event-backend
event-backend copied to clipboard
[Snyk] Fix for 2 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-ANSIREGEX-1583908 |
No | Proof of Concept | |
718/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.5 |
Race Condition SNYK-JS-GRUNT-2813632 |
No | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: grunt
The new version differs by 75 commits.- 82d79b8 1.5.3
- 572d79b Merge pull request #1745 from gruntjs/fix-copy-op
- 58016ff Patch up race condition in symlink copying.
- 0749e1d Merge pull request #1746 from JamieSlome/patch-1
- 69b7c50 Create SECURITY.md
- ac667b2 1.5.2
- 7f15fd5 Update Changelog
- b0ec6e1 Merge pull request #1743 from gruntjs/cleanup-link
- 433f91b Clean up link handling
- d5969ec 1.5.1
- ad22608 Merge pull request #1742 from gruntjs/update-symlink-test
- 0652305 Fix symlink test
- a7ab0a8 1.5.0
- b2b2c2b Updated changelog
- 3eda6ae Merge pull request #1740 from gruntjs/update-deps-22-10
- 47d32de Update testing matrix
- 2e9161c More updates
- 04b960e Remove console log
- aad3d45 Update dependencies, tests...
- fdc7056 Merge pull request #1736 from justlep/main
- e35fe54 support .cjs extension
- ee722d1 1.4.1
- e7625e5 Update Changelog
- 5d67e34 Merge pull request #1731 from gruntjs/update-options
Package name: mocha
The new version differs by 50 commits.- ef6c820 Release v6.2.1
- 9524978 updated CHANGELOG for v6.2.1 [ci skip]
- dfdb8b3 Update yargs to v13.3.0 (#3986)
- 18ad1c1 treat '--require esm' as Node option (#3983)
- fcffd5a Update yargs-unparser to v1.6.0 (#3984)
- ad4860e Remove extraGlobals() (#3970)
- b269ad0 Clarify effect of .skip() (#3947)
- 1e6cf3b Add Matomo to website (#3765)
- 91b3a54 fix style on mochajs.org (#3886)
- 0e9d8ad tty.getWindowSize is not a function inside a "worker_threads" worker (#3955)
- 48da42e Remove jsdoc index.html placeholder from eleventy file structure and fix broken link in jsdoc tutorial (#3966)
- bd47776 Release v6.2.0
- cc595af update CHANGELOG.md for v6.2.0 [ci skip]
- 59d70ee fix: remove duplicate line-height property (#3957)
- f77cac4 fix: do not redeclare variable (#3956)
- 6201e42 Hide stacktrace when cli args are missing (#3963)
- 88f45d5 Don't re-initialize grep option on watch re-run (#3960)
- 5d4dd98 Fix No Files error when file is passed via --files (#3942)
- 15b96af Collect test files later (#3953)
- ccee5f1 Base reporter store ref to console.log (#3725)
- 47318a7 update @ mocha/contributors to v1.0.4 (#3944)
- c903147 More, improved integration tests for watching (#3929)
- e341ea4 Update CI config files to use Node-12.x (#3919)
- 3064d25 update @ mocha/docdash to v2.1.1 (#3945)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: 🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.