MMM-OnScreenMenu icon indicating copy to clipboard operation
MMM-OnScreenMenu copied to clipboard

[Snyk] Security upgrade pm2 from 2.10.4 to 3.0.0

Open snyk-bot opened this issue 2 years ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 748/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.1
Improper Privilege Management
SNYK-JS-SHELLJS-2332187
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: pm2 The new version differs by 200 commits.
  • 47eecb9 fix: README update + downgrade promptly
  • 5a17688 docs: update documentation, change monitor to monit
  • a082a5f docs: update documentation about new pm2 apm and metrics system
  • 29cccd9 Merge remote-tracking branch 'origin/development'
  • ca968cf Merge pull request #3728 from Unitech/release_3.0.0
  • 9cb24dd test: remove tests on http:transaction from apm, it was removed in apm 2.0.2
  • 2e91827 chore: upgrade pm2-io-apm to 2.0.2
  • 64c1ac8 Update README.md
  • 6392a38 chore: upgrade pm2-io-apm to 2.0.1 to fix https patching
  • b6e0650 Merge pull request #3734 from f-hj/development
  • 792cef8 Fix #3669
  • 6e3b45f chore: upgrade mocha to version 5
  • 9459937 chore: upgrades node modules
  • 66d5e06 chore: display active transport
  • dfd3d62 fix: format cpu usage at root
  • a3c2900 refactor: change default log date format
  • 439c373 chore: update readme with breaking changes
  • 829fcb3 chore: update version to 3.0.0
  • 09aacdc chore: upgrade module and version
  • df081ed Merge remote-tracking branch 'origin/master' into development
  • 0255c5a Merge pull request #3726 from soyuka/fix-list
  • d39a424 Fix cpu value for modules
  • a39eb4f Merge pull request #3725 from soyuka/fix-list
  • 623eb78 Fix pm2 list cpu display

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

snyk-bot avatar Jan 16 '22 16:01 snyk-bot