gulp-armadillo
gulp-armadillo copied to clipboard
[Snyk] Fix for 1 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 718/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.5 |
Uncontrolled Resource Consumption ('Resource Exhaustion') SNYK-JS-TAR-6476909 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: eyeglass
The new version differs by 250 commits.- 6b06179 Publish
- 77b3f43 Add yarn back to the package dev dependencies.
- 9ee991e Updates to broccoli-eyeglass to support dart-sass.
- c07029d Update CHANGELOG files for broccoli and ember-cli.
- 9617614 README updates for 2.5 and 3.0.
- 6e1d933 dart-sass support (#247)
- d9b1844 Don't test against node 8 anymore.
- 228b167 chore: Refactor eyeglass version lookup to a utility.
- 7b7fd25 chore: Remove deprecated assets APIs.
- c63656c chore: Remove obsolete test case.
- e1741d2 chore: Remove deprecated API Eyeglass#enableImportOnce.
- 6ab4f9b chore: Remove deprecated sass engine argument from Eyeglass constructor.
- 1ecd85f Deprecated options will now cause an error.
- 57d33b0 chore: Remove deprecated sassOptions() method.
- 5b89784 Enable esModuleInterop for all packages.
- 0935d09 chore: Pin node and yarn versions in remaining packages.
- f9e5e57 chore: Emit typescript output for node 10+.
- b784582 feat: Officially drop support for node 6, 8, and 11.
- 8334e0e fix: Remove deprecation warning and emit errors instead for version conflicts when strictModuleVersions is set.
- cc00552 docs: Note duplicate modules change in the CHANGELOG.
- 521f485 Merge branch 'ignore-duplicate-modules' into release-3.0
- 9d9500a fix: Don't add manual modules if they already exist.
- 1a537a1 Don't even try to install deasync.
- 7664351 docs: CHANGELOG entry for deasync removal.
Package name: gulp-sass
The new version differs by 28 commits.- 5775044 Update CHANGELOG.md
- 978b8f6 Update to major version 5 (#802)
- 10eae93 Update changelog for 4.1.1
- 947b26c Upgrade lodash to fix a security issue (#776)
- 8d6ac29 Update changelog
- 43c0547 4.1.0
- ebe3ec6 Set appropriate file stat times (#763)
- 7ab018e Migrate to the lodash package
- fa670c6 4.0.2
- fefa00e Revert package.json version bump
- 98254d2 Fix README typos
- 8a14419 Continue loading Node Sass by default
- 938afbe Add a note about synchronous versus asynchronous speed
- 7cc2db1 Make this package implementation-agnostic
- 643f73b Add documentation for synchronous code options
- 0b3c7e7 4.0.1
- daca90d Merge pull request #681 from DKvistgaard/master
- 71471c2 Declaring logError as function instead of arrow function.
- 450a7b8 4.0.0
- e9b1fe8 Fix node versions in appveyor.yml
- 44be409 Merge pull request #667 from dlmanning/next
- 7656eff Adopt airbnb eslint preset
- 1293169 Bump autoprefixer@^8.1.0, gulp-postcss@^7.0.1
- 9fa817b Bump gulp-sourcemaps@^2.6.4
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: