Capgemini / mesos-ui

An alternative web UI for Apache Mesos, built with :heart: and React.JS
http://capgemini.github.io/devops/mesos-ui
MIT License
220 stars 48 forks source link

[Snyk] Security upgrade node-zookeeper-client from 0.2.2 to 1.1.1 #127

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 596/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.5
Arbitrary Code Injection
SNYK-JS-UNDERSCORE-1080984
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: node-zookeeper-client The new version differs by 14 commits.
  • 50d7295 Upgrade dependencies (#116)
  • 3ffbed8 Bump underscore from 1.4.4 to 1.12.1 (#111)
  • 0a7cb95 Release 1.1.0 and update outdated dependencies (#96)
  • 0208a2e Add removeAll and getAllChildren (#88)
  • 4f2edaf Fix #92, use safer Buffer allocation method (#93)
  • e4e91dc 0.2.3
  • 16d958d Bump up the version to 0.2.3
  • a33a83e Remove support for Node 4
  • 44c1312 Fixes #64: webpack doesn't like SPECIFICATION_FILE constant
  • 290e468 Fix examples link
  • b462db5 Merge pull request #43 from lightswitch05/feature/improve-coverage
  • 9eeb2e7 Merge pull request #41 from lightswitch05/feature/use-eslint
  • 70f2b9f Improve code coverage.
  • 2794529 Replaced JSLint with ESLint.
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic