spotify-api-graphql-console
spotify-api-graphql-console copied to clipboard
[Snyk] Fix for 1 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 661/1000 Why? Recently disclosed, Has a fix available, CVSS 7.5 |
Prototype Pollution SNYK-JS-LOADERUTILS-3043105 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: source-map-loader
The new version differs by 25 commits.- e0ec5d9 chore(release): 1.0.0
- 87fa9ae refactor: remove whatwg-encoding (#115)
- 4d043f0 docs: ignore example
- 1ccc708 test: coverage (#111)
- 73773e2 test: validate options (#110)
- 0d77b18 refactor: code
- 2ceba27 test: code (#108)
- 1e785a1 fix: use webpack fs (#105)
- 01b3812 refactor: code (#104)
- 4c39c22 fix: perf and crashing (#101)
- b64f7d8 fix: absolute path for sources and add sources in dependendencies
- c18d1f9 feat: indexed-sourcemap
- 526c229 test: refactor (#97)
- 7f769aa fix: avoid crash on big data URL source maps
- 2da2b2e chore(defaults): update (#95)
- 8433ed3 chore(release): 0.2.4
- 8262587 fix(package): 5 low severity vulnerabilities (#72)
- 637fde1 chore(package): remove unused `source-map` dependency (`dependencies`) (#71)
- e2fdbfd fix(index): resolve source maps with root-relative paths correctly (#68)
- 78ad469 fix(index): handle exception on loading invalid source maps (#67)
- a0b84d4 docs(README): typo fix (#64)
- 7843bb3 refactor(package): updates dependencies to fix CVE-2015-8315 (#62)
- 4f3833b docs(CHANGELOG): updates for `v0.2.3`
- 420e866 chore(release): 0.2.3
Package name: ts-loader
The new version differs by 250 commits.- 268bc69 chore(deps): upgrade most production deps (#1237)
- e160564 Add a cache to file path mapping (#1228)
- 14fa3f8 Add documentation about performance profiling (#1230)
- 3cc78b8 Fix typo in README.md (#1229)
- 8f2a509 Add documentation for the useCaseSensitiveFileNames option (#1227)
- 566e6ce Instead of checking date, check time thats more accurate to see if something has changed (#1217)
- 172ebeb Feature/typescript 4 1 (#1213)
- 0816fe9 Add peer dependencies for Yarn PnP (#1209)
- 4909d99 Fixed missing errors in watch mode in webpack5 (#1208)
- 3f73e98 Fix failed builds when using thread-loader (#1207)
- e90f8ad Fix memory leak when using multiple webpack instances (#1205)
- 95050eb Speeds up project reference build and doesnt store the result in memory (#1202)
- f99c7c4 doc: escape pipe in table (#1201)
- 0b4a86d Replace afterCompile to stop webpack 5 warning (#1200)
- 6d8d601 Fixed deprecation warnings on webpack@5. (#1195)
- cafc933 Fix installation link on README.md (#1192)
- f5e901e Bump http-proxy in /examples/react-babel-karma-gulp (#1182)
- 0767bce add github action status badge (#1190)
- db5ea55 Feature/upgrade testpack to ts4 (#1189)
- 95b6fe8 Uses existing instance if config file is same as already built solution (#1177)
- b38678a Update minimum compiler version to 3.6.3 (#1188)
- f8eba53 Add documentation and example code for projectReferences (#1184)
- 46d9761 Update docs to show transpileOnly does not affect project references (#1175)
- 0e64ceb Fix getOptionsHash when two options has different props but same values. (#1170)
Package name: webpack
The new version differs by 250 commits.- 610f368 5.0.0
- 5ce65c1 update examples
- bbe1230 Merge pull request #11628 from webpack/bugfix/real-content-hash
- 75ecff2 5.0.0-rc.6
- bfc35d6 Merge pull request #11603 from MayaWolf/master
- 76e8cbd Merge pull request #11622 from webpack/dependabot/npm_and_yarn/types/node-13.13.25
- 9fd1be2 chore(deps-dev): bump @ types/node from 13.13.23 to 13.13.25
- 36bcfaa Merge pull request #11621 from webpack/bugfix/11619
- 9130d10 fix called variables with ProvidePlugin
- 3e42105 Merge pull request #11620 from webpack/bugfix/11617
- 4709719 skip connections copied to concatenated module
- 57b493f 5.0.0-rc.5
- 1658e2f Merge pull request #11618 from webpack/bugfix/11615
- a8fb45d fixes crash in SideEffectsFlagPlugin
- 84b196d emit error instead of crashing when unexpected problem occurs
- 5573fed Merge pull request #11601 from Hornwitser/improve-suggested-polyfill-config
- 9b5cce9 Merge pull request #11609 from snitin315/export-types
- 37c495c export type RuleSetUseItem
- 39faf34 export type RuleSetUse
- e5fd246 export type RuleSetConditionAbsolute
- 660baad export RuleSetCondition types
- 13e3ca5 Merge pull request #11602 from webpack/bugfix/shared-runtime-chunk
- 9c0587e Merge pull request #11606 from webpack/dependabot/npm_and_yarn/simple-git-2.21.0
- 502d166 Merge pull request #11607 from webpack/dependabot/npm_and_yarn/acorn-8.0.4
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: