wip
wip copied to clipboard
[Snyk] Fix for 1 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|
![]() |
Prototype Pollution SNYK-JS-DOTPROP-543489 |
Yes | Proof of Concept |
Commit messages
Package name: configstore
The new version differs by 25 commits.- 310f25f 5.0.0
- b05129a Require Node.js 8
- 6138851 Tidelift tasks
- da89479 Create funding.yml
- f075bc5 Meta tweaks
- 0b26655 Add Tidelift mention in the readme
- 0df1ec9 Mention `conf` in the readme (#62)
- fca8373 4.0.0
- d9b3257 Require Node.js 6
- b8d6372 Do not create a file on read if it doesn't exist (#57)
- 0dc1a8f Add `configPath` option (#58)
- f09f067 3.1.2
- d213757 Add license file
- 35d46bb 3.1.1
- 7bd5030 Pass options object to makeDir.sync (#55)
- 0108c44 Update renamed `electron-config` → `electron-store`
- fbb075d 3.1.0
- a4067fd Bump dependencies and switch to `make-dir`
- f48ba06 Add note about Electron
- 7ce00b4 3.0.0
- 66f605d Simplify the XDG config fallback
- 76fea84 Bump dependencies
- 383b09f Remove the deprecated `.del()` method
- 9ed0378 ES2015ify
Package name: update-notifier
The new version differs by 66 commits.- adf7803 4.0.0
- fb5161c Remove the `callback` option (#158)
- 39682de Rename `boxenOpts` option to `boxenOptions`
- bc1721a Avoid showing notification if current version is the latest (#174)
- ccaf686 Update dependencies
- b1525e6 Disable when `NODE_ENV` is `test` (#173)
- bf73119 Fix install command for npm global (#165)
- 592b025 3.0.1
- f8b4e60 Update Travis matrix
- a6d6b49 Update URL to TTY (#163)
- f9d168a Remove object spread to support node >=8.0.0 <8.6.0 (#164)
- 1712928 Tidelift tasks
- 72f83d1 Create funding.yml
- a7bb3ee 3.0.0
- ad8ed1b Suggest yarn when installed with yarn (#132)
- 5f06620 Exit the update check process if it does not respond after 30s (#156)
- 79e89ad Fix failing test (#155)
- c8faa84 Add `distTag` option (#151)
- 14632e4 Add failing test for #153 (#154)
- aafd8a0 Require Node.js 8
- 0d49f51 Add Tidelift mention in the readme
- 8df01b3 Fix docs position of `shouldNotifyInNpmScript` (#143)
- d371834 Docs: isGlobal option does not default to true (#142)
- 5cd6577 2.5.0
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: