beer icon indicating copy to clipboard operation
beer copied to clipboard

[Snyk] Upgrade grunt-cli from 1.3.2 to 1.4.3

Open snyk-bot opened this issue 3 years ago • 0 comments

Snyk has created this PR to upgrade grunt-cli from 1.3.2 to 1.4.3.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 4 versions ahead of your current version.
  • The recommended version was released a year ago, on 2021-05-25.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
375/1000
Why? CVSS 7.5
No Known Exploit
Prototype Pollution
SNYK-JS-SETVALUE-450213
375/1000
Why? CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-SETVALUE-1540541
375/1000
Why? CVSS 7.5
No Known Exploit
Prototype Pollution
SNYK-JS-SETVALUE-450213
375/1000
Why? CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-SETVALUE-1540541
375/1000
Why? CVSS 7.5
No Known Exploit
Prototype Pollution
SNYK-JS-MIXINDEEP-450212
375/1000
Why? CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: grunt-cli from grunt-cli GitHub release notes
Commit messages
Package name: grunt-cli
  • cf8c452 1.4.3
  • 07f3b0d Fix preload option (#147)
  • 4d691e2 Revert liftoff (#144)
  • e820858 Revert liftoff changes due to https://github.com/gruntjs/grunt/issues/1725 (#143)
  • 2293dc5 1.4.0
  • bbc4400 Update changelog
  • 3fa5bf6 Ignore package-lock
  • c271173 Update deps, switch to actions (#141)
  • 84ebcb8 Bump deps, required node version and ci (#137)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

snyk-bot avatar May 26 '22 14:05 snyk-bot