Skip to content

Conversation

leonardoadame
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging. 

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
No Proof of Concept
low severity 506/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @npmcli/run-script The new version differs by 15 commits.
  • fcebe38 chore: release 7.0.2
  • 30623cf deps: bump node-gyp from 9.4.1 to 10.0.0
  • 54e5bd0 chore: postinstall for dependabot template-oss PR
  • 7d95e9f chore: bump @ npmcli/template-oss from 4.18.1 to 4.19.0
  • 90bcf54 chore: postinstall for dependabot template-oss PR
  • ba0ab48 chore: bump @ npmcli/template-oss from 4.18.0 to 4.18.1
  • 43ccfc7 chore: release 7.0.1
  • f61fd84 deps: bump @ npmcli/promise-spawn from 6.0.2 to 7.0.0
  • 87b740b chore: release 7.0.0
  • e1b1a3c fix: drop node14 support
  • a8045a9 deps: bump which from 3.0.1 to 4.0.0
  • c4f4fb4 chore: postinstall for dependabot template-oss PR
  • dacd67e chore: bump @ npmcli/template-oss from 4.17.0 to 4.18.0
  • 9d2d807 chore: postinstall for dependabot template-oss PR
  • 8b21725 chore: bump @ npmcli/template-oss from 4.15.1 to 4.17.0

See the full diff

Package name: @npmcli/template-oss The new version differs by 58 commits.

See the full diff

Package name: libnpmversion The new version differs by 250 commits.

See the full diff

Package name: node-gyp The new version differs by 40 commits.

See the full diff

Package name: pacote The new version differs by 29 commits.

See the full diff

Package name: tap The new version differs by 250 commits.
  • 793c1c0 update versions
  • 47a2289 add missing @ tapjs/mock service key polyfill
  • 6622dca snapshot: update snapshot
  • 556e520 mock: actually be resilient against multiple instances
  • 2c135b0 Add `t.mockAll` method
  • d7e7e4f clean process.cwd() out of snapshots by default
  • 4c0dc72 use the released version of tshy
  • c858f37 need to check in .tshy configs for typedoc to work
  • 82f48cd update versions
  • 0f27f73 TypeScript 5.2, use tshy for hybrid builds
  • de09096 remove my home directory from parser snapshots
  • 46e2bbb repl: mkdirp the .tap dir if missing
  • acfae01 link typedocs to main website
  • 2ece1da core spawn test even less flaky
  • a7a12d2 update typedoc to latest, ts-node to temporary fork
  • a5c0e0c some changelog updates
  • caf8d81 document repl
  • a5dc854 Store t.testdir() fixtures in .tap/fixtures
  • 6914d23 remove docs from source control
  • 1dcc6a7 exclude test files themselves from coverage
  • aff25fc update versions
  • c5972e7 core: make spawn timeout test less flaky
  • 1c11b37 stack: properly parse ErrnoException errors
  • 1280a55 parser: remove node v12 skip check

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

Copy link

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

Copy link

vercel bot commented Dec 2, 2023

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
cli-1leonardoadame ❌ Failed (Inspect) Dec 2, 2023 5:57pm
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants