AutolabJS / autolabcli

Command line client for AutolabJS
https://autolabjs.github.io
GNU General Public License v3.0
10 stars 10 forks source link

[Snyk] Security upgrade caporal from 0.9.0 to 1.0.0 #139

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: caporal The new version differs by 21 commits.
  • ae5d2c3 Merge branch 'master' of github.com:mattallty/Caporal.js
  • 9577743 fix: Fix vulnerabilities (#125)
  • e4f9dc7 chore(release): 1.0.0
  • 57b2f9b chore(release): 1.0.0
  • ca3d237 docs(CHANGELOG): 1.0.0
  • e949a4e chore: migrate to cli-table3 (#115)
  • bf25c33 feat: Implicit boolean option (#109)
  • d712dd8 fix: A few fixes and improvements (#104)
  • 801f667 fix: fix it.only(...) causing the #118 issue test case to run alone (#124)
  • d2fc842 perf: swap chalk for colorette (#117)
  • fba6d4a docs: Update npm install line (#90)
  • 0a9558f Fix error label when only short name option is provided (#122)
  • 4950a75 fix: exit with status code 1 when command does not exist (#106)
  • cb06bd0 chore(release): 0.10.0
  • b4fa874 docs(CHANGELOG): 0.10.0
  • f35a1f5 fix: Fix #91 typescript types
  • e4c07a8 fix: Display thrown error message when validation fails (#98)
  • 0d621d0 fix($cli): Multi-help sections support (#82)
  • 3be93c5 fix: Make usage display name if available (#97)
  • a900fc0 fix: Small typo/regex issues
  • 3c96cae Replace --no-colors in README (#88)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic