generator-smarttv
generator-smarttv copied to clipboard
[Snyk] Security upgrade yeoman-generator from 0.24.1 to 1.1.1
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
658/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-HOSTEDGITINFO-1088355 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: yeoman-generator
The new version differs by 54 commits.- 80863b0 1.1.1
- af3048f Fix issue with API documentation deploy script
- 74cb46f Document legacy Generator.extend method properly - rel #996
- 6d267f0 Use XO
- 17173a2 chore(package): update yeoman-assert to version 3.0.0 (#1004)
- 59d0120 Add eslint as direct dev dependency
- cf67f66 Bump dependencies
- ac542ba Bump dev dependencies
- 0b06786 Improve option name validation message
- 67b90f4 Add failing test for Boolean options starting with no-
- 51414c0 Update Travis test matrix
- 5c79882 1.1.0
- b59ffa2 Bump mem-fs-editor - fix #998
- cc675f0 Fix fs documentation (#997)
- 8c791e7 1.0.1
- 244c92c Fix undefined boolean options - Fix #988 (#989)
- e841f35 Update example for docs (#987)
- 138ed98 v1.0.0
- 871ed39 v1.0.0-rc1
- df7012f Fix composeWith to allow passing explicit arguments for yeoman-generator@<1.0
- 9aa4e02 Alias desc to description in argument/option config
- 1b6eede Remove Gruntfile api - Fix #744
- fedb2fb Update composeWith to take path or namespace as first argument - Fix #983
- 1885dec Single way of passing both arguments and options to composed generator
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report