audius-client icon indicating copy to clipboard operation
audius-client copied to clipboard

[Snyk] Security upgrade glslify from 1.6.1 to 2.0.0

Open snyk-bot opened this issue 2 years ago • 1 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/web/src/utils/visualizer/gl-vignette-background/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 794/1000
Why? Mature exploit, Has a fix available, CVSS 7.3
Arbitrary Code Execution
npm:static-eval:20171016
Yes Mature

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: glslify The new version differs by 17 commits.
  • 558205e Merge pull request #37 from stackgl/2.0.0
  • ba86634 expose node-friendly API
  • 9b043f7 browserify transform: use .inline API
  • db2426c error variable fix
  • 476852b bin.js: use depper.inline() instead of current hack
  • 2606dbe accurate expanded example
  • f602803 migration docs
  • e5dab89 syntax highlighting fix
  • de48733 update glslify-bundle
  • 79355cc Handle cwd for shaders properly in browserify transform
  • 7994da7 ignore .json files
  • 59139fe add CLI tests
  • 5111f9d tests for browserify transform
  • 68859b1 support for global/post transforms
  • f45a04f docs additions
  • a2a727c Feedback fixes
  • 6ed21e4 2.0.0 pre-releaseish

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Arbitrary Code Execution

snyk-bot avatar Aug 21 '22 05:08 snyk-bot

Preview this change https://demo.audius.co/snyk-fix-bc4f279abb336e0b8f506adb2365e792

audius-infra avatar Aug 21 '22 05:08 audius-infra