egg-init
egg-init copied to clipboard
[Snyk] Security upgrade globby from 9.2.0 to 10.0.0
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 479/1000 Why? Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-GLOBPARENT-1016905 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: globby
The new version differs by 12 commits.- 878ef6e 10.0.0
- 3706920 Upgrade `fast-glob` package to v3 (#126)
- 8aadde8 Add `globby.stream` (#113)
- 2dd76d2 Remove `**/bower_components/**` as a default ignore pattern
- 9f781ce Require Node.js 8
- 04d51bf Upgrade `ignore` package (#120)
- 2b61484 Readme tweaks
- ff3e1f9 Tidelift tasks
- 31f18ae Create funding.yml
- 33ca01c Fix using the `gitignore` and `stats` options together (#121)
- c737820 Minor TypeScript definition improvements
- 82db101 Add Node.js 12 to testing (#117)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report