Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #68

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

ryan-ally
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: metalsmith The new version differs by 196 commits.
  • ba18d85 Release 2.6.0
  • d5ce2c8 Prepare changelog for 2.6.0
  • baee1de Removes stray cross-spawn dependency & use --no-package-lock for CI
  • 17e421b test: migrate from nyc to c8 for coverage reports
  • 2ef473b types: fix source code link line numbers
  • e12537f feat/add v0.12.8 announcement post nodejs/nodejs.org#379 - use lodash.clonedeepwith instead, document watch type, fix issues in CLI
  • 9d40674 Resolves add v0.12.8 announcement post nodejs/nodejs.org#379: add metalsmith.watch option setter and watcher
  • 48a0167 fix: package.json node version, type docs, readme formatting
  • 3a93270 test: fix FS race condition in #build should return a promise only when callback omitted
  • dbfe32a docs: Updates readme examples to ESM & Gitter link to Matrix Element
  • 4469020 CLI: Fix ESM dynamic import issue with absolute paths on Windows
  • 58217a5 Adds CLI support & tests for loading ESM configs or Metalsmith instances
  • c272b8b ci: remove Node 12, add Node 20
  • 0810728 Updates commander from 8.3.0 -> 10.0.1
  • ae05945 Removes rimraf dependency, refactors helpers using fs/promises and upgrades @ types/node
  • 80d8508 Drops support for Node < 14
  • 3754a6a chore: Remove stray console.error log in bin
  • acb363e Trims whitespace from parsed front-matter excerpt and adds test for dynamic front-matter lang
  • 2bfe800 Fix: don't keep gray-matter excerpt at the start of file contents
  • 7ec31d0 Adds a matter member object to metalsmith instance with stringify & parse methods
  • 424e6ec Support 'module.exports = Metalsmith()'-style configs in CLI
  • 82969ef dev: update devDependencies & fix security warnings
  • 58db90c ci: remove obsolete Gitter notification flow
  • 58d22a3 Resolves Be consistent with quotes in examples. nodejs/nodejs.org#356: adds Typescript support to Metalsmith package

See the full diff

Package name: standard The new version differs by 82 commits.
  • fa0c1e4 update authors
  • 81de719 16.0.0
  • 9f94f98 prep changelog for 16.0.0
  • f5b298a standard-engine@14
  • 9f73bf2 eslint-config-standard-jsx@10
  • 0ce671d eslint-config-standard@16
  • dfea036 changelog
  • c167c0a disable failing repos for 'no-var' rule
  • 24ddf3f changelog
  • 258ee48 disable no-var rule for cmd since it needs to run on all node versions
  • 59dc70e remove eslint-plugin-standard
  • 7c7dbec changelog
  • 6fbe538 test: fix logs
  • e5e0b37 test: disable failing repos
  • a98eba7 test: re-enable disabled repos which now pass!
  • 0bfd793 test: disable non-existent repo
  • 6f9f2f1 test: add script to detect non-existent repos
  • 0d429d0 test: remove non-existant repo
  • 0b64eb3 test: add --write option to save changes to "disable" prop
  • 8b97b72 test: add test packages into same repo
  • e1b0466 changelog
  • 692c0fe changelog
  • c30a584 remove mkdirp dependency
  • d1f9de1 remove broken eslint-index package

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants