wip
wip copied to clipboard
[Snyk] Fix for 1 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
768/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-ANSIREGEX-1583908 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: boxen
The new version differs by 46 commits.- d839e71 4.1.0
- 53ebdc1 Update dependencies
- 5fc95ec Tidelift tasks
- 4c4d452 4.0.0
- 2e99867 Require Node.js 8 and upgrade dependencies
- 3dc6e48 Enable the repo Sponsor button
- d58a3f0 3.2.0
- c009431 Add `bold` border style
- fad8517 Add Node.js 12 to testing (#41)
- d566dd4 3.1.0
- cb77ed1 Refactor TypeScript definition to CommonJS compatible export (#40)
- 7fd83f0 3.0.0
- 60d37a8 Meta tweaks
- dd85217 Add TypeScript definition (#39)
- ae48864 2.1.0
- d7e0350 Update dependencies (#37)
- 7e31c3c 2.0.0
- 7b20756 Require Node.js 6
- dbaf2a9 Add ability to pass hex color to the `borderColor` and `backgroundColor ` options (#34)
- 9026b1e Meta tweaks
- f968a18 1.3.0
- 84b1d59 Update `widest-line` dependency (#31)
- b874bbb 1.2.2
- 34ce0ce Prevent padding error for center alignment (#28)
Package name: update-notifier
The new version differs by 66 commits.- adf7803 4.0.0
- fb5161c Remove the `callback` option (#158)
- 39682de Rename `boxenOpts` option to `boxenOptions`
- bc1721a Avoid showing notification if current version is the latest (#174)
- ccaf686 Update dependencies
- b1525e6 Disable when `NODE_ENV` is `test` (#173)
- bf73119 Fix install command for npm global (#165)
- 592b025 3.0.1
- f8b4e60 Update Travis matrix
- a6d6b49 Update URL to TTY (#163)
- f9d168a Remove object spread to support node >=8.0.0 <8.6.0 (#164)
- 1712928 Tidelift tasks
- 72f83d1 Create funding.yml
- a7bb3ee 3.0.0
- ad8ed1b Suggest yarn when installed with yarn (#132)
- 5f06620 Exit the update check process if it does not respond after 30s (#156)
- 79e89ad Fix failing test (#155)
- c8faa84 Add `distTag` option (#151)
- 14632e4 Add failing test for #153 (#154)
- aafd8a0 Require Node.js 8
- 0d49f51 Add Tidelift mention in the readme
- 8df01b3 Fix docs position of `shouldNotifyInNpmScript` (#143)
- d371834 Docs: isGlobal option does not default to true (#142)
- 5cd6577 2.5.0
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report