Calidad-del-Aire icon indicating copy to clipboard operation
Calidad-del-Aire copied to clipboard

[Snyk] Security upgrade serialport from 2.1.2 to 6.0.0

Open UlisesGascon opened this issue 1 year ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • snippets/temperatura y humedad/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Prototype Pollution
SNYK-JS-AJV-584908
Yes No Known Exploit
high severity 624/1000
Why? Has a fix available, CVSS 8.2
Arbitrary File Overwrite
SNYK-JS-TAR-1536528
Yes No Known Exploit
high severity 624/1000
Why? Has a fix available, CVSS 8.2
Arbitrary File Overwrite
SNYK-JS-TAR-1536531
Yes No Known Exploit
low severity 410/1000
Why? Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
Yes No Known Exploit
high severity 639/1000
Why? Has a fix available, CVSS 8.5
Arbitrary File Write
SNYK-JS-TAR-1579147
Yes No Known Exploit
high severity 639/1000
Why? Has a fix available, CVSS 8.5
Arbitrary File Write
SNYK-JS-TAR-1579152
Yes No Known Exploit
high severity 639/1000
Why? Has a fix available, CVSS 8.5
Arbitrary File Write
SNYK-JS-TAR-1579155
Yes No Known Exploit
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Prototype Pollution
npm:hoek:20180212
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: serialport The new version differs by 250 commits.
  • 6ed7b3b docs(README): fix api links
  • a972686 docs: Collapse the beta changes in changelog and upgrade guide
  • af97b09 Bump to v6.0.0
  • 4ff9c67 feat(windows): Add ERROR_INVALID_PARAMETER to supported bindings errors (#1354)
  • dffa9d5 Bump to 6.0.0-beta3
  • 530247a chore(package): update sinon to version 4.0.0 (#1348)
  • a5c01ff chore(package): update mocha to version 4.0.0 (#1352)
  • bcb492f feat(parsers): Add cctalk parsers (#1342)
  • a3b8d35 feat(open): Throw on incorrect baudrate option (#1347)
  • c590021 chore(packages): upgrade eslint and sinon (#1343)
  • 4850901 Update publishing instructions
  • 3faadac fix(docs): add missing parsers to properties list
  • ad8abf6 6.0.0-beta2
  • 69de595 fix(windows): Asynchronous callbacks for reading and writing (#1328)
  • c7a3be4 Revert "fix(windows): Asynchronous callbacks for reading and writing on Windows" (#1323)
  • 2c2a8b6 fix(windows): Asynchronous callbacks for reading and writing on Windows (#1313)
  • bf251a9 fix: Fixed typo in upgrade guide (#1321)
  • 722d589 chore(package): update eslint to version 4.5.0 (#1315)
  • 1ee4e5a chore(package): update debug to version 3.0.1 (#1314)
  • 4e266e5 chore(package): update sinon to version 3.2.1 (#1316)
  • 4987750 fix(package): update debug to version 3.0.0 (#1292)
  • 76b7191 fix(docs): Add a note about windows support
  • e83ec4e fix(docs): correct default highWaterMark to 65536 bytes
  • 335ede9 6.0.0-beta1

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Arbitrary File Overwrite 🦉 Arbitrary File Overwrite 🦉 Arbitrary File Write 🦉 More lessons are available in Snyk Learn

UlisesGascon avatar Jun 22 '22 07:06 UlisesGascon