-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Fix for 36 vulnerabilities #175
base: master
Are you sure you want to change the base?
Conversation
…duce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230 - https://snyk.io/vuln/SNYK-JS-LODASH-567746 - https://snyk.io/vuln/SNYK-JS-BL-608877 - https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908 - https://snyk.io/vuln/SNYK-JS-BRACES-6838727 - https://snyk.io/vuln/SNYK-JS-DECODEURICOMPONENT-3149970 - https://snyk.io/vuln/SNYK-JS-LODASH-6139239 - https://snyk.io/vuln/SNYK-JS-SEMVER-3247795 - https://snyk.io/vuln/SNYK-JS-INI-1048974 - https://snyk.io/vuln/SNYK-JS-LODASH-450202 - https://snyk.io/vuln/SNYK-JS-LODASH-608086 - https://snyk.io/vuln/SNYK-JS-LODASHSET-1320032 - https://snyk.io/vuln/npm:deep-extend:20180409 - https://snyk.io/vuln/SNYK-JS-LODASH-1040724 - https://snyk.io/vuln/SNYK-JS-TAR-6476909 - https://snyk.io/vuln/SNYK-JS-TAR-1579147 - https://snyk.io/vuln/SNYK-JS-TAR-1579152 - https://snyk.io/vuln/SNYK-JS-TAR-1579155 - https://snyk.io/vuln/SNYK-JS-DOTPROP-543489 - https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116 - https://snyk.io/vuln/SNYK-JS-TAR-1536528 - https://snyk.io/vuln/SNYK-JS-TAR-1536531 - https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 - https://snyk.io/vuln/SNYK-JS-MICROMATCH-6838728 - https://snyk.io/vuln/SNYK-JS-TRIMNEWLINES-1298042 - https://snyk.io/vuln/SNYK-JS-UNSETVALUE-2400660 - https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905 - https://snyk.io/vuln/SNYK-JS-LODASH-1018905 - https://snyk.io/vuln/SNYK-JS-NODEFETCH-2342118 - https://snyk.io/vuln/SNYK-JS-KINDOF-537849 - https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795 - https://snyk.io/vuln/npm:braces:20180219 - https://snyk.io/vuln/npm:debug:20170905 - https://snyk.io/vuln/SNYK-JS-GOT-2932019 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818 - https://snyk.io/vuln/SNYK-JS-TAR-1536758
PR Reviewer Guide 🔍Here are some key observations to aid the review process:
|
PR Code Suggestions ✨Explore these optional code suggestions:
|
User description
Snyk has created this PR to fix 36 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
packages/cli/package.json
packages/cli/package-lock.json
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-CROSSSPAWN-8303230
SNYK-JS-LODASH-567746
SNYK-JS-BL-608877
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-BRACES-6838727
SNYK-JS-DECODEURICOMPONENT-3149970
SNYK-JS-LODASH-6139239
SNYK-JS-SEMVER-3247795
SNYK-JS-INI-1048974
SNYK-JS-LODASH-450202
SNYK-JS-LODASH-608086
SNYK-JS-LODASHSET-1320032
npm:deep-extend:20180409
SNYK-JS-LODASH-1040724
SNYK-JS-TAR-6476909
SNYK-JS-TAR-1579147
SNYK-JS-TAR-1579152
SNYK-JS-TAR-1579155
SNYK-JS-DOTPROP-543489
SNYK-JS-INFLIGHT-6095116
SNYK-JS-TAR-1536528
SNYK-JS-TAR-1536531
SNYK-JS-MINIMIST-559764
SNYK-JS-MICROMATCH-6838728
SNYK-JS-TRIMNEWLINES-1298042
SNYK-JS-UNSETVALUE-2400660
SNYK-JS-GLOBPARENT-1016905
SNYK-JS-LODASH-1018905
SNYK-JS-NODEFETCH-2342118
SNYK-JS-KINDOF-537849
SNYK-JS-MINIMIST-2429795
npm:braces:20180219
npm:debug:20170905
SNYK-JS-GOT-2932019
SNYK-JS-MINIMATCH-3050818
SNYK-JS-TAR-1536758
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Prototype Pollution
🦉 Open Redirect
🦉 More lessons are available in Snyk Learn
PR Type
Enhancement
Description
yeoman-generator
: 3.1.1 → 6.0.0update-notifier
: 1.0.0 → 7.3.0yeoman-environment
: 1.5.2 → 3.0.0semver
: 5.3.0 → 5.7.2tar-fs
: 1.12.0 → 2.1.1rimraf
: 2.6.1 → 4.3.1@octokit/rest
,chokidar
,del
, andglobby
Changes walkthrough 📝
package.json
Dependency Updates for Security Vulnerability Fixes
packages/cli/package.json
vulnerabilities
yeoman-generator
(3.x to6.x),
update-notifier
(1.x to 7.x), andyeoman-environment
(1.x to3.x)
@octokit/rest
,chokidar
,del
,globby
, and otherssemver
,tar-fs
, andrimraf
package-lock.json
Package Lock File Updates for New Dependencies
packages/cli/package-lock.json
package-lock.json
...
packages/cli/package-lock.json
...