newman-reporter-html icon indicating copy to clipboard operation
newman-reporter-html copied to clipboard

[Snyk] Security upgrade newman from 4.5.7 to 5.2.0

Open snyk-bot opened this issue 4 years ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 776/1000
Why? Recently disclosed, Has a fix available, CVSS 9.8
Prototype Pollution
SNYK-JS-LODASH-590103
Yes No Known Exploit
medium severity 520/1000
Why? Has a fix available, CVSS 5.9
Regular Expression Denial of Service (ReDoS )
SNYK-JS-MARKED-584281
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: newman The new version differs by 226 commits.
  • 1c9c649 Merge branch 'release/5.2.0' into master
  • 924a4eb Release v5.2.0
  • ea420f4 Update CHANGELOG
  • 4e706c0 Update dependencies
  • c641fb0 fix: package.json & package-lock.json to reduce vulnerabilities (#2497)
  • 6ad8443 fix: package.json & package-lock.json to reduce vulnerabilities (#2494)
  • fa31b98 Update dependabot.yml
  • a7008c5 Update CLI run command description
  • 52b645e Update CLI options description
  • fc06b17 Add cookieJar option (#2393)
  • 1e857a4 Chore(deps): bump commander from 5.1.0 to 6.1.0 (#2491)
  • 0612bfe Create dependabot.yml
  • 63b41fb Merge pull request #2448 from postmanlabs/dependabot/npm_and_yarn/postman-request-2.88.1-postman.24
  • 37828b8 Merge branch 'develop' into dependabot/npm_and_yarn/postman-request-2.88.1-postman.24
  • faed735 docs: add JSON to the -d description
  • 3a60d2c typo: "it's" => "its" (#2438)
  • 3b11e6f docs: include `envVar` (#2464)
  • 96e8f22 Chore(deps): bump postman-request
  • b426081 Update dependencies
  • abd7baa Merge branch 'release/5.1.2' into develop
  • e618e8e Merge branch 'release/5.1.2'
  • d344a1f Update postman-collection-transformer to version 3.3.3
  • 366b481 Merge branch 'release/5.1.2' into develop
  • 9ec6c77 Merge branch 'release/5.1.2'

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

snyk-bot avatar Sep 02 '20 06:09 snyk-bot