Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #142

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

sheerun
Copy link
Owner

@sheerun sheerun commented Nov 30, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: lint-staged The new version differs by 80 commits.
  • 072924f Merge pull request #724 from okonet/beta
  • f9e128d docs: Improve config section documentation
  • e1cd6ba Merge branch 'master' into beta
  • af58e6e docs: refine examples formatting (#767)
  • 82bee06 Merge branch 'master' into beta
  • af4604a docs: Improve documentation on the --debug flag (#766)
  • bd3721f Merge branch 'master' into beta
  • 8bdeec0 feat: throw error to prevent empty commits unless --allow-empty is used (#762)
  • 2cd1d37 docs: add funding property to package.json linking to Open Collective (#763)
  • 056723b docs: Document how to deal with eslintignore warnings (#759)
  • 30b4809 fix: error handling skips dropping backup stash after internal git errors
  • da22cf2 fix: handle git MERGE_* files separately; improve error handling
  • 20d5c5d feat: support async function tasks
  • f2a2702 Merge branch 'master' into beta
  • 1b64239 fix: fail with a message when backup stash is missing
  • 9913bb2 test: do not write file into repo during test run
  • d091f71 fix: correctly recover when unstaged changes cannot be restored
  • f8ddfc2 fix: restore metadata about git merge before running tasks
  • 22ba124 refactor: minor optimizations
  • f3ae378 fix: better workaround for git stash --keep-index bug
  • 33b9752 docs: improve example perfomance by returning single command (#753)
  • 083b8e7 fix: automatically add modifications only to originally staged files
  • 814b9df feat: bump Node.js version dependency to at least 10.13.0 (#747)
  • 0eedacd test: remove non-working concurrency tests for now

See the full diff

Package name: prettierx The new version differs by 250 commits.
  • e96b04d prettierx 0.19.0
  • 8968c39 prettierx: Update postcss -> 8.3.5 - dependency (#648)
  • 420328f prettierx: Update @ typescript-eslint/typescript-estree -> 4.28.2 - dependency (#638)
  • 2a90a09 prettierx: Update webpack -> 5.42.1 - devDependency (#614)
  • e66a5a4 [prettierx] chore: update renovate.json re: x-unsupported
  • c1f65b8 [prettierx] merge PR #630
  • f7c4bb6 [prettierx] chore: update CHANGELOG.md re: 0.19.0-01 (...)
  • d4e08c9 [prettierx] merge updates from Prettier main branch
  • eaa31de [prettierx] docs: combine 7933.md into CHANGELOG.md
  • c10ae7e [prettierx] test: update html-tags-with-void-tags (...)
  • cf90dda [prettierx] Merge branch 'dev' into 0.19.0-01-update-branch
  • e9d20e5 [prettierx] test: add html-tags-with-void-tags (...)
  • bf5c9dd [prettierx] fix-up re: apply language-js features (...)
  • 159fc3d Build(deps-dev): Bump eslint from 7.29.0 to 7.30.0 (#11156)
  • 840a9db Build(deps): Bump typescript from 4.3.4 to 4.3.5 (#11158)
  • 6c57261 Build(deps-dev): Bump webpack from 5.40.0 to 5.42.0 in /website (#11152)
  • 4889b17 Build(deps-dev): Bump @ types/estree from 0.0.48 to 0.0.49 (#11160)
  • 1fd627f Build(deps-dev): Bump eslint-plugin-unicorn from 33.0.1 to 34.0.1 (#11163)
  • a2b2eac Build(deps): Bump @ typescript-eslint/typescript-estree (#11166)
  • 50addfa Build(deps-dev): Bump @ glimmer/reference from 0.79.4 to 0.80.0 (#11153)
  • 06a7ffb Build(deps): Bump jest-docblock from 27.0.1 to 27.0.6 (#11165)
  • 5310dd3 Build(deps-dev): Bump core-js from 3.15.1 to 3.15.2 (#11164)
  • f3f55a4 Build(deps-dev): Bump webpack from 5.40.0 to 5.42.0 (#11161)
  • 56a108a Build(deps-dev): Bump babel-jest from 27.0.5 to 27.0.6 (#11159)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
馃 View latest project report

馃洜 Adjust project settings

馃摎 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

馃 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants