auth0-authorization-extension
auth0-authorization-extension copied to clipboard
[Snyk] Fix for 1 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-ANSIREGEX-1583908 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: nconf
The new version differs by 26 commits.- 85229df chore: enable circleci
- 91e9106 chore: update changelog
- 4122731 0.11.0
- 56794d1 chore: upgrade deps to fix security vulns
- 1392ac4 0.10.0
- 01f25fa Regex as env separator (#288)
- 16667be Argv store separator (#291)
- bac910a 0.9.1
- 2bdf7e1 Clean Argv Store options (#290)
- b9321b2 transformer can now return an undefined key (#289)
- 81ce0be Update changelog
- b1ee63c fix error in transform function when dealing with dropped entries (#287)
- 9f70ba1 [doc] Update changelog
- 8afcf99 [dist] Version bump. 0.9.0
- b41c505 Save conf to dedicated file (#283)
- 52e0a35 Update changelog
- fa215a4 add tests for the normal configuration of yargs via argv
- 802a8d6 test for yargs custom instance (more flexible check isYargs)
- 3e26bb2 Add posibility to pass a yargs instance to argv() method
- 856fdf8 First pass at transform functions (#279)
- b9c345b Fix `parseValues` option name
- 35088a3 Added nconf.any method (#278)
- ca10d0e Add basic linting rules
- bfb0220 Remove unused module (#277)
Package name: npm
The new version differs by 250 commits.- 30a9844 7.21.0
- 0b2cd9d update AUTHORS
- 06461ec docs: changelog for v7.21.0
- 771a1cb chore(tests): fix snapshots
- 71cdfd8 [email protected]
- 94f92de [email protected]
- 7ac621c [email protected]
- 218caca [email protected]
- ff6626a fix(docs): update npm-publish access flag info
- b6f40b5 [email protected]
- e9e5ee5 @ npmcli/[email protected]
- 991a3bd [email protected]
- f077724 [email protected]
- 68a19bb fix(error-message): look for er.path not er.file
- ff34d6c feat(cache): initial implementation of ls and rm
- 8183976 [email protected]
- df57f0d @ npmcli/[email protected]
- 487731c fix(logging): sanitize logged argv
- 7a58264 chore(ci): check that docs are up to date in ci
- 22f3bbb chore(docs): add more 'autogenerated' comments
- 4314490 fix(docs): revert auto-generated portion of docs
- 32e88c9 fix(did-you-mean): switch levenshtein libraries
- 59b9851 7.20.6
- 2591e67 update AUTHORS
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.