audius-client icon indicating copy to clipboard operation
audius-client copied to clipboard

[Snyk] Security upgrade glslify-loader from 1.0.2 to 2.0.0

Open snyk-bot opened this issue 2 years ago • 1 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/web/package.json
    • packages/web/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 706/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.7
Remote Memory Exposure
SNYK-JS-BL-608877
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: glslify-loader The new version differs by 9 commits.
  • 3419e9d v2.0.0
  • 4ca84bc Merge pull request #15 from pqml/master
  • 75bff2a Add an example with hot reloading and regl
  • 7ca310d Leave version number as the current one
  • c75fb47 Rewrite Readme, add tests, add webpack 4 support
  • 5dc4eea 1.0.4
  • 6a450f3 Add post-transforms ability
  • 75f9345 1.0.3
  • b7db26d Update code to work with glslify-deps and glslify-bundle

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

snyk-bot avatar Aug 21 '22 19:08 snyk-bot

Preview this change https://demo.audius.co/snyk-fix-a84a9efd64d40a6cedc2d7e55464551f

audius-infra avatar Aug 21 '22 20:08 audius-infra