magento2-gulpfile icon indicating copy to clipboard operation
magento2-gulpfile copied to clipboard

[Snyk] Fix for 2 vulnerable dependencies

Open kesonno opened this issue 7 years ago • 0 comments
trafficstars

This PR fixes one or more vulnerable packages in the npm dependencies of this project. See the Snyk test report for this project for details.

This PR includes:

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:

    • package.json
  • A Snyk policy (.snyk) file, with updated settings.

Vulnerabilities that will be fixed

With an upgrade:
With a Snyk patch:

You can read more about Snyk's upgrade and patch logic in Snyk's documentation.

Check the changes in this PR to ensure they won't cause issues with your project.

Stay secure, The Snyk team

kesonno avatar May 10 '18 22:05 kesonno