cli icon indicating copy to clipboard operation
cli copied to clipboard

[Snyk-dev] Security upgrade uglify-js from 2.8.29 to 3.14.3

Open ariel-henryson opened this issue 2 years ago • 1 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • test/fixtures/uglify-package/node_modules/ug-deep/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: uglify-js The new version differs by 250 commits.
  • bca83cb v3.14.3
  • a841d45 fix corner case in `awaits` (#5160)
  • eb93d92 fix corner case in `awaits` (#5158)
  • a0250ec fix corner case in `dead_code` (#5154)
  • 2580162 parse `let` as symbol names correctly (#5151)
  • 32ae994 fix issues in tests flagged by LGTM (#5150)
  • 03aec89 fix corner cases in `strings` & `templates` (#5147)
  • faf0190 document ECMAScript quirks (#5148)
  • c8b0f68 fix corner case in `merge_vars` (#5143)
  • 87b9916 fix corner case in `inline` (#5141)
  • 940887f fix corner case in `evaluate` (#5139)
  • 0b2573c fix corner case in `templates` (#5137)
  • 1575210 avoid potential RegExp denial-of-service (#5135)
  • f766bab enhance `templates` (#5131)
  • 436a293 enhance `dead_code` (#5130)
  • 55418fd fix corner case in `rests` (#5129)
  • 8578688 v3.14.2
  • 4b88dfb tweak test & warnings (#5123)
  • c3aef23 fix corner case in `reduce_vars` (#5121)
  • db94d21 fix corner case in `side_effects` (#5118)
  • 9634a9d fix corner cases in `optional_chains` (#5110)
  • befb99b fix corner case in `inline` (#5115)
  • 02eb8ba fix corner case in `collapse_vars` (#5113)
  • c09f63a fix corner case in `rests` (#5109)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

ariel-henryson avatar Jul 27 '22 20:07 ariel-henryson

Warnings
:warning:

"fix: test/fixtures/uglify-package/node_modules/ug-deep/package.json to reduce vulnerabilities" is too long. Keep the first line of your commit message under 72 characters.

Generated by :no_entry_sign: dangerJS against e22f7e42f573473d5ada773bf462be25be2f4959

github-actions[bot] avatar Jul 27 '22 20:07 github-actions[bot]