explain-analyzer
explain-analyzer copied to clipboard
[Snyk] Security upgrade mithril from 1.1.7 to 2.0.3
trafficstars
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 696/1000 Why? Recently disclosed, Has a fix available, CVSS 8.2 |
Prototype Pollution SNYK-JS-MITHRIL-2413672 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: mithril
The new version differs by 250 commits.- 0d10dc2 v2.0.3
- e58e918 Take 2
- 9d3ce5f v2.0.2
- ad680c6 Preparing for release
- 8d506ad Fix release script
- 97fa178 Prevent prototype pollution while parsing query strings (#2494)
- 48e7fd1 Refactor scripts (#2465)
- 62172cb Fix pen [skip ci]
- 39fa2b3 Fix #1881 + related ospec bug (#2492)
- 90f96eb Update issue templates (#2485)
- 123c0db Missed a link
- ba1498b ospec 4.0.0
- be0213a Hide the "Upcoming" section from the live site [skip ci]
- 516a3a6 v2.0.1
- 1776366 v2.0.0
- 234b1c9 Update migration, fix various minor issues
- 8186818 Add TS installation notes
- b580e24 Prepare for v2, s/markup/html/g in code blocks
- 20f0759 Fix docs (#2482)
- 61b087e Conform stream.map to FL spec and clarify stream internal properties (#2481)
- 84baff8 Fix part 1 of #2477
- ae6b547 v2.0.0-rc.9
- c30a716 Update readme when releasing, too
- 17f2ab2 Merge branch 'next'
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report