grunt-tight-sprite
                                
                                
                                
                                    grunt-tight-sprite copied to clipboard
                            
                            
                            
                        [Snyk] Security upgrade canvas from 2.6.1 to 2.8.0
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
 - package-lock.json
 
 
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity | 
|---|---|---|---|---|
| 718/1000   Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.5  | 
Uncontrolled Resource Consumption ('Resource Exhaustion')  SNYK-JS-TAR-6476909  | 
No | Proof of Concept | 
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: canvas
The new version differs by 48 commits.- 8707f3d v2.8.0
 - 5b5140e Add Node.js 16 to CI, remove 15
 - 2bf76b5 export type NodeCanvasRenderingContext2D
 - 0b49442 Update changelog to reflect previous commit
 - c166443 Add ctx2d.setTransform(mat) overload
 - 2f84eee Add ctx2d.getTransform() function
 - d107c04 Update changelog to reflect previous commit
 - 234e659 Fix text actualBoundingBoxLeft and actualBoundingBoxRight measures by using ink_rect instead of logical_rect
 - e4f901c Loosen text measurement expectation.
 - 12e671d Fix crash if exception thrown from onload/onerror
 - 8cd191c Update changelog
 - 6fae569 Use node pre gyp v1
 - 7a84fc5 Fix always-false comparison warning in Canvas.cc in Node 15+
 - 646b605 Update changelog
 - b549ab6 Fix Windows CI build, add Node.js v15
 - f8305fb Fix dtslint failing in CI
 - 547b050 Fix dangling reference in BackendOperationNotAvailable exception.
 - beaee39 add Dockerfile for linux prebuild image
 - e476656 Added stride to the Typescript typings
 - 41d1c99 Fix PNG stream method name in benchmark (fixes #1672)
 - 595d559 Add invertSelf to the DOMMatrix object (#1649)
 - 5054b7b translate "sans-serif" to "sans" for Pango
 - 58bc728 v2.7.0
 - e8ad788 Switch prebuild trigger to manual
 
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:  
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: