defunctr
defunctr copied to clipboard
[Snyk] Fix for 1 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 658/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-SEMVER-3247795 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: eslint
The new version differs by 250 commits.- 3dd6741 7.0.0
- 9a722f9 Build: changelog update for 7.0.0
- b98d8bd Upgrade: [email protected] (#13271)
- 4c0b028 Fix: remove Node.js and CommonJS category from build process (#13242)
- 401a687 Chore: fix rules list for prereleases (#13230)
- 4ef6158 Breaking: [email protected] (#13270)
- b5c8d73 Docs: update 7.0.0 migration guide for consistency (#13267)
- 356fdb4 Docs: add migration guide (#12692)
- 015edf6 Sponsors: Sync README with website
- fdfa364 7.0.0-rc.0
- 8d1b4db Build: changelog update for 7.0.0-rc.0
- 0b1d65a Update: Improve report location for array-callback-return (refs #12334) (#13109)
- d85e291 Fix: yoda left string fix for exceptRange (fixes #12883) (#13052)
- 2ce6bed Chore: added tests for nested arrays (#13145)
- d3aac53 Update: report backtick loc in no-unexpected-multiline (refs #12334) (#13142)
- 8e7a2d9 Fix: func-call-spacing "never" reports wrong message (fixes #13190) (#13193)
- bcafd0f Update: Add ESLint API (refs eslint/rfcs#40) (#12939)
- 3eeae56 Upgrade: some (dev) deps (#13155)
- 6b7030b Chore: Run tests on Node.js v14 (#13210)
- ebc28d7 Fix: Remove default .js from --ext CLI option (#13176)
- 5c1bdeb Update: Improve report location for getter-return (refs #12334) (#13164)
- 56d2bee Docs: fix typos (#13204)
- e13256e Chore: use espree.latestEcmaVersion in config-initializer (#13157)
- e4f57b7 Chore: add nested array tests for array-element-newline (#13161)
Package name: gulp
The new version differs by 134 commits.- 55eb23a Release: 4.0.0
- 173a532 Docs: Fix the installation instructions
- ec54d09 Docs: Improve note about out-of-date docs
- 03b7c98 Docs: Update recipes to install gulp@next
- 2eba29e Docs: Remove run-sequence from recipes
- 76eb4d6 Docs: Add installation instructions & update badges
- fbc162f Docs: Remove references to gulp-util
- 3011cf9 Scaffold: Normalize repository
- f27be05 Update: Remove graceful-fs from test suite
- 361ab63 Upgrade: Update glob-watcher
- 064d100 Build: Avoid broken node 9
- 057df59 Release: 4.0.0-alpha.3
- c1ba80c Breaking: Upgrade major versions of glob-watcher, gulp-cli & vinyl-fs
- 89acc5c Docs: Improve ES2015 task exporting examples (#1999)
- 0ac9e04 Docs: Add "Project structure" section to CONTRIBUTING.md (#1859)
- 723cbc4 Docs: Fix syntax in recipe example (#1715)
- d420a6a Docs: Have gulp.lastRun take a function to avoid task registration (#1828)
- 29ece6f Upgrade: Update undertaker
- e931cb0 Docs: Fix changelog typos (#1696)
- 477db84 Docs: Add a "BrowserSync with Gulp 4" recipe (#1659)
- d4ed3c7 Docs: Add options.cwd for gulp.src API (#1645)
- 5dc3b07 Docs: Update gulp.watch API to align with glob-watcher
- 0c66069 Breaking: Replace chokidar as gulp.watch with glob-watcher wrapper
- c3dbc10 Docs: Clarify incremental builds example (#1609)
Package name: gulp-nuget-pack
The new version differs by 6 commits.- 89d5f1c v0.1.0
- b0ad29e Upgrade gulp to v4 (#4 from apneer/fixvulnerab)
- dc88e22 move to deps
- ab3e7a9 Merge branch 'fixvulnerab' of github.com:apneer/gulp-nuget-pack into fixvulnerab
- 7bed36d Update gulp to remove vulnerabilities; remove deprecated gulp-util
- 8b3ac7e Upgrade gulp to v4 to fix vulnerabilites in minimatch; remove gulp-util that is deprecated
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
π§ View latest project report
π Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
π¦ Regular Expression Denial of Service (ReDoS)