htmlhint-loader icon indicating copy to clipboard operation
htmlhint-loader copied to clipboard

[Snyk] Security upgrade htmlhint from 0.10.1 to 0.16.2

Open snyk-bot opened this issue 2 years ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-ASYNC-2441827
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: htmlhint The new version differs by 187 commits.
  • 9796b67 chore(release): 0.16.2 [skip ci]
  • 98e45b9 fix: clenaup non-functional typos (#727)
  • 081db96 chore(deps-dev): bump @ types/xml from 1.0.5 to 1.0.6 (#740)
  • fad78d8 chore(deps): bump async from 3.2.0 to 3.2.2 (#739)
  • 63d367e refactor: move eslint config to type overrides (#725)
  • 77e9a6c chore(dependabot): correct quoting for prettier (#735)
  • e95cd82 chore: run lint once for CI (#726)
  • 88d3670 chore(build): add Dependabot for website packages (#721)
  • 4f85a1a chore(build): remove redundant matrix (#720)
  • 3c25de8 style: run prettier during lint (#724)
  • 26b4e44 chore(build): use caching in setup-node (#723)
  • 5b52a27 chore(build): run matrix on current node releases (#719)
  • 4de808c fix changelog duplication (#717)
  • ec2da2c chore(release): 0.16.1 [skip ci]
  • 4d702d8 fix: tagname-specialchars description (#714)
  • e027f30 Fix `How To Use` link. (#715)
  • f1030e3 chore(deps): bump y18n from 4.0.0 to 4.0.3 in /website (#713)
  • cdba1b3 chore(deps): bump lodash from 4.17.15 to 4.17.21 in /website (#712)
  • 2561560 chore(deps): bump ssri from 6.0.1 to 6.0.2 in /website (#711)
  • d8a28ea chore(deps): bump dns-packet from 1.3.1 to 1.3.4 in /website (#710)
  • 37a4d2b chore(deps): bump color-string from 1.5.3 to 1.6.0 in /website (#706)
  • 593ac56 chore(deps): bump url-parse from 1.4.7 to 1.5.3 in /website (#703)
  • 9f09a72 chore(deps): bump postcss from 7.0.30 to 7.0.39 in /website (#708)
  • d30a1e7 chore(deps): bump ws from 6.2.1 to 6.2.2 in /website (#707)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

snyk-bot avatar Apr 11 '22 16:04 snyk-bot