next-reason-boilerplate
next-reason-boilerplate copied to clipboard
[Snyk] Fix for 2 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-ANSIHTML-1296849 |
Yes | Proof of Concept |
![]() |
586/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-WS-1296835 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: next
The new version differs by 250 commits.- 8c899ee v9.3.4
- e000d84 v9.3.4-canary.4
- 7b546a9 Update hello-world example React version & name for CodeSandbox (#11550)
- a37ad0a Add notes to styled-components example README (#11540)
- a992444 v9.3.4-canary.3
- 3f6bd47 Update build output with renamed column (#11401)
- 1992e2a Example/update unstated (#11534)
- d61eced Update to make sure AMP only bundles are always removed in pro⦠(#11527)
- fa5da6d Remove passing of NODE_OPTIONS='--inspect' to subprocesses (#11041)
- f9cd7c5 v9.3.4-canary.2
- c17ee73 Generic Type for GetStaticPaths (#11430)
- 2263876 added "with-route-as-modal" example (#11473)
- f2315ff update auth0 example with getServerSideProps (#11051)
- b307ed9 Update checking for existing dotenv usage (#11496)
- b8d075e Update environment support (#11524)
- ce3f7d0 Drop url dependency (#11503)
- 0bfc0b3 v9.3.4-canary.1
- b88f20c Fix lockfile
- d7f9a52 correct babel dev dependency
- 755dc40 postcss loaders
- a3ec26d ignore-loader
- 8dad5ab file-loader
- c855a38 babel-loader, cache-loader
- 84a46df thread-loader
Package name: pm2
The new version differs by 250 commits.- 56ee2cd [email protected]
- b73c61a bump CHANGELOG.md
- caca206 psh
- 593b43c various fixes for N14
- 42a10f4 bump @ pm2/js-api + mocharc.yml -> mocharc.js
- e41282d fixes for node 14 + shelljs
- a38b6ed bump pkg
- c667244 add node 14 to travis
- 6f704e6 Merge branch 'master' into development
- 5dfb667 [email protected]
- 9d763ed cli-table-redemption -> cli-tableau
- 3980bff bump cli-table-redemption
- 9ee8a0f [email protected]
- 956afe7 [email protected]
- 851c44c update changelog
- 03d0b28 Merge pull request #4662 from Timic3/fix/common-module-import
- d8a6d38 bump pm2-deploy
- 4d1aedf throttle cron test
- 8fae340 bump vizion
- b097dc2 pkg.json version bump
- 7a5da59 drop date-fns
- 195eb6e drop lodash lib
- 526756d 4.3.0
- 7323438 Add .cjs (common JS) as a viable extension
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
π§ View latest project report
π Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
π¦ Learn about vulnerability in an interactive lesson of Snyk Learn.