Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade winreg from 1.2.2 to 1.2.5 #37

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

m-heyda
Copy link
Owner

@m-heyda m-heyda commented Sep 24, 2024

snyk-top-banner

Snyk has created this PR to upgrade winreg from 1.2.2 to 1.2.5.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 3 versions ahead of your current version.

  • The recommended version was released on a year ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Directory Traversal
SNYK-JS-MOMENT-2440688
589 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
589 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASHMERGEWITH-174136
589 Proof of Concept
high severity Code Injection
SNYK-JS-LODASH-1040724
589 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-450202
589 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-567746
589 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-608086
589 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-6139239
589 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-73638
589 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
589 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
589 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
589 Proof of Concept
Release notes
Package name: winreg
  • 1.2.5 - 2023-10-20
    • fixes a possible security issue if an attacker is able to pollute Object.prototype (thanks to Mikhail Shcherbakov KTH Royal Institute of Technology for reporting)
    • adds support for electron apps
    • updates the development dependencies
    • updates the mocha tests
  • 1.2.4 - 2017-05-12

    1.2.4

  • 1.2.3 - 2017-01-21
    • unfreezed all prototypes and instances which adds stubbing support
  • 1.2.2 - 2016-08-28

    increment version to 1.2.2

from winreg GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Description by Korbit AI

What change is being made?

Upgrade the winreg package from version 1.2.2 to 1.2.5 in both package.json and package-lock.json.

Why are these changes being made?

The upgrade addresses potential security vulnerabilities and ensures compatibility with other dependencies. This update is part of regular maintenance to keep the project dependencies up-to-date and secure.

Is this description stale? Ask me to generate a new description by commenting /korbit-generate-pr-description

Snyk has created this PR to upgrade winreg from 1.2.2 to 1.2.5.

See this package in npm:
winreg

See this project in Snyk:
https://app.snyk.io/org/insanepl/project/fc5df254-de83-46d6-8b60-eedab0d543ab?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

korbit-ai bot commented Sep 24, 2024

You've used up your 5 PR reviews for this month under the Korbit Starter Plan. You'll get 5 more reviews on October 9th, 2024 or you can upgrade to Pro for unlimited PR reviews and enhanced features in your Korbit Console.

Copy link

@korbit-ai korbit-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have reviewed your code and did not find any issues 🎉

Please note that I can make mistakes, and you should still encourage your team to review your code as well.

Need a new review? Comment /korbit-review on this PR and I'll review your latest changes.

Korbit Guide: Usage and Customization

Interacting with Korbit

  • You can manually ask Korbit to review your PR using the /korbit-review command in a comment at the root of your PR.
  • You can ask Korbit to generate a new PR description using the /korbit-generate-pr-description command in any comment on your PR
  • Chat with Korbit on issues we post by tagging @korbit-ai in your reply.
  • Help train Korbit to improve your reviews by giving a 👍 or 👎 on the comments Korbit posts.

Customizing Korbit

  • Check out our docs on how you can make Korbit work best for you and your team.
  • Customize Korbit for your organization through the Korbit Console.

Current Korbit Configuration

General Settings
Setting Value
Review Schedule Automatic excluding drafts
Max Issue Count 10
Automatic PR Descriptions
Issue Categories
Category Enabled
Naming
Database Operations
Documentation
Logging
Error Handling
Systems and Environment
Objects and Data Structures
Tests
Readability and Maintainability
Asynchronous Processing
Design Patterns
Third-Party Libraries
Performance
Security
Functionality

Feedback and Support

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants