Skip to content

Conversation

Bhanditz
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 579/1000
Why? Has a fix available, CVSS 7.3
Arbitrary File Overwrite
SNYK-JS-FSTREAM-174725
No No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
No Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Internal Property Tampering
SNYK-JS-TAFFYDB-2992450
Yes Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: jsdoc The new version differs by 132 commits.
  • 0842185 4.0.0
  • b018408 chore!: replace taffydb package with @ jsdoc/salty
  • dc48aa6 3.6.11
  • cccfd3d chore(deps): resolve dependency vulnerability
  • ff5963a fix(deps): rollback klaw to 3.x (#2002)
  • 2bf9f88 3.6.10
  • ffa07da remove `npm preinstall` script (#1971)
  • aab7b50 3.6.9
  • 24c1354 fix installation error when installing via npm (#1970)
  • c5ea65a 3.6.8
  • a024054 update dependencies
  • e1f1919 3.6.7
  • f7a64bd chore(deps): update selected dependencies
  • 3f5c462 3.6.6
  • 95e3192 fix: correctly track interface members
  • ef05a69 3.6.5
  • a59b5cd fix: prevent circular refs when params have the same type expression
  • 8d0fce6 chore: bump version; update release notes
  • 91c9aa7 chore(deps): update dependencies
  • ef33f07 3.6.3
  • 0e468af 3.6.2
  • d5e0eb0 Add 3.6.2 changelog.
  • 61ae11c Ensure that ES 2015 classes appear in the generated docs when they're supposed to. (#1644)
  • 03b8abd Add 3.6.1 changelog.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Server-side Request Forgery (SSRF)
🦉 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants