barista icon indicating copy to clipboard operation
barista copied to clipboard

[Snyk] Security upgrade @actions/core from 1.2.6 to 1.9.1

Open DavidPHirsch opened this issue 2 years ago • 1 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • tools/slack-release-notifier/package.json
    • tools/slack-release-notifier/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 536/1000
Why? Recently disclosed, Has a fix available, CVSS 5
Improper Input Validation
SNYK-JS-ACTIONSCORE-2980270
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

DavidPHirsch avatar Aug 14 '22 17:08 DavidPHirsch

Deploy preview for barista ready!

✅ Preview https://barista-m944ewxn9-dynatrace-oss.vercel.app

Built with commit 9d7d7b730d9b5dd07d0bd4aecb809f72c74ca971. This pull request is being automatically deployed with vercel-action

github-actions[bot] avatar Aug 14 '22 18:08 github-actions[bot]