phoenix
phoenix copied to clipboard
[Snyk] Security upgrade tern from 0.20.0 to 0.21.0
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- src/extensions/default/JavaScriptCodeHints/package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
551/1000 Why? Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MINIMATCH-3050818 |
No | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: tern
The new version differs by 41 commits.- e6a7777 Mark version 0.21.0
- 3f440fd Remove trailing whitespace
- 3cfb76a Use characters, rather than utf16 units, as counting unit in queries
- 46fd2dd Make Object.assign also copy 3rd and 4th args properties
- 4ec34a2 Fix typo in manual
- db13aac [webpack plugin] Fix root array support
- 93f4420 update acorn dependency
- 21b4f4b reference Chocolat editor support
- 4a88712 browser index items for Storage, localStorage and sessionStorage are not
- 3043088 Typo
- 2489fd3 Remove duplicate keys in definition files
- b26e513 allow for `modules` options in the webpack plugin
- a9be241 add support for `modules` key
- 0705849 fix typo
- 8b89a62 allow for function configs
- f9bde57 [emacs mode] Fix activity check in tern-run-command
- 0093913 add plugin_webpack link to TOC
- de94445 Remove NPM warning about minimatch RegExp DoS issue
- c752a24 [webpack plugin] Add documentation
- 4393441 [doc_comments plugin] Ignore leading question or exclamation marks
- 3f4794d Clear scopes on AST before analysis
- 141eba1 Fix links to demo
- 4ed1e1c [browser defs] Add MutationObserver interface
- ca40568 [browser defs] Add some methods
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
Error: Contributor Licence Agreement Signature Missing
The following commiter(s) has not signed the Contributor Licence Agreement: snyk-bot Please sign the Contributor Licence Agreement by clicking the following link.
Kudos, SonarCloud Quality Gate passed!
0 Bugs
0 Vulnerabilities
0 Security Hotspots
0 Code Smells
No Coverage information
0.0% Duplication