Skip to content
This repository has been archived by the owner on Jan 7, 2022. It is now read-only.

[Snyk] Security upgrade chokidar from 1.7.0 to 2.0.0 #17

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
low severity Regular Expression Denial of Service (ReDoS)
npm:braces:20180219
Yes Proof of Concept
Commit messages
Package name: chokidar The new version differs by 15 commits.
  • 3409db8 Release 2.0.0
  • d5187a2 Merge pull request #660 from phated/docs
  • 77cf90f Merge pull request #659 from phated/ci-updates
  • 41021e8 Update changelog for 2.0
  • 4ec944e Update AppVeyor badge location
  • d2d8132 Add node 9 to both CI
  • febd028 Avoid flakey coveralls API from failing the tests
  • fe97886 Update Travis & AppVeyor to allow node 0.10 failures
  • 51ca0d5 Merge pull request #658 from phated/replace-syspath
  • 2f3112a Upgrade other deps
  • a92f089 Attempt to fix glob tests
  • cde757a Update globbing deps
  • cbdf255 fix for handling braces in path (#622)
  • 528826f Add node v8 to CI configs
  • 3d91781 print fsevents require error when env var set (#605)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/npm:braces:20180219
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant