beer
beer copied to clipboard
[Snyk] Security upgrade snyk from 1.192.5 to 1.230.7
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
706/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.7 |
Server-side Request Forgery (SSRF) SNYK-JS-NETMASK-6056519 |
No | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: snyk
The new version differs by 225 commits.- 7d81923 Merge pull request #800 from snyk/fix/fix-yarn-release
- 5571ce7 fix: leave proxy-agent as bundled only to fix yarn install
- e6568ec Merge pull request #797 from snyk/test/remove-bad-test
- f365660 test: skip test that uses previous bad version
- 0c6026e Merge pull request #795 from snyk/fix/https-agent-vuln
- c918814 fix: add packed dependency to prevent download from git
- ed05431 Merge pull request #790 from snyk/fix/https-agent-vuln
- 8815e84 fix: address https-proxy-agent vulnerability
- 18bcfb8 Merge pull request #784 from snyk/fix/improve-marker-expression-parsing
- f6e31a2 Merge pull request #783 from snyk/fix/https-proxy-agent
- e85691f fix: Improve parsing for marker expressions for python projects
- 244d0e0 fix: ignoring SNYK-JS-HTTPSPROXYAGENT-469131
- c965884 Merge pull request #772 from snyk/chore/introduce-prettier
- 9917da8 chore: apply prettier rules
- 9d9506f chore: add prettier configuration
- f75bb70 Merge pull request #782 from snyk/fix/docs-spelling
- 8506395 Merge pull request #781 from snyk/fix/remediation-package-text-color
- 7802663 Merge pull request #780 from snyk/feat/cocoapods
- a73c5ea fix: correct docs spelling
- b9867a3 fix: remediation package name color from cyan to default (grey)
- 2306a8c Merge pull request #768 from snyk/sfat-patch-1-1
- 4bbcc3c feat: add CocoaPods support
- 825666d Merge pull request #779 from snyk/fix/remove-stringly-typed-boolean-option-values
- 1efdee3 refactor: no need to use lodash to retrieve strictOutOfSync
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: