rtc-diagnostics-react-app
rtc-diagnostics-react-app copied to clipboard
[Snyk] Security upgrade cli-ux from 5.5.1 to 6.0.9
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-ANSIREGEX-1583908 |
Yes | Proof of Concept | |
| 681/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.2 |
Command Injection SNYK-JS-LODASHTEMPLATE-1088054 |
Yes | Proof of Concept | |
| 696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-SEMVER-3247795 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: cli-ux
The new version differs by 92 commits.- 94a2dbf chore(release): 6.0.9 [ci skip]
- 270efe3 fix: deprecate cli ux (#477)
- 82449f0 chore(release): 6.0.8 [ci skip]
- 0511944 fix(security): bump cli-progress
- bab8a2b chore(release): 6.0.7 [ci skip]
- ce8cec5 fix: bump @ oclif/core (#475)
- 8c2ee67 Merge pull request #474 from oclif/dependabot-npm_and_yarn-typescript-4.5.4
- 4358d81 chore(deps-dev): bump typescript from 4.5.2 to 4.5.4
- e76b18c chore: sync dependabot.yml (#419)
- 3889c2e ci: sync .circleci/config.yml (#470) [skip ci]
- ed5d19f chore: fix url hyperlink test (#469)
- cd4e665 Merge pull request #466 from oclif/dependabot-npm_and_yarn-axios-0.24.0
- 7be5090 Merge pull request #467 from oclif/dependabot-npm_and_yarn-typescript-4.5.2
- a2ae094 chore: replace instances of master with main [skip ci]
- 474e88e chore: update author [skip ci]
- 5ce5f19 chore: release as latest [skip ci]
- 0b2017f chore(deps-dev): bump typescript from 4.4.3 to 4.5.2
- ac0d7f6 chore(deps-dev): bump axios from 0.21.4 to 0.24.0
- 21e8525 chore(release): 6.0.6 [ci skip]
- 44eecd0 fix: bump deps and fix tests (#465)
- 9da5c51 chore: add windows tests [skip ci]
- 256325e chore(release): 6.0.5 [ci skip]
- 2b8699d fix: bump deps (#462)
- 641a2fb chore(dependabot): add versioning-strategy [skip ci]
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS) 🦉 Command Injection