tiny-care-terminal icon indicating copy to clipboard operation
tiny-care-terminal copied to clipboard

[Snyk] Upgrade git-utils from 5.6.2 to 5.7.3

Open snyk-bot opened this issue 2 years ago • 0 comments

Snyk has created this PR to upgrade git-utils from 5.6.2 to 5.7.3.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 4 versions ahead of your current version.
  • The recommended version was released a year ago, on 2021-07-08.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Arbitrary Code Injection
SNYK-JS-UNDERSCORE-1080984
382/1000
Why? Proof of Concept exploit, CVSS 5.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: git-utils
  • 5.7.3 - 2021-07-08
  • 5.7.2 - 2021-06-21
  • 5.7.1 - 2021-01-14
  • 5.7.0 - 2020-12-07

    5.7.0

  • 5.6.2 - 2019-11-27

    Releasing v5.6.2

from git-utils GitHub release notes
Commit messages
Package name: git-utils
  • 208a033 5.7.3
  • dea9ac5 5.7.2
  • 1c78b00 Merge pull request #113 from atom/update-nan
  • 4db2768 Bump [email protected]
  • aeb59c7 Merge pull request #112 from atom/migrate-to-gh-actions
  • 0bf7dee gh actions
  • 572d3e8 5.7.1
  • a265d04 Merge pull request #104 from aminya/submodule-init
  • 06842ce Set CRLF on Appveyor
  • 4a22127 .npmignore: Ignore heavy, unused parts of libgit2 (#108)
  • 8bc1ccb Use MSVC 2015 in Appveyor
  • ff04ff1 Use node 12 in the CI
  • 826031a Run the tests on Windows
  • 6d86f97 Update temp to fix the tests on Windows
  • cc9ecf9 Fix `jasmine-focused does not contain a package.json file`
  • 8f9cc2b fix CI script
  • 409bff8 Emphesize running `npm run prepare` for development
  • d6be34b fix: use prepare to init the submodule
  • 86b38eb 5.7.0
  • 407f34e git-diff: Update README (#101)
  • d2cb646 git-diff: Add support for ignoreChangeWhitespace & ignoreWhitespace (#100)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

snyk-bot avatar Sep 09 '22 04:09 snyk-bot