Next.js-Flat-Prototype-Pollution icon indicating copy to clipboard operation
Next.js-Flat-Prototype-Pollution copied to clipboard

[Snyk] Upgrade flat from 5.0.0 to 5.0.2

Open PwnFunction opened this issue 1 year ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade flat from 5.0.0 to 5.0.2.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.
  • The recommended version was released 3 years ago, on 2020-08-06.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-FLAT-596927
621/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: flat from flat GitHub release notes
Commit messages
Package name: flat
  • e5ffd66 Release 5.0.2
  • fdb79d5 Update dependencies, refresh lockfile, format with standard.
  • e52185d Test against node 14 in CI.
  • 0189cb1 Avoid arrow function syntax.
  • f25d3a1 Release 5.0.1
  • 54cc7ad use standard formatting
  • 779816e drop dependencies
  • 2eea6d3 Bump lodash from 4.17.15 to 4.17.19
  • a61a554 Bump acorn from 7.1.0 to 7.4.0
  • 20ef0ef Fix prototype pollution on unflatten
  • e8fb281 Test prototype pollution on unflatten
  • 6e95c43 Add node 10 & 12 to travis config.

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

PwnFunction avatar Oct 12 '23 14:10 PwnFunction