Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #94

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

skmezanul
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • build/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: asar The new version differs by 21 commits.

See the full diff

Package name: babel-eslint The new version differs by 43 commits.

See the full diff

Package name: github-releases The new version differs by 3 commits.
  • fc3b492 Fix error happend when converting CoffeeScript
  • dbfb940 Convert CoffeeScript to JS
  • 0ce3644 Update dependencies

See the full diff

Package name: grunt-babel The new version differs by 4 commits.

See the full diff

Package name: grunt-electron-installer The new version differs by 20 commits.

See the full diff

Package name: npm The new version differs by 250 commits.
  • 0ec3f66 3.10.4
  • 66b5c43 update AUTHORS
  • f99bfa7 doc: update changelog for 3.10.4
  • ee5bfb3 test: fix Windows path issue for local shrinkwrap test
  • 346bba1 install: Resolve local deps in shrinkwrap relative to top
  • afa2133 install: Refactor shrinkwrap specifier lookup into shared function
  • 2820b56 inflate-shrinkwrap: Refactor into separate functions
  • 4a67fdb install: Load shrinkwrap before arg metadata
  • a11a7b2 install: Resolve local args relative to cwd
  • c6942a7 doc: Fix typos in CHANGELOG.md
  • e63d913 doc: Fix old reference to `doc/install` in comment
  • 099d23c doc: correct link to `npm-tag` from tag docs
  • 900a5b7 [email protected]
  • 69267f4 test: Added tests to verify correct-mkdir race patch
  • e5f50ea test: Added tests to verify addLocal race patch
  • 2a37c97 cache: ignore enoent on chownr while adding packages to cache
  • ea018b9 utils: Fix a Windows corner case with correct-mkdir
  • 703ca3a cache: Fixed Windows issue with addLocal
  • dd2b5e8 doc: tweak issue template
  • 8a5b926 ci: speed up Travis
  • c843908 doc: tweak formatting for issue template
  • aa977a8 doc: tweak issue template
  • 82b1b6e create issue template
  • 8c64640 3.10.3

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Reset size of letters list panel
2 participants