vuejs-datatable
vuejs-datatable copied to clipboard
[Snyk] Security upgrade object-path from 0.11.4 to 0.11.8
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
661/1000 Why? Recently disclosed, Has a fix available, CVSS 7.3 |
Prototype Pollution SNYK-JS-OBJECTPATH-1585658 |
No | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: object-path
The new version differs by 18 commits.- e6bb638 0.11.8
- 4f0903f Fix prototype pollution vulnerability
- 43a926f 0.11.7
- 3864273 Update readme with info about the security fix
- 94f92d8 0.11.6
- 7bdf4ab Fix prototype pollution when path components are not strings
- ebc5e2c Upgrade dependencies
- 86a3562 Update README.md
- d27e97c Make security fix message more prominent
- 489b954 Remove sponsor
- 8e32400 Add vulnerability fix in changelog. Drop support to node < 10, at least officially (latest version of mocha does not work in node < 10). Remove sponsor.
- 2be3354 Fix prototype pollution in set()
- 404223b Add modern Node.js to travis tests
- b43cc8c Slightly improve performances for set() and update dev dependencies
- b45fb77 Update README.md
- d680fe7 Merge pull request #92 from arunasank/hot-chai
- ee0c79f update tests after updating chai
- 354ba96 chai 4.1.2
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report