
  • 0ccd823 upgrade all dependencies (#1540)
  • 923d0a4 4.3.9
  • 1a0f887 make
  • a141e57 upgrade deps
  • d9ff2c6 4.3.8
  • 8d3205b build
  • b351dc0 Fix: update exports.version to current version (#1534)
  • 1a8247f Update CONTRIBUTING.md (#1521)
  • 3a8c49a docs: specify return type of objDisplay (#1490)
  • b455124 test: fix typo in test.js (#1459)
  • 98f4233 build(deps): bump socket.io-parser from 4.0.4 to 4.0.5 (#1488)
  • acd16e0 chore: 4.x.x: Fix link to commit logs on GitHub (#1487)
  • 3c947a7 build
  • 775f509 4.3.7
  • 8e780b4 fix: deep-eql bump package to support symbols comparison (#1483)
  • 529b8b5 4.3.6
  • e4d7f2e build chaijs
  • d88684e fix: use loupe@^2.3.1
  • 99e36a8 4.3.5
  • fca5bb1 build chaijs
  • 747eb4e build(deps-dev): bump codecov from 3.1.0 to 3.7.1 (#1446)
  • 022c2fa fix package.json exports
  • 5276af6 fix: package.json - deprecation warning on exports field (#1400)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants