libreact
libreact copied to clipboard
[Snyk] Fix for 2 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 551/1000 Why? Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MINIMATCH-3050818 |
Yes | No Known Exploit | |
| 589/1000 Why? Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MOCHA-2863123 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: gulp
The new version differs by 134 commits.- 55eb23a Release: 4.0.0
- 173a532 Docs: Fix the installation instructions
- ec54d09 Docs: Improve note about out-of-date docs
- 03b7c98 Docs: Update recipes to install gulp@next
- 2eba29e Docs: Remove run-sequence from recipes
- 76eb4d6 Docs: Add installation instructions & update badges
- fbc162f Docs: Remove references to gulp-util
- 3011cf9 Scaffold: Normalize repository
- f27be05 Update: Remove graceful-fs from test suite
- 361ab63 Upgrade: Update glob-watcher
- 064d100 Build: Avoid broken node 9
- 057df59 Release: 4.0.0-alpha.3
- c1ba80c Breaking: Upgrade major versions of glob-watcher, gulp-cli & vinyl-fs
- 89acc5c Docs: Improve ES2015 task exporting examples (#1999)
- 0ac9e04 Docs: Add "Project structure" section to CONTRIBUTING.md (#1859)
- 723cbc4 Docs: Fix syntax in recipe example (#1715)
- d420a6a Docs: Have gulp.lastRun take a function to avoid task registration (#1828)
- 29ece6f Upgrade: Update undertaker
- e931cb0 Docs: Fix changelog typos (#1696)
- 477db84 Docs: Add a "BrowserSync with Gulp 4" recipe (#1659)
- d4ed3c7 Docs: Add options.cwd for gulp.src API (#1645)
- 5dc3b07 Docs: Update gulp.watch API to align with glob-watcher
- 0c66069 Breaking: Replace chokidar as gulp.watch with glob-watcher wrapper
- c3dbc10 Docs: Clarify incremental builds example (#1609)
Package name: mocha
The new version differs by 250 commits.- 5f96d51 build(v10.1.0): release
- ed74f16 build(v10.1.0): update CHANGELOG
- 51d4746 chore(devDeps): update 'ESLint' to v8 (#4926)
- 4e06a6f fix(browser): increase contrast for replay buttons (#4912)
- 41567df Support prefers-color-scheme: dark (#4896)
- 61b4b92 fix the regular expression for function `clean` in `utils.js` (#4770)
- 77c18d2 chore: use standard 'Promise.allSettled' instead of polyfill (#4905)
- 84b2f84 chore(ci): upgrade GH actions to latest versions (#4899)
- 023f548 build(v10.0.0): release
- 62b1566 build(v10.0.0): update CHANGELOG
- fbe7a24 chore: update dependencies (#4878)
- 2b98521 docs: replace 'git.io' short links (#4877) [ci skip]
- 007fa65 chore(ci): add Node v18 to test matrix (#4876)
- f6695f0 chore(esm): remove code for Node v12 (#4874)
- 59f6192 chore(ci): conditionally skip 'push' event (#4872)
- b863359 docs: fix 'fgrep' url (#4873)
- baaa41a chore(ci): ignore changes to docs files (#4871)
- ac81cc5 refactor!: drop support of 'growl' notification (#4866)
- 3946453 chore(deps)!: upgrade 'minimatch' (#4865)
- 592905b refactor!: rename 'bin/mocha' to 'bin/mocha.js' (#4863)
- b7b849b refactor!: remove deprecated Runner signature (#4861)
- 0608fa3 chore(site): fix supporters' download (#4859)
- 785aeb1 chore(test): drop AMD/'requirejs' (#4857)
- ed640c4 chore(devDeps): upgrade 'coffee-script' (#4856)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS) 🦉 Regular Expression Denial of Service (ReDoS)