rtc-diagnostics-react-app icon indicating copy to clipboard operation
rtc-diagnostics-react-app copied to clipboard

[Snyk] Security upgrade cli-ux from 5.5.1 to 6.0.9

Open twilio-product-security opened this issue 1 year ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 125/1000
Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5
Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
Yes No Known Exploit
high severity 125/1000
Why? Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5
Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: cli-ux The new version differs by 92 commits.
  • 94a2dbf chore(release): 6.0.9 [ci skip]
  • 270efe3 fix: deprecate cli ux (#477)
  • 82449f0 chore(release): 6.0.8 [ci skip]
  • 0511944 fix(security): bump cli-progress
  • bab8a2b chore(release): 6.0.7 [ci skip]
  • ce8cec5 fix: bump @ oclif/core (#475)
  • 8c2ee67 Merge pull request #474 from oclif/dependabot-npm_and_yarn-typescript-4.5.4
  • 4358d81 chore(deps-dev): bump typescript from 4.5.2 to 4.5.4
  • e76b18c chore: sync dependabot.yml (#419)
  • 3889c2e ci: sync .circleci/config.yml (#470) [skip ci]
  • ed5d19f chore: fix url hyperlink test (#469)
  • cd4e665 Merge pull request #466 from oclif/dependabot-npm_and_yarn-axios-0.24.0
  • 7be5090 Merge pull request #467 from oclif/dependabot-npm_and_yarn-typescript-4.5.2
  • a2ae094 chore: replace instances of master with main [skip ci]
  • 474e88e chore: update author [skip ci]
  • 5ce5f19 chore: release as latest [skip ci]
  • 0b2017f chore(deps-dev): bump typescript from 4.4.3 to 4.5.2
  • ac0d7f6 chore(deps-dev): bump axios from 0.21.4 to 0.24.0
  • 21e8525 chore(release): 6.0.6 [ci skip]
  • 44eecd0 fix: bump deps and fix tests (#465)
  • 9da5c51 chore: add windows tests [skip ci]
  • 256325e chore(release): 6.0.5 [ci skip]
  • 2b8699d fix: bump deps (#462)
  • 641a2fb chore(dependabot): add versioning-strategy [skip ci]

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncontrolled resource consumption

twilio-product-security avatar May 14 '24 06:05 twilio-product-security