coverage-blamer
coverage-blamer copied to clipboard
[Snyk] Security upgrade stylus from 0.54.8 to 0.56.0
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
658/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-SEMVER-3247795 |
No | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: stylus
The new version differs by 27 commits.- fc2e630 chore: add url parse guard (#2600)
- 3329f5b deps: remove semver and mkdirp deps and add node17 test (#2641)
- e64ae7d feat: upgrade debug version from v3 to v4 (#2643)
- 33a5fd9 Fix: variable names beginning with a keyword and dash (#2634)
- d2cddcf Fix: `@ import` url() error in dependency resolver (#2632)
- 9cb7635 chore: add new npm ugnore config (#2631)
- dde9868 0.55.0 (#2630)
- fe5bde1 Replace dependency css-parse with css (#2554)
- 7334567 Add deg and fr as exceptions for 0 value unit omission (#2578)
- 57480a4 chore: update history.md and readme.md (#2628)
- f5a02e8 chore: add macos platform test (#2624)
- 1f7f419 fix yaml front matter (#2617)
- 6a96c0f [skip ci]chore: update reademe.md content (#2602)
- 99b05a9 chore: add issue and pull request template (#2606)
- ae9d267 chore: add github actions ci and improve test (#2601)
- 11a0735 Bump lodash from 4.17.19 to 4.17.21 (#2589)
- 7a8e777 Bump glob-parent from 5.1.1 to 5.1.2 (#2592)
- 23d3295 Merge pull request #2571 from dthadi3/ppc64le
- f546669 Travis-ci: Updated nodejs versions 10, 12, 14
- 5b90e45 Travis-ci: added support for ppc64le
- 59bc665 Merge pull request #2549 from mockee/dev
- 96c02de Bug fixes of encoding png image in `url` lib function.
- 8f42760 Merge pull request #2186 from royels/1567
- 775537b Create SECURITY.md
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: