Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade newman from 4.5.7 to 5.1.2 #9

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-LODASH-567746
Yes Proof of Concept
Commit messages
Package name: newman The new version differs by 206 commits.
  • e618e8e Merge branch 'release/5.1.2'
  • d344a1f Update postman-collection-transformer to version 3.3.3
  • 366b481 Merge branch 'release/5.1.2' into develop
  • 9ec6c77 Merge branch 'release/5.1.2'
  • e6077ab Release v5.1.2
  • 600493b Update system test
  • 76b4722 Update getpostman.com -> postman.com
  • 3455a65 Update dependencies
  • c30b1c5 Merge branch 'release/5.1.1' into develop
  • 0515695 Merge branch 'release/5.1.1'
  • 64b743f Release v5.1.1
  • d3858d8 Merge pull request #2398 from postmanlabs/dependabot/npm_and_yarn/mocha-8.0.1
  • b586ac8 Merge branch 'develop' into dependabot/npm_and_yarn/mocha-8.0.1
  • c7e450e Chore(deps-dev): bump mocha from 7.2.0 to 8.0.1
  • 5137161 Merge pull request #2426 from postmanlabs/dependabot/npm_and_yarn/chardet-1.2.1
  • b1fa61b Merge pull request #2418 from postmanlabs/dependabot/npm_and_yarn/nock-13.0.2
  • 604e6b9 Merge pull request #2425 from postmanlabs/dependabot/npm_and_yarn/eslint-7.4.0
  • cc1b9fa Chore(deps): bump chardet from 1.1.0 to 1.2.1
  • 040f5ca Chore(deps-dev): bump nock from 12.0.3 to 13.0.2
  • c1dd59c Chore(deps-dev): bump eslint from 7.2.0 to 7.4.0
  • 977545e Merge pull request #2403 from postmanlabs/dependabot/npm_and_yarn/postman-runtime-7.26.1
  • 70bdc6b Merge branch 'develop' into dependabot/npm_and_yarn/postman-runtime-7.26.1
  • cc52dfb Update integration test coverage threshold
  • 318fbce Skip failing /redirect-to tests

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
馃 View latest project report

馃洜 Adjust project settings

馃摎 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant