nasa-cli
nasa-cli copied to clipboard
[Snyk] Security upgrade ora from 3.4.0 to 6.0.0
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
768/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-ANSIREGEX-1583908 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: ora
The new version differs by 50 commits.- 8364664 6.0.0
- ede1a54 Require Node.js 12.20 and move to ESM
- 9c01990 Improve `ora.promise()` (#181)
- d51c971 Improve performance of the `.clear()` method (#182)
- 476935f 5.4.1
- 7577836 Meta tweaks
- 659f839 Don't allow `default` as a spinner (#175)
- c7d6dba 5.4.0
- c884e0d Improve detection for terminals supporting Unicode
- 498c40a Rename `master` branch to `main`
- 29d9fcf 5.3.0
- af52bbd Use nice spinner on VSCode's terminal and Windows Terminal (#167)
- 705a473 5.2.0
- 98d3529 Update dev dependencies
- 56de27f Use `bl` package instead of `mute-stream` (#163)
- 37a149f Move to GitHub Actions
- 8ac502b Avoid using `Array#reduce` (#158)
- 5be19fc Add Kia to the related packages (#157)
- 6d19ac2 5.1.0
- 1bd812a Add `isSilent` option (#155)
- 561bc85 Allow setting `prefixText` dynamically (#154)
- 3dc7379 5.0.0
- 87010c5 Require Node.js 10
- ffcf7e3 4.0.5
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report