[Snyk] Fix for 1 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
:sparkles: Snyk has automatically assigned this pull request, set who gets assigned.
As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 658/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-AXIOS-6124857 |
No | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @googlemaps/google-maps-services-js
The new version differs by 34 commits.- 92a5b5a chore(release): 3.3.40 [skip ci]
- a0d416b fix: only use pre-ESM dependencies (#1047)
- dacfff6 build(deps): bump retry-axios from 2.6.0 to 3.1.0 (#1027)
- c5c0990 chore: update all dependencies (#1044)
- 9a5405f chore(release): 3.3.39 [skip ci]
- fe1b7b8 build(deps-dev): bump @ types/node from 20.7.0 to 20.8.2 (#1043)
- 218c66c build(deps-dev): bump @ types/node from 20.6.2 to 20.7.0 (#1041)
- a2d68dd build(deps-dev): bump @ types/node from 20.6.0 to 20.6.2 (#1036)
- 0b8bb3f chore(release): 3.3.38 [skip ci]
- 22e6139 docs: highlight API key in Quick Start example (#1014)
- dfca658 build(deps-dev): bump @ types/node from 20.5.9 to 20.6.0 (#1033)
- b1a7ef1 build(deps-dev): bump typedoc from 0.25.0 to 0.25.1 (#1031)
- 798938f build(deps-dev): bump prettier from 3.0.2 to 3.0.3 (#1032)
- 59b3517 chore(release): 3.3.37 [skip ci]
- a4a6f59 build(deps-dev): bump @ types/node from 20.5.1 to 20.5.9 (#1030)
- d2fa136 build(deps-dev): bump typedoc from 0.24.8 to 0.25.0 (#1026)
- 4216b1e build(deps-dev): bump prettier from 3.0.1 to 3.0.2 (#1024)
- 476aa7d build(deps-dev): bump @ types/node from 20.5.0 to 20.5.1 (#1023)
- dc3c68e chore(release): 3.3.36 [skip ci]
- fdba501 build(deps-dev): bump nock from 13.3.2 to 13.3.3 (#1022)
- 1a5f4da build(deps-dev): bump prettier from 3.0.0 to 3.0.1 (#1019)
- 4dcd924 build(deps-dev): bump @ types/node from 20.4.8 to 20.5.0 (#1020)
- e4be842 build(deps): bump agentkeepalive from 4.3.0 to 4.5.0 (#1018)
- 77e49b4 build(deps-dev): bump @ types/node from 20.4.5 to 20.4.8 (#1017)
Package name: axios
The new version differs by 46 commits.- b15b918 chore(release): v1.6.3 (#6151)
- b76cce0 chore(ci): added branches filter for notify action; (#6084)
- 5e7ad38 fix: Regular Expression Denial of Service (ReDoS) (#6132)
- 8befb86 docs: update alloy link (#6145)
- d18f40d docs: add headline sponsors
- b3be365 chore(release): v1.6.2 (#6082)
- 8739acb chore(ci): removed redundant release action; (#6081)
- bfa9c30 chore(docs): fix outdated grunt to npm scripts (#6073)
- a2b0fb3 chore(docs): update README.md (#6048)
- b12a608 chore(ci): removed paths-ignore filter; (#6080)
- 0c9d886 chore(ci): reworked ignoring files logic; (#6079)
- 30873ee chore(ci): add paths-ignore config to testing action; (#6078)
- cff9967 feat(withXSRFToken): added withXSRFToken option as a workaround to achieve the old `withCredentials` behavior; (#6046)
- 7009715 chore(ci): fixed release notification action; (#6064)
- 7144f10 chore(ci): fixed release notification action; (#6063)
- f6d2cf9 chore(ci): fix publish action content permission; (#6061)
- a22f4b9 chore(release): v1.6.1 (#6060)
- cb8bb2b chore(ci): Publish to NPM with provenance (#5835)
- 37cbf92 chore(ci): added labeling and notification for published PRs; (#6059)
- dd465ab fix(formdata): fixed content-type header normalization for non-standard browser environments; (#6056)
- 3dc8369 fix(platform): fixed emulated browser detection in node.js environment; (#6055)
- f7adacd chore(release): v1.6.0 (#6031)
- 9917e67 chore(ci): fix release-it arg; (#6032)
- 96ee232 fix(CSRF): fixed CSRF vulnerability CVE-2023-45857 (#6028)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
👩💻 Set who automatically gets assigned
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: