pg-generator icon indicating copy to clipboard operation
pg-generator copied to clipboard

[Snyk] Fix for 1 vulnerabilities

Open ozum opened this issue 2 years ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: chalk The new version differs by 53 commits.
  • 3fca615 2.0.0
  • f66271e Add tagged template literal (#163)
  • 23ef1c7 fix linter errors
  • c015568 add rainbow example
  • 09fb2d8 Re-implement `chalk.enabled` (#160)
  • 608242a spoof supports-color
  • 18f2e7c add host information output
  • 523b998 Revert "TEMPORARY: emergency travis CI fix (see comments)"
  • 54975fb TEMPORARY: emergency travis CI fix (see comments)
  • 1d73b21 Improve readme
  • 6f4d6b3 Bump dependencies
  • 8702496 Remove `chalk.styles`
  • 0412cdf Minor code improvements
  • 249b9ac ES2015ify the codebase
  • cb3f230 Add RGB (256/Truecolor) support (#140)
  • dbae68d Update dependent package count in the readme (#154)
  • 9b60021 Drop support for Node.js 0.10 and 0.12
  • 0d21449 check parent builder object for enabled status (#142)
  • 5a69476 add XO badge
  • 492f11f add example file
  • 4ce73b6 make XO happy
  • 7c02cf4 Add log statement to chalk examples (#129)
  • 835ca3d You've just reached 10,000 dependent modules. (#122)
  • 74c087d minor doc improvements (#120)

See the full diff

Package name: inquirer The new version differs by 250 commits.
  • 54285c7 Publish
  • a2a751a Update dependencies
  • 3986ea3 Update lerna to use yarn
  • 7bcb7d3 close keypress stream when rl close (#835)
  • 83e8727 Update lodash (#834)
  • 2fbec5c Bump dependencies
  • 5c9f9e0 Fix typo (#826)
  • da5d0e2 Publish
  • e05ae81 Issue 711 update (#825)
  • dbfe890 Clear password field on backspace (#821)
  • e14796b Upgrade lodash to 4.17.12 to Fix Vulnerability (#824)
  • 29ac965 Update husky to the latest version 🚀 (#819)
  • d82131e Update lint-staged to the latest version 🚀 (#818)
  • 1f849ab feat: add inquirer-file-tree-selection-prompt readme (#815)
  • b951b48 Publish
  • aeab66e Revert "Remove all event listeners on close to avoid memory leak (#808)" (#813)
  • 5f0b513 Publish
  • 38569a3 Bump dependencies
  • 705e9cc Remove all event listeners on close to avoid memory leak (#808)
  • 91a4d59 Remove paginated option from example (#801)
  • c64cf89 Update husky to the latest version 🚀 (#798)
  • e41c61d Setup publishConfig to public
  • ee1cc70 Publish
  • 8535305 Add number support for choices prompt (#796)

See the full diff

Package name: nunjucks The new version differs by 7 commits.
  • 53d1223 Release v3.2.1
  • 93129bf Replace yargs with commander
  • 17691da Chokidar bump
  • 40dfdf0 Remove dead link
  • cefb1cf Prevent optional dependency Chokidar from loading when not watching
  • 1485a44 Add badges in README.md
  • 2246457 Add Mozilla Code of Conduct file

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

ozum avatar May 14 '22 07:05 ozum