code-push-server icon indicating copy to clipboard operation
code-push-server copied to clipboard

[Snyk] Fix for 1 vulnerabilities

Open lisong opened this issue 2 years ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 703/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.2
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: aliyun-sdk The new version differs by 16 commits.
  • 3f0c2be 1.12.2
  • 6db2525 x-oss-object-acl
  • 3a3214b fix dependency
  • 17ba115 BatchCompute增加getAvailable接口
  • 06dd64d 1.12.0
  • 3c14590 Merge pull request #177 from aliyun-UED/cname_request_payer
  • c42e269 feat: support canme and requestpayer for oss
  • 3303b86 update version to 1.11.12
  • 66e03b2 Merge pull request #173 from liketic/add-new-alert-api
  • 4846276 Remove redundant required tag
  • 00b8c29 Fix method name
  • 29dc9a7 Update alert api
  • d60ce9e Merge pull request #172 from Chunlin-Li/master
  • 5d26f8b 1.11.11
  • 104d3f1 feat(APIs): 更新 SLS 中 alert 和 savedsearch 相关的 API
  • 704fcf8 update version to 1.11.10

See the full diff

Package name: i18n The new version differs by 43 commits.
  • e0dbcc4 Merge branch 'release/0.8.4' into npm
  • 7f4c5da version bumb & docs
  • 94db9e7 Merge pull request #261 from emmerich/master
  • 0e7b67a feat(messageformat): backward compat parsing
  • 1f6f10e test: re-enabled messageformat tests
  • 599cfbd chore(dotfiles): better local dev setup
  • 1f732ef Create SECURITY.md
  • e8dcd30 Create FUNDING.yml
  • 22fb910 audit fix
  • 9dcea0d greenkeeper badge to top
  • 00c8e17 Merge pull request #414 from mashpie/greenkeeper/initial
  • a238551 skip windows CI for now
  • 8a037d4 travis +osx +windows
  • 8133cf1 chore: adapt code to updated dependencies
  • 3d498a4 chore(package): update lockfile package-lock.json
  • c2cb924 docs(readme): add Greenkeeper badge
  • 1428a3d chore(package): update dependencies
  • 9aae8f4 travis: all branches enabled
  • aefa31d Merge pull request #411 from 0xflotus/patch-1
  • 298da08 fixed small errors
  • 83caab3 Merge pull request #395 from rimiti/some-improvements
  • 2e0d87a doc(README.md) broken badge + license duplicate block removed
  • bd4a6e1 chore(appveyor.yml) file removed
  • 3244756 feat(.travis.yml) iojs removed from pipeline

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

lisong avatar Dec 05 '23 14:12 lisong