Skip to content
This repository has been archived by the owner on Jan 6, 2020. It is now read-only.

[Snyk] Upgrade commander from 2.9.0 to 2.20.3 #9

Merged
merged 1 commit into from Jan 6, 2020

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to upgrade commander from 2.9.0 to 2.20.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
  • The recommended version is 18 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2019-10-11.

The recommended version fixes:

Severity Issue
Prototype Pollution
SNYK-JS-LODASH-73638
Prototype Pollution
SNYK-JS-LODASH-450202
Regular Expression Denial of Service (ReDoS)
npm:tough-cookie:20170905
Prototype Pollution
npm:lodash:20180130
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
Release notes
Package name: commander
  • 2.20.3 - 2019-10-11

    Ran "npm unpublish commander@2.20.2". There is no 2.20.2.

    Fixed

    • Support Node.js 0.10 (Revert #1059)
  • 2.20.1 - 2019-09-28

    Fixed

    • Improve tracking of executable subcommands.

    Changed

    • update development dependencies

    Credits:

    • issue identified by Checkmarx Application Security Research Team
  • 2.20.0 - 2019-04-03
    • fix: resolve symbolic links completely when hunting for subcommands (#935)
    • Update index.d.ts (#930)
    • Update Readme.md (#924)
    • Remove --save option as it isn't required anymore (#918)
    • Add link to the license file (#900)
    • Added example of receiving args from options (#858)
    • Added missing semicolon (#882)
    • Add extension to .eslintrc (#876)
  • 2.19.0 - 2018-10-08
    • Removed newline after Options and Commands headers (#864)
    • Bugfix - Error output (#862)
    • Fix to change default value to string (#856)
  • 2.18.0 - 2018-09-07
  • 2.17.1 - 2018-08-07
  • 2.17.0 - 2018-08-04
  • 2.16.0 - 2018-06-29
  • 2.15.1 - 2018-03-20
  • 2.15.0 - 2018-03-08
  • 2.14.1 - 2018-02-07
  • 2.14.0 - 2018-02-06
  • 2.13.0 - 2018-01-11
  • 2.12.2 - 2017-11-28
  • 2.12.1 - 2017-11-23
  • 2.12.0 - 2017-11-22
  • 2.11.0 - 2017-07-03
  • 2.10.0 - 2017-06-23
  • 2.9.0 - 2015-10-13
from commander GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@temyers temyers merged commit 39a216a into master Jan 6, 2020
@temyers temyers deleted the snyk-upgrade-cc0fe19ec2ea7ce657f9af40095eba12 branch January 6, 2020 04:48
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants