Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @cypress/request from 2.88.7 to 2.88.8 #19107

Closed
wants to merge 1 commit into from

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • cli/package.json
⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 716/1000
Why? Recently disclosed, Has a fix available, CVSS 8.6
Prototype Pollution
SNYK-JS-JSONSCHEMA-1920922
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@snyk-bot snyk-bot requested a review from a team as a code owner November 25, 2021 08:38
@snyk-bot snyk-bot requested review from jennifer-shehane and removed request for a team November 25, 2021 08:38
@cypress-bot
Copy link
Contributor

cypress-bot bot commented Nov 25, 2021

Thanks for taking the time to open a PR!

@CLAassistant
Copy link

CLAassistant commented Nov 25, 2021

CLA assistant check)
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement) before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck) it.

@cypress
Copy link

cypress bot commented Nov 25, 2021



Test summary

18709 0 202 0Flakiness 5


Run details

Project cypress
Status Passed
Commit 71d92e0
Started Nov 29, 2021 5:54 PM
Ended Nov 29, 2021 6:06 PM
Duration 11:52 💡
OS Linux Debian - 10.10
Browser Multiple

View run in Cypress Dashboard ➡️


Flakiness

settings_spec.js Flakiness
1 Settings > file preference panel > loads preferred editor, available editors and shows spinner
commands/net_stubbing_spec.ts Flakiness
1 network stubbing > waiting and aliasing > can timeout waiting on a single request using "alias.request"
2 network stubbing > intercepting request > can modify the request body
cypress/proxy-logging-spec.ts Flakiness
1 Proxy Logging > request logging > xhr log has response body/status code
2 Proxy Logging > request logging > xhr log has response body/status code

This comment has been generated by cypress-bot as a result of this project's GitHub integration settings. You can manage this integration in this project's settings in the Cypress Dashboard

@jennifer-shehane
Copy link
Member

Duplicate of #19099

@jennifer-shehane jennifer-shehane marked this as a duplicate of #19099 Nov 29, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants