Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #26

Open
wants to merge 1 commit into
base: winter-16
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: browser-sync The new version differs by 119 commits.
  • 24206ca 2.12.1
  • 5f9423c fix(cli): add shebang
  • e1babca 2.12.0
  • 10c7720 deps: bump lodash, yargs, micromatch, chokidar
  • 308b76c bump brower-sync-ui to inherit fixes for #802 #931
  • 6c95765 tests: plugins: add tests for incorrectly configured plugins
  • 8113649 [wip] - adding support for plugin errors
  • f0ac65f fix(proxy): fail when second port scanner (when proxy.ws=true) throws
  • c85195d chore: remove redundant 'bs.app' check
  • decb092 tests: ensure second call to getPorts (when proxy.ws=true) can handle an error correctly
  • 7a1e42e tests: add initial rewriteRule to ensure the filtering works as expected
  • 7acc3fa cleanup: remove redundant isArray check from each series
  • f09a3ed tests: add tests for init with null/undefined
  • 94d4414 test(plugins): Add test for plugins that cannot be located
  • ce6a293 logger: remove unused methods
  • 0a63c8f ci: allow builds on older nodes
  • 5a0665d tests: Add tests for proxy rewrites
  • 2e8ea4d Update README.md
  • 11a5825 Merge branch 'feature/backport-proxy'
  • 8572f06 feat(middleware): accept route/handler in plain objects
  • 55749b0 Simplify cli input
  • 36ae237 cli: Move handler functions outside try/catch of yargs
  • b3198fd yarf
  • 2853d47 fix(plugin-resolve): Also use process.cwd() as base for node_modules resolution

See the full diff

Package name: gulp-lintspaces The new version differs by 15 commits.

See the full diff

Package name: gulp-util The new version differs by 13 commits.

See the full diff

Package name: imagemin-cli The new version differs by 8 commits.

See the full diff

Package name: imagemin-pngquant The new version differs by 14 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant