Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: chai, chai-http, cross-env, js-yaml, eslint, eslint-config-airbnb-base, eslint-plugin-promise, helmet, husky, lint-staged, mocha, nodemon, nyc, prettier, prettier-eslint, swagger-tools, uuid #154

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

WontonSam
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

Name Versions Released on

chai
from 4.5.0 to 5.1.1 | 9 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 4 months ago
on 2024-05-09
chai-http
from 4.4.0 to 5.0.0 | 3 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 3 months ago
on 2024-06-07
cross-env
from 5.2.1 to 7.0.3 | 8 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 4 years ago
on 2020-12-01
js-yaml
from 3.14.1 to 4.1.0 | 2 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 3 years ago
on 2021-04-14
eslint
from 5.16.0 to 9.9.0 | 143 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-09
eslint-config-airbnb-base
from 13.2.0 to 15.0.0 | 5 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 3 years ago
on 2021-11-09
eslint-plugin-promise
from 4.3.1 to 7.1.0 | 16 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-06
helmet
from 3.23.3 to 7.1.0 | 33 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 10 months ago
on 2023-11-07
husky
from 2.7.0 to 9.1.4 | 94 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-07-29
lint-staged
from 8.2.1 to 15.2.9 | 153 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-13
mocha
from 6.2.3 to 10.7.3 | 44 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-09
nodemon
from 1.19.4 to 3.1.4 | 45 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 3 months ago
on 2024-06-20
nyc
from 14.1.1 to 17.0.0 | 9 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 3 months ago
on 2024-06-09
prettier
from 1.19.1 to 3.3.3 | 61 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
on 2024-07-13
prettier-eslint
from 9.0.2 to 16.3.0 | 19 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 8 months ago
on 2024-01-20
swagger-tools
from 0.10.1 to 0.10.4 | 3 versions ahead of your current version | 6 years ago
on 2018-07-20
uuid
from 8.3.2 to 10.0.0 | 4 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 3 months ago
on 2024-06-09

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOCHA-2863123
58 No Known Exploit
high severity Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
58 Proof of Concept
high severity Command Injection
SNYK-JS-SIMPLEGIT-2421199
58 Proof of Concept
high severity Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
SNYK-JS-SIMPLEGIT-2434306
58 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-SIMPLEGIT-3112221
58 Proof of Concept
high severity Prototype Override Protection Bypass
npm:qs:20170213
58 No Known Exploit
high severity Remote Code Execution (RCE)
SNYK-JS-SIMPLEGIT-3177391
58 Proof of Concept
high severity Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
58 No Known Exploit
high severity Prototype Override Protection Bypass
npm:qs:20170213
58 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
58 Proof of Concept
high severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
58 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-COOKIEJAR-3149984
58 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
58 Proof of Concept
medium severity Reverse Tabnabbing
SNYK-JS-ISTANBULREPORTS-2328088
58 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
58 Proof of Concept
critical severity Prototype Pollution
SNYK-JS-PROPERTYEXPR-598800
58 Proof of Concept
high severity Prototype Pollution
npm:extend:20180424
58 No Known Exploit
high severity Prototype Override Protection Bypass
npm:qs:20170213
58 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
npm:string:20170907
58 Mature
medium severity Information Exposure
npm:superagent:20181108
58 No Known Exploit
medium severity Open Redirect
SNYK-JS-GOT-2932019
58 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-YUP-2420835
58 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
58 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
58 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
58 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:ms:20170412
58 No Known Exploit
low severity Denial of Service (DoS)
npm:superagent:20170807
58 No Known Exploit
Release notes
Package name: chai from chai GitHub release notes
Package name: chai-http

Snyk has created this PR to upgrade:
  - chai from 4.5.0 to 5.1.1.
    See this package in npm: https://www.npmjs.com/package/chai
  - chai-http from 4.4.0 to 5.0.0.
    See this package in npm: https://www.npmjs.com/package/chai-http
  - cross-env from 5.2.1 to 7.0.3.
    See this package in npm: https://www.npmjs.com/package/cross-env
  - js-yaml from 3.14.1 to 4.1.0.
    See this package in npm: https://www.npmjs.com/package/js-yaml
  - eslint from 5.16.0 to 9.9.0.
    See this package in npm: https://www.npmjs.com/package/eslint
  - eslint-config-airbnb-base from 13.2.0 to 15.0.0.
    See this package in npm: https://www.npmjs.com/package/eslint-config-airbnb-base
  - eslint-plugin-promise from 4.3.1 to 7.1.0.
    See this package in npm: https://www.npmjs.com/package/eslint-plugin-promise
  - helmet from 3.23.3 to 7.1.0.
    See this package in npm: https://www.npmjs.com/package/helmet
  - husky from 2.7.0 to 9.1.4.
    See this package in npm: https://www.npmjs.com/package/husky
  - lint-staged from 8.2.1 to 15.2.9.
    See this package in npm: https://www.npmjs.com/package/lint-staged
  - mocha from 6.2.3 to 10.7.3.
    See this package in npm: https://www.npmjs.com/package/mocha
  - nodemon from 1.19.4 to 3.1.4.
    See this package in npm: https://www.npmjs.com/package/nodemon
  - nyc from 14.1.1 to 17.0.0.
    See this package in npm: https://www.npmjs.com/package/nyc
  - prettier from 1.19.1 to 3.3.3.
    See this package in npm: https://www.npmjs.com/package/prettier
  - prettier-eslint from 9.0.2 to 16.3.0.
    See this package in npm: https://www.npmjs.com/package/prettier-eslint
  - swagger-tools from 0.10.1 to 0.10.4.
    See this package in npm: https://www.npmjs.com/package/swagger-tools
  - uuid from 8.3.2 to 10.0.0.
    See this package in npm: https://www.npmjs.com/package/uuid

See this project in Snyk:
https://app.snyk.io/org/cachiman/project/a6d0b707-2cea-495d-9bdf-8e95d87ac53b?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

google-cla bot commented Sep 9, 2024

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants