Skip to content
This repository was archived by the owner on Feb 7, 2023. It is now read-only.

[Snyk] Fix for 1 vulnerabilities#193

Open
vladimyr wants to merge 1 commit intodevelopfrom
snyk-fix-ac38f93a62c15f227af408fa2aaf2075
Open

[Snyk] Fix for 1 vulnerabilities#193
vladimyr wants to merge 1 commit intodevelopfrom
snyk-fix-ac38f93a62c15f227af408fa2aaf2075

Conversation

@vladimyr
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: node-sass The new version differs by 74 commits.
  • 99242d7 7.0.1
  • 77049d1 build(deps): bump sass-graph from 2.2.5 to 4.0.0 (#3224)
  • c929f25 build(deps): bump node-gyp from 7.1.2 to 8.4.1 (#3209)
  • 918dcb3 Lint fix
  • 0a21792 Set rejectUnauthorized to true by default (#3149)
  • e80d4af chore: Drop EOL Node 15 (#3122)
  • d753397 feat: Add Node 17 support (#3195)
  • dcf2e75 build(deps-dev): bump eslint from 7.32.0 to 8.0.0
  • bfa1a3c build(deps): bump actions/setup-node from 2.4.0 to 2.4.1
  • 80d6c00 chore: Windows x86 on GitHub Actions (#3041)
  • 566dc27 build(deps-dev): bump fs-extra from 0.30.0 to 10.0.0 (#3102)
  • 7bb5157 build(deps): bump npmlog from 4.1.2 to 5.0.0 (#3156)
  • 2efb38f build(deps): bump chalk from 1.1.3 to 4.1.2 (#3161)
  • fca5257 build(deps): bump actions/setup-node from 2.3.0 to 2.4.0
  • 6200b21 docs: Double word "support" (#3159)
  • eaf791a build(deps): bump actions/setup-node from 2.1.5 to 2.3.0
  • 16b8d4b build(deps): bump coverallsapp/github-action from 1.1.2 to 1.1.3
  • c167004 6.0.1
  • 911d4db remove mkdirp dep (#3108)
  • 30a52f7 build(deps): bump meow from 3.7.0 to 9.0.0
  • 7e08463 build(deps-dev): bump mocha from 8.4.0 to 9.0.1
  • cfcbb2c chore: Use default Apline version from docker-node (#3121)
  • 886319b chore: Drop Node 10 support
  • c908f4f fix: Bump OSX minimum to 10.11

See the full diff

Package name: sequelize-cli The new version differs by 13 commits.
  • 3d3f74a 6.3.0
  • 8bfe993 Prepare v6.3.0
  • eaf7216 fix: lint errors #967 (#968)
  • b00fc76 Create FUNDING.yml
  • be5b445 fix(migrator): do not match `.d.ts` files by default (#928)
  • 7dad0d3 Fixes minor formatting typo in documentation (#916)
  • 929bfdd fix(deps): update dependency fs-extra to v9 (#922)
  • 34373a1 fix(deps): update dependency yargs to v15 (#923)
  • 4084eee fix(deps): update dependency cli-color to v2 (#921)
  • a8cd526 chore(deps): update dependency through2 to v4 (#920)
  • 9a05a22 chore(deps): update dependency mocha to v8 (#919)
  • 8d23192 chores: update renovate config
  • 278c0f8 chore(deps): add renovate.json (#917)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants