plugin-flex-outbound-dialpad icon indicating copy to clipboard operation
plugin-flex-outbound-dialpad copied to clipboard

[Snyk] Security upgrade twilio-run from 2.1.1 to 2.5.0

Open twilio-product-security opened this issue 2 years ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • dialpad-functions/package.json
    • dialpad-functions/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 556/1000
Why? Recently disclosed, Has a fix available, CVSS 5.4
Open Redirect
SNYK-JS-GOT-2932019
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: twilio-run The new version differs by 46 commits.
  • 27d1d0e chore(release): 2.5.0
  • 525f70c feat(logger): expose errors better & upgrade serverless (#132)
  • 966a089 fix(templating): catch errors in command, not before (#130)
  • f8e49b5 feat(start): handle EADDRINUSE by asking for another port number (#127)
  • 540f9b0 docs(logs): adds logs docs to README (#126)
  • 0c111c3 Merge pull request #129 from ShelbyZ/patch-2
  • 73fab1f Fixing docs link in README
  • 3ba05b8 2.4.1
  • abd9f43 Merge branch 'fix-array-flat'
  • cd52b9a fix(templates): adds tests for getFiles and replaces Array.flat
  • 2693c05 chore(release): 2.4.0
  • 773d073 feat(templates): support nested templates to create nested routes (#123)
  • 91c5768 chore(release): 2.3.0
  • ec4af4a feat(logs): adds command to access new logging functions (#110)
  • fe85cc3 chore: remove package-lock.json from repo (#118)
  • 1e487f1 chore: remove package-lock.json from repo
  • e105f36 feat(templates): add support for custom template URLs (#115)
  • 523e09a feat(templates): template README downloaded and saved to readmes… (#116)
  • 09e94a2 Merge pull request #117 from badsketch/update-node-check
  • 0c5635d fix: changes pinned node version to 10.x
  • 8fbe2e1 chore(release): 2.2.1
  • 21c8309 fix(activate): remove required to flag because of production option
  • 8a8d4d5 chore(release): 2.2.0
  • f4b3038 feature: #90 allow users to specify a github token (#96)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Open Redirect

twilio-product-security avatar Jun 19 '22 20:06 twilio-product-security