Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 556/1000
Why? Recently disclosed, Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-JS-PRISMJS-2404333
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: prismjs The new version differs by 22 commits.
  • 703881e 1.27.0
  • 7ac1373 Updated changelog for v1.27.0 (#3342)
  • e002e78 Command Line: Escape markup in command line output (#3341)
  • 13b56a9 Bump follow-redirects from 1.14.7 to 1.14.8 (#3338)
  • f094c4a Bump yargs-parser from 5.0.0 to 5.0.1 (#3334)
  • 9fd4c74 Bump ajv from 6.10.0 to 6.12.6 (#3333)
  • 3fcca6b Bump pathval from 1.1.0 to 1.1.1 (#3331)
  • 1784b17 Command Line: Add support for line continuation and improved colors (#3326)
  • f545843 ESLint: Allow `Map` and `Set` in ES5 code (#3328)
  • d6c5372 PureBasic: Added missing keyword and fixed constants ending with `$` (#3320)
  • 82d0ca1 Command Line: Added span around command and output (#3312)
  • 2cc4660 Core: Added better error message for missing grammars (#3311)
  • 3f8cc5a Added UO Razor Script (#3309)
  • bcb2e2c AutoIt: Allow hyphen in directive (#3308)
  • deb3a97 INI: Swap out `header` for `section` (#3304)
  • e46501b editorconfig: Change alias of `section` from `keyword` to `selector` (#3305)
  • 2eb89e1 Swap out `operator` for `punctuation` (#3306)
  • 3a20bdc Bump node-fetch from 2.6.1 to 3.1.1 (#3307)
  • 081d515 Bump copy-props from 2.0.4 to 2.0.5 (#3300)
  • b90e97c Bump follow-redirects from 1.13.1 to 1.14.7 (#3299)
  • 8458c41 MongoDB: Added v5 support (#3297)
  • 441a142 Scala: Added support for interpolated strings (#3293)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@previ previ closed this Jul 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants