Skip to content

Conversation

titanism
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • example/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging. 

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
  828  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

@socket-security
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/commander@2.13.0 filesystem, shell 0 56.1 kB abetomo
npm/load-json-file@1.1.0 None 0 3.4 kB sindresorhus
npm/path-type@1.1.0 None 0 3.54 kB sindresorhus
npm/read-pkg-up@1.0.1 None 0 4.25 kB sindresorhus
npm/read-pkg@1.1.0 None 0 4.42 kB sindresorhus
npm/snapdragon-util@3.0.1 None +1 64.1 kB jonschlinkert
npm/source-list-map@2.0.1 None 0 26.4 kB sokra
npm/source-map-resolve@0.5.2 None 0 84.9 kB lydell
npm/source-map-support@0.5.9 filesystem, unsafe 0 82.2 kB linusu
npm/source-map-url@0.4.0 None 0 19.4 kB lydell
npm/spdx-correct@3.0.2 None 0 21.8 kB taleinat
npm/spdx-exceptions@2.2.0 None 0 2.57 kB kemitchell
npm/spdx-expression-parse@3.0.0 None 0 11.9 kB kemitchell
npm/spdx-license-ids@3.0.1 None 0 7.68 kB shinnn
npm/split-string@3.1.0 None 0 13.8 kB jonschlinkert
npm/sprintf-js@1.0.3 None 0 34.8 kB alexei
npm/sshpk@1.15.1 None 0 214 kB arekinath
npm/ssri@5.3.0 None 0 40.5 kB zkat
npm/stack-utils@1.0.1 None 0 13.5 kB isaacs
npm/static-extend@0.1.2 None 0 4.69 kB jonschlinkert
npm/stealthy-require@1.1.1 None 0 12.5 kB analog-nico
npm/stream-browserify@2.0.1 None 0 7.18 kB stevemao
npm/stream-each@1.2.3 None 0 6.74 kB mafintosh
npm/stream-http@2.8.3 None 0 91.3 kB jhiesey
npm/stream-shift@1.0.0 None 0 3.87 kB mafintosh
npm/string-length@2.0.0 None 0 2.97 kB sindresorhus
npm/strip-ansi@3.0.1 None 0 3.1 kB jbnicolai
npm/strip-eof@1.0.0 None 0 2.64 kB sindresorhus
npm/strip-json-comments@2.0.1 None 0 5.06 kB sindresorhus
npm/supports-color@2.0.0 None 0 3.75 kB sindresorhus
npm/symbol-observable@1.0.1 None 0 7.44 kB blesh
npm/symbol-tree@3.2.2 None 0 56.8 kB joris-van-der-wel
npm/tar@4.4.6 environment, filesystem +1 146 kB isaacs
npm/test-exclude@4.2.3 None 0 14.3 kB coreyfarrell
npm/thread-loader@1.2.0 filesystem, shell, unsafe 0 36.4 kB evilebottnawi
npm/throat@4.1.0 None 0 7.91 kB forbeslindesay
npm/through@2.3.8 None 0 12.5 kB dominictarr
npm/through2@2.0.3 None 0 16.5 kB rvagg
npm/timers-browserify@2.0.10 None 0 10.2 kB jryans
npm/tmp@0.0.33 filesystem 0 26 kB raszi
npm/tmpl@1.0.4 None 0 2.81 kB daaku
npm/to-arraybuffer@1.0.1 None 0 5.54 kB jhiesey
npm/to-object-path@0.3.0 None 0 5.07 kB jonschlinkert
npm/to-regex-range@2.1.1 None 0 20.3 kB jonschlinkert
npm/tr46@1.0.1 None +1 355 kB sebmaster
npm/trim-right@1.0.1 None 0 2.61 kB sindresorhus
npm/tslib@1.9.3 None 0 58.4 kB typescript
npm/tty-browserify@0.0.0 None 0 1.99 kB substack
npm/tunnel-agent@0.6.0 environment, network 0 16.7 kB mikeal
npm/type-check@0.3.2 None 0 20.9 kB gkz
npm/type-is@1.6.16 None 0 16.7 kB dougwilson
npm/typedarray@0.0.6 None 0 26 kB substack
npm/ua-parser-js@0.7.18 None 0 203 kB faisalman
npm/uglify-es@3.3.9 eval, filesystem 0 768 kB alexlamsl
npm/uglify-js@3.4.9 eval, filesystem 0 687 kB alexlamsl
npm/uglifyjs-webpack-plugin@1.3.0 eval Transitive: filesystem +2 877 kB evilebottnawi
npm/unicode-canonical-property-names-ecmascript@1.0.4 None 0 4.34 kB mathias
npm/unicode-match-property-ecmascript@1.0.4 None 0 4.41 kB mathias
npm/unicode-match-property-value-ecmascript@1.0.2 None 0 23.4 kB mathias
npm/unicode-property-aliases-ecmascript@1.0.4 None 0 5.21 kB mathias
npm/union-value@1.0.0 None 0 6.83 kB jonschlinkert
npm/unique-filename@1.1.1 None 0 41.4 kB iarna
npm/unique-slug@2.0.1 None 0 3.11 kB iarna
npm/unset-value@1.0.0 None 0 8.53 kB jonschlinkert
npm/upath@1.1.0 None 0 33.9 kB anodynos
npm/uri-js@4.2.2 None 0 533 kB garycourt
npm/urix@0.1.0 None 0 4.37 kB lydell
npm/url@0.11.0 None 0 76.8 kB defunctzombie
npm/use@3.1.1 None 0 9.51 kB jonschlinkert
npm/util-deprecate@1.0.2 None 0 5.48 kB tootallnate
npm/util.promisify@1.0.0 None 0 13.3 kB ljharb
npm/util@0.10.4 environment 0 18 kB goto-bus-stop
npm/utils-merge@1.0.1 None 0 3.72 kB jaredhanson
npm/validate-npm-package-license@3.0.4 None 0 16.6 kB kemitchell
npm/vary@1.1.2 None 0 8.75 kB dougwilson
npm/verror@1.10.0 None 0 35.8 kB dap
npm/vm-browserify@0.0.4 eval 0 21.5 kB substack
npm/w3c-hr-time@1.0.1 None 0 14.6 kB timothygu
npm/walker@1.0.7 filesystem 0 5.78 kB daaku
npm/watch@0.18.0 filesystem 0 24 kB mikeal
npm/watchpack@1.6.0 None 0 22.7 kB sokra
npm/webidl-conversions@4.0.2 None 0 19.3 kB domenic
npm/webpack-hot-middleware@2.24.3 None 0 31 kB glenjamin
npm/webpack-sources@1.3.0 None 0 30 kB sokra
npm/webpack@4.20.2 environment, filesystem, unsafe 0 1.31 MB sokra
npm/whatwg-fetch@3.0.0 network 0 46.5 kB mislav
npm/whatwg-mimetype@2.2.0 None 0 16.2 kB domenic
npm/whatwg-url@6.5.0 None 0 77.1 kB domenic
npm/which-module@2.0.0 None 0 4.58 kB nexdrew
npm/wide-align@1.1.3 None 0 4.55 kB iarna
npm/worker-farm@1.6.0 environment, shell 0 47.2 kB rvagg
npm/wrap-ansi@2.1.0 None 0 7.79 kB sindresorhus
npm/wrappy@1.0.2 None 0 2.96 kB zkat
npm/xml-name-validator@3.0.0 None 0 23 kB domenic
npm/xpipe@1.0.5 None 0 4.6 kB nodexo
npm/yallist@2.1.2 None 0 13.6 kB isaacs

🚮 Removed packages: npm/@babel/plugin-check-constants@7.0.0-beta.38, npm/@babel/plugin-external-helpers@7.0.0, npm/@babel/plugin-syntax-nullish-coalescing-operator@7.0.0, npm/@babel/plugin-syntax-optional-chaining@7.0.0, npm/@babel/plugin-syntax-typescript@7.0.0, npm/@babel/plugin-transform-member-expression-literals@7.0.0, npm/@babel/plugin-transform-object-assign@7.0.0, npm/@babel/plugin-transform-property-literals@7.0.0, npm/@babel/plugin-transform-react-display-name@7.0.0, npm/@babel/plugin-transform-react-jsx-source@7.0.0, npm/@babel/plugin-transform-runtime@7.1.0, npm/@babel/plugin-transform-typescript@7.1.0, npm/@babel/runtime@7.1.2, npm/absolute-path@0.0.0, npm/ansi-colors@1.1.0, npm/ansi-cyan@0.1.1, npm/ansi-gray@0.1.1, npm/ansi-red@0.1.1, npm/ansi-wrap@0.1.0, npm/ansi@0.3.1, npm/arr-diff@1.1.0, npm/arr-union@2.1.0, npm/array-filter@0.0.1, npm/array-map@0.0.0, npm/array-reduce@0.0.0, npm/array-slice@0.2.3, npm/art@0.10.3, npm/babel-helper-builder-react-jsx@6.26.0, npm/babel-helper-call-delegate@6.24.1, npm/babel-helper-define-map@6.26.0, npm/babel-helper-function-name@6.24.1, npm/babel-helper-get-function-arity@6.24.1, npm/babel-helper-hoist-variables@6.24.1, npm/babel-helper-optimise-call-expression@6.24.1, npm/babel-helper-replace-supers@6.24.1, npm/babel-plugin-check-es2015-constants@6.22.0, npm/babel-plugin-syntax-class-properties@6.13.0, npm/babel-plugin-syntax-flow@6.18.0, npm/babel-plugin-syntax-jsx@6.18.0, npm/babel-plugin-syntax-trailing-function-commas@6.22.0, npm/babel-plugin-transform-class-properties@6.24.1, npm/babel-plugin-transform-es2015-arrow-functions@6.22.0, npm/babel-plugin-transform-es2015-block-scoped-functions@6.22.0, npm/babel-plugin-transform-es2015-block-scoping@6.26.0, npm/babel-plugin-transform-es2015-classes@6.24.1, npm/babel-plugin-transform-es2015-computed-properties@6.24.1, npm/babel-plugin-transform-es2015-destructuring@6.23.0, npm/babel-plugin-transform-es2015-for-of@6.23.0, npm/babel-plugin-transform-es2015-function-name@6.24.1, npm/babel-plugin-transform-es2015-literals@6.22.0, npm/babel-plugin-transform-es2015-modules-commonjs@6.26.2, npm/babel-plugin-transform-es2015-object-super@6.24.1, npm/babel-plugin-transform-es2015-parameters@6.24.1, npm/babel-plugin-transform-es2015-shorthand-properties@6.24.1, npm/babel-plugin-transform-es2015-spread@6.22.0, npm/babel-plugin-transform-es2015-template-literals@6.22.0, npm/babel-plugin-transform-es3-member-expression-literals@6.22.0, npm/babel-plugin-transform-es3-property-literals@6.22.0, npm/babel-plugin-transform-flow-strip-types@6.22.0, npm/babel-plugin-transform-object-rest-spread@6.26.0, npm/babel-plugin-transform-react-display-name@6.25.0, npm/babel-plugin-transform-react-jsx@6.24.1, npm/babel-plugin-transform-strict-mode@6.24.1, npm/babel-preset-fbjs@2.3.0, npm/big-integer@1.6.36, npm/bplist-creator@0.0.7, npm/bplist-parser@0.1.1, npm/color-support@1.1.3, npm/commander@2.19.0, npm/compressible@2.0.15, npm/compression@1.7.3, npm/connect@3.6.6, npm/cosmiconfig@5.0.6, npm/create-react-class@15.6.3, npm/denodeify@1.2.1, npm/envinfo@5.10.0, npm/errorhandler@1.5.0, npm/event-target-shim@1.1.1, npm/eventemitter3@3.1.0, npm/extend-shallow@1.1.4, npm/fancy-log@1.3.2, npm/fbjs-css-vars@1.0.1, npm/fbjs-scripts@0.8.3, npm/fbjs@1.0.0, npm/finalhandler@1.1.0, npm/fs-extra@1.0.0, npm/gauge@1.2.7, npm/globals@11.8.0, npm/image-size@0.6.3, npm/jest-haste-map@23.5.0, npm/jsesc@2.5.1, npm/json-stable-stringify@1.0.1, npm/jsonfile@2.4.0, npm/jsonify@0.0.0, npm/kind-of@1.1.0, npm/klaw@1.3.1, npm/load-json-file@2.0.0, npm/lodash.pad@4.5.1, npm/lodash.padend@4.6.1, npm/lodash.padstart@4.6.1, npm/metro-babel-register@0.48.1, npm/metro-babel7-plugin-react-transform@0.48.1, npm/metro-cache@0.48.1, npm/metro-config@0.48.1, npm/metro-core@0.48.1, npm/metro-memory-fs@0.48.1, npm/metro-minify-uglify@0.48.1, npm/metro-resolver@0.48.1, npm/metro-source-map@0.48.1, npm/metro@0.48.1, npm/mime-types@2.1.11, npm/mime@1.6.0, npm/npmlog@2.0.4, npm/nullthrows@1.1.0, npm/opn@3.0.3, npm/options@0.0.6, npm/parse-json@4.0.0, npm/path-type@2.0.0, npm/pegjs@0.10.0, npm/pify@3.0.0, npm/plist@3.0.1, npm/plugin-error@0.1.2, npm/pretty-format@4.3.1, npm/react-clone-referenced-element@1.1.0, npm/react-deep-force-update@1.1.2, npm/react-devtools-core@3.4.0, npm/react-is@16.6.0-alpha.8af6728, npm/react-native@0.57.3, npm/react-proxy@1.1.8, npm/react-test-renderer@16.6.0-alpha.8af6728, npm/react-timer-mixin@0.13.4, npm/react-transform-hmr@1.0.4, npm/read-pkg-up@2.0.0, npm/read-pkg@2.0.0, npm/sax@1.1.6, npm/serialize-error@2.1.0, npm/simple-plist@0.2.1, npm/slide@1.1.6

View full report↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants