Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade documentation from 14.0.1 to 14.0.3 #890

Merged
merged 1 commit into from
Oct 23, 2024

Conversation

lholmquist
Copy link
Member

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 498/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 2.1
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VUETEMPLATECOMPILER-8219888
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: documentation The new version differs by 26 commits.
  • 8aae14b chore(release): 14.0.3
  • 9c42abb build(deps): bump actions/setup-node from 3.6.0 to 3.8.0 (#1614)
  • d4559be build(deps-dev): bump mock-fs from 5.1.4 to 5.2.0 (#1601)
  • e030a3f Sort memberof (#1452)
  • 930edd2 Update USAGE.md (#1463)
  • 1cc2f98 fix: fix GFM markdown output (#1553)
  • 4600c97 Remove broken David badge on README (#1611)
  • 12cfa02 Update NODE_API.md (#1616)
  • de30e89 Update membership.js (#1620)
  • 8fcbeae Fix a few typos on CHANGELOG (#1610)
  • f8fd216 chore(release): 14.0.2
  • 9b3d82a Add node 20 to ci
  • 49ce1e0 build(deps-dev): bump husky from 8.0.1 to 8.0.3 (#1587)
  • 16adbd9 build(deps): bump pify from 6.0.0 to 6.1.0 (#1579)
  • 3ddeedd build(deps): bump actions/setup-node from 3.5.1 to 3.6.0 (#1585)
  • def9713 build(deps): bump vfile from 5.3.4 to 5.3.7 (#1592)
  • 3bc4024 build(deps-dev): bump prettier from 2.7.1 to 2.8.8 (#1598)
  • 798fa10 fix(exported): respect `parse-extension` & `require-extension` (#1484)
  • 4fec3f4 Added Another Use full example with Screenshot (#1557)
  • 8f00576 build(deps): bump ini from 3.0.0 to 3.0.1 (#1551)
  • 73913f1 build(deps): bump unist-util-visit from 4.1.0 to 4.1.1 (#1550)
  • ba29602 build(deps): bump actions/setup-node from 3.4.1 to 3.5.1 (#1566)
  • 608611c build(deps): bump vue-template-compiler from 2.7.8 to 2.7.14 (#1576)
  • 3f5164d build(deps): bump @ babel/generator from 7.18.12 to 7.20.5 (#1577)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

@coveralls
Copy link

Pull Request Test Coverage Report for Build 11473883120

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 98.328%

Totals Coverage Status
Change from base Build 11331355812: 0.0%
Covered Lines: 374
Relevant Lines: 375

💛 - Coveralls

@lholmquist lholmquist merged commit 6cd2895 into main Oct 23, 2024
15 checks passed
@lholmquist lholmquist deleted the snyk-fix-138f2ab8604538e47304d5ee3f1c7de3 branch October 23, 2024 14:15
This was referenced Oct 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants