Skip to content

[Snyk] Security upgrade npm from 8.19.2 to 10.2.0#12

Open
mgulter wants to merge 1 commit intomasterfrom
snyk-fix-61ab7b3e7e462e2ac8ec3ba4e9c29e2b
Open

[Snyk] Security upgrade npm from 8.19.2 to 10.2.0#12
mgulter wants to merge 1 commit intomasterfrom
snyk-fix-61ab7b3e7e462e2ac8ec3ba4e9c29e2b

Conversation

@mgulter
Copy link
Copy Markdown

@mgulter mgulter commented May 21, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
  • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: npm The new version differs by 250 commits.
  • 26415f4 chore: release 10.2.0
  • aa6728b deps: tar@6.2.0
  • ce9089f deps: npm-package-arg@11.0.1
  • 39d7f04 deps: minipass@7.0.4
  • 0a47af5 deps: hosted-git-info@7.0.1
  • af93130 deps: glob@10.3.10
  • 3ebc474 deps: @ npmcli/query@3.0.1
  • ba4d099 chore: @ npmcli/arborist@7.1.0
  • 284cbfd deps: @ npmcli/agent@2.2.0
  • 68031f2 docs: update `CONTRIBUTING.md` to prevent errors (#6844)
  • 0860159 fix: ensure workspace links query parents correctly (#6829)
  • 7c459d2 feat: add npm sbom command (#6801)
  • 3ac703c docs: add `include `param to commands that have `omit` param (#6831)
  • 6500218 chore: benchmark script fixes (#6824)
  • 9ffeb69 chore: use proxy instead of http-proxy (#6814)
  • 2207628 fix: use strip-ansi module instead of internal regex (#6823)
  • 03912db docs: add init-specific params to init docs/help (#6819)
  • 8088325 docs: Update npm-doctor.md (#6800)
  • 0270a7d chore: set workspace engines
  • 43241f6 fix: set engines to ^16.14.0 || >=18.0.0
  • 92e3f3f fix: set engines to ^16.14.0 || >=18.0.0
  • fec08ad chore: @ npmcli/template-oss@4.19.0
  • bef7481 fix: query with workspace descendents (#6782)
  • 0dc6332 chore: send benchmark dispatch to correct repo

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Note: This is a default PR template raised by Snyk. Find out more about how you can customise Snyk PRs in our documentation.

Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants