rtc-diagnostics-react-app
rtc-diagnostics-react-app copied to clipboard
[Snyk] Security upgrade cli-ux from 5.5.1 to 6.0.9
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 125/1000 Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5 |
Uncontrolled resource consumption SNYK-JS-BRACES-6838727 |
Yes | No Known Exploit | |
| 125/1000 Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5 |
Inefficient Regular Expression Complexity SNYK-JS-MICROMATCH-6838728 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: cli-ux
The new version differs by 92 commits.- 94a2dbf chore(release): 6.0.9 [ci skip]
- 270efe3 fix: deprecate cli ux (#477)
- 82449f0 chore(release): 6.0.8 [ci skip]
- 0511944 fix(security): bump cli-progress
- bab8a2b chore(release): 6.0.7 [ci skip]
- ce8cec5 fix: bump @ oclif/core (#475)
- 8c2ee67 Merge pull request #474 from oclif/dependabot-npm_and_yarn-typescript-4.5.4
- 4358d81 chore(deps-dev): bump typescript from 4.5.2 to 4.5.4
- e76b18c chore: sync dependabot.yml (#419)
- 3889c2e ci: sync .circleci/config.yml (#470) [skip ci]
- ed5d19f chore: fix url hyperlink test (#469)
- cd4e665 Merge pull request #466 from oclif/dependabot-npm_and_yarn-axios-0.24.0
- 7be5090 Merge pull request #467 from oclif/dependabot-npm_and_yarn-typescript-4.5.2
- a2ae094 chore: replace instances of master with main [skip ci]
- 474e88e chore: update author [skip ci]
- 5ce5f19 chore: release as latest [skip ci]
- 0b2017f chore(deps-dev): bump typescript from 4.4.3 to 4.5.2
- ac0d7f6 chore(deps-dev): bump axios from 0.21.4 to 0.24.0
- 21e8525 chore(release): 6.0.6 [ci skip]
- 44eecd0 fix: bump deps and fix tests (#465)
- 9da5c51 chore: add windows tests [skip ci]
- 256325e chore(release): 6.0.5 [ci skip]
- 2b8699d fix: bump deps (#462)
- 641a2fb chore(dependabot): add versioning-strategy [skip ci]
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: