Skip to content

Conversation

@twilio-product-security

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Uncaught Exception
SNYK-JS-YAML-5458867
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: husky The new version differs by 50 commits.

See the full diff

Package name: lint-staged The new version differs by 25 commits.
  • 04529e2 perf: replace `cosmiconfig` with `lilconfig` (#981)
  • f861d8d fix: unbreak windows by correctly normalizing cwd (#1029)
  • 11c004e fix: remove dangling chars from git dir (#1028)
  • f291824 fix: detect git repo root correctly on cygwin (#1026)
  • 32c08d3 feat(deps): update and slim down dependencies (#1003)
  • 3885af8 docs: Use /usr/bin/env sh instead of direct path (#1020)
  • 0ef25e8 docs: simplify Ignoring Files From .eslintignore. (#1013)
  • ad4316c docs: fix incorrect folding (#1006)
  • b3d97cf fix: try to automatically fix and warn about invalid brace patterns (#992)
  • f8807d7 docs: simplify configuration example for formatting any format Prettier supports (#997)
  • f7302f4 fix: the shell option value should be optional instead of required (#996)
  • fea8033 feat: allow a path to be supplied to the --shell option (#994)
  • 7734156 fix: do not swallow already detected deprecated usage by last task (#991)
  • 4f9a146 docs: Hardcode mrm@2 in the documentation (#976)
  • e5e186d ci: remove Node.js 10 from Appveyor test matrix
  • 852aa6e feat: bump Node.js version requirement to 12.13.0
  • db861ce ci: replace Node.js 15 with 16
  • f8a0261 fix: migrate commander@7
  • 5560d97 fix: migrate husky@6
  • ab7a211 chore(deps): update dependencies
  • 6808f06 docs: corrects minor typos and grammar in README (#964)
  • 101ad5e docs: update installation and examples (#960)
  • d1207d2 Use simple-git-hooks in examples (#955)
  • feb663b docs: husky to simple-git-hooks migration in mrm (#954)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-YAML-5458867
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants