beer
beer copied to clipboard
[Snyk] Upgrade grunt-cli from 1.3.2 to 1.4.3
Snyk has created this PR to upgrade grunt-cli from 1.3.2 to 1.4.3.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is 4 versions ahead of your current version.
- The recommended version was released a year ago, on 2021-05-25.
The recommended version fixes:
| Severity | Issue | PriorityScore (*) | Exploit Maturity |
|---|---|---|---|
| Prototype Pollution SNYK-JS-UNSETVALUE-2400660 |
375/1000 Why? CVSS 7.5 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-SETVALUE-450213 |
375/1000 Why? CVSS 7.5 |
Proof of Concept | |
| Prototype Pollution SNYK-JS-SETVALUE-1540541 |
375/1000 Why? CVSS 7.5 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-SETVALUE-450213 |
375/1000 Why? CVSS 7.5 |
Proof of Concept | |
| Prototype Pollution SNYK-JS-SETVALUE-1540541 |
375/1000 Why? CVSS 7.5 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-MIXINDEEP-450212 |
375/1000 Why? CVSS 7.5 |
Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: grunt-cli
- 1.4.3 - 2021-05-25
-
1.4.2 - 2021-04-04
- Revert liftoff (#144) 4d691e2
- Revert liftoff changes due to gruntjs/grunt#1725 (#143) e820858
-
1.4.1 - 2021-03-25
- Revert liftoff changes due to gruntjs/grunt#1725 (#143) e820858
- 1.4.0 - 2021-03-25
- 1.3.2 - 2018-11-04No content.
Commit messages
Package name: grunt-cli
- cf8c452 1.4.3
- 07f3b0d Fix preload option (#147)
- 4d691e2 Revert liftoff (#144)
- e820858 Revert liftoff changes due to https://github.com/gruntjs/grunt/issues/1725 (#143)
- 2293dc5 1.4.0
- bbc4400 Update changelog
- 3fa5bf6 Ignore package-lock
- c271173 Update deps, switch to actions (#141)
- 84ebcb8 Bump deps, required node version and ci (#137)
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🔕 Ignore this dependency or unsubscribe from future upgrade PRs