Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to upgrade eslint-plugin-import from 2.22.1 to 2.25.4.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 13 versions ahead of your current version.
  • The recommended version was released 3 months ago, on 2022-01-02.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-MINIMIST-2429795
256/1000
Why? Recently disclosed, CVSS 3.7
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: eslint-plugin-import from eslint-plugin-import GitHub release notes
Commit messages
Package name: eslint-plugin-import
  • 68cea3e Bump to v2.25.4
  • dbf668e [Dev Deps] update `safe-publish-latest`
  • ef93681 [Deps] update `eslint-module-utils`
  • de88739 utils: v2.7.2
  • 9e06eff [utils] [Refactor] inline `pkgDir` implementation; remove `pkg-dir`
  • 210e40a [utils] [patch] Fix `@ babel/eslint-parser` 8 compatibility
  • e3ca68e [Fix] `named`/`ExportMap`: handle named imports from CJS modules that use dynamic import
  • ef980d4 [Fix] `importType`: properly resolve `@/*`-aliased imports as internal
  • e156316 [Docs] `prefer-default-export`: fix typo
  • e8d79b5 [Tests] fix OSX tests
  • 3875392 [Fix] `first`: prevent crash when parsing angular templates
  • 3edcd8d [Tests] `packages`: run on multiple eslint versions
  • 8ce0936 [Deps] update `tsconfig-paths`
  • 32cae19 [Docs] `order`: Remove duplicate mention of default
  • 2c33530 [Fix] `no-default-import`: report on the token "default" instead of the entire node
  • f4d3020 [Refactor] `no-default-export`: tweak rule
  • e8794f1 [Fix] `importType`: avoid crashing on a non-string
  • 7c239fe Bump to v2.25.3
  • dfc5b54 [Fix] `no-import-module-exports`: avoid a crash in eslint < 4
  • 790d9af [Tests] skip 2020 test in eslint < 6
  • 3fbc252 [Deps] update `eslint-module-utils`, `is-core-module`
  • cdcc76a [eslint] consolidate configs
  • 332d3c8 [Fix] `no-import-module-exports`: avoid false positives with a shadowed `module` or `exports`
  • add650a [Docs] HTTP => HTTPS

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants