Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #69

Closed
wants to merge 1 commit into from

Conversation

rdenarie
Copy link
Member

@rdenarie rdenarie commented Feb 2, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 761/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.8
Information Exposure
SNYK-JS-SIMPLEGET-2361683
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @truffle/contract The new version differs by 250 commits.
  • d30ce8f Publish
  • 6885f47 Merge pull request #5253 from trufflesuite/further-test-work
  • 26279d3 Merge pull request #5255 from trufflesuite/more-test-consolidation
  • 57e0414 Merge pull request #5252 from trufflesuite/test-work
  • cfa5a93 add one trivial test to fixture
  • 3ed1b1e remove happy path tests and move contents to simple integration tests for compile and test
  • 3680f30 remove unnecessary manual call to delete temp files
  • 80b5fc3 remove some redundant tests
  • 89f2574 consolidate before steps in test
  • 9cd85b4 simplify genesis time scenario tests
  • 55c1b9c simplify some scenario tests
  • ca217db fully get rid of Reporter helper in scenario tests
  • fc50b8d update some scenario tests
  • e485acc Merge pull request #5245 from trufflesuite/fix-url-to-console
  • 043934b Refactor console tests
  • 7fa2a48 Merge pull request #5239 from trufflesuite/simplify-cs
  • d9da056 Add removeCallback function again
  • d6a237f Get rid of reporter from the tests
  • eeb9f00 Add more tests to cover all the cases
  • 9e150c8 Refactor console-child.js to remove hardcoded develop network settings
  • e458ae1 Fix bug in truffle console command
  • c86f72b simplify default export for contract-sources
  • 7f6e741 Merge pull request #5250 from trufflesuite/gethy2
  • b5ffb31 pin geth to v1.10.19

See the full diff

Package name: truffle The new version differs by 250 commits.
  • 4900bd4 Publish
  • 8a8e8ae Merge pull request #4998 from trufflesuite/fix-unbox-event-output
  • 7ee5dec Merge pull request #4995 from bytecurl/develop
  • 1d9ce6d events: fix bad unbox spinner success text
  • 2eff5e1 box: only fire unbox:failed once on failure
  • 8dbe24b Merge pull request #4997 from trufflesuite/fix-debug-spinner-crash
  • 0f160d1 core: fix debugger -x crash due to missing spinner
  • 0d46890 Merge pull request #4996 from trufflesuite/no-comment
  • 34834d0 Remove commented-out code
  • e434385 Merge pull request #4989 from trufflesuite/hygrometer
  • db0c1d4 Update name that I missed
  • f58a914 Merge pull request #4986 from trufflesuite/torch-cpr
  • 013b1c6 Merge pull request #4994 from trufflesuite/bump-more
  • bfc40f1 Rename ReadErrorStorageDeliberate to StorageNotSuppliedError
  • d49afa1 add ^ to @ truffle/error specifications in package.jsons
  • 0a79446 Merge pull request Update license header for Meeds #2 from bytecurl/add-recycle-bin
  • 6602bc7 Add $RECYCLE.BIN
  • cd8d228 Merge pull request Fake PR #1 from bytecurl/add-thumbs-db
  • 08bae8c Add Thumbs.db
  • 33063db Upgrade dependency: @ truffle/error@0.1.0
  • 0b8f7be Merge pull request #4904 from aymen94/develop
  • 1bad6f1 init variable
  • b416a67 make overwrite=true the default for copy util
  • 9dc357f Add test of ?-detecting function

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@boubaker boubaker closed this Aug 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants