DemocracyOS / democracyos

Democracia en Red is focusing on specific implementations of DemocracyOS. We are working now working with governments and activists all over Latin America. If you are interested in our online participation tools you can check them out on our site.
https://democraciaos.org/en/
GNU General Public License v3.0
1.77k stars 616 forks source link

[Snyk] Fix for 1 vulnerabilities #1675

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 758/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-Y18N-1021887
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: transliteration The new version differs by 174 commits.
  • c9d7285 bump version
  • 51b06ba Merge branch 'master' of https://github.com/dzcpy/transliteration
  • ec3cbe7 - Fix #229 data issue
  • 5e990ed fix typo in slugify lowercase description
  • 3654e96 chore(deps): update dependency rollup-plugin-babel to v5.0.0-alpha.2
  • 08ce30a fix:
  • 1219955 fix: fix #223
  • 0ed71a5 upgrade dependencies
  • e85eb78 Update dependency @types/yargs to v15.0.3
  • 21bfb58 Update dependency codecov to v3.6.5 [SECURITY]
  • 222d723 Update dependency typescript to v3.8.2
  • c300007 Update dependency rollup to v1.31.0
  • 0a80c1c Update dependency codecov to v3.6.4
  • 22bbf24 Update dependency rollup to v1.30.1
  • 0867f42 Update dependency @types/yargs to v15.0.2
  • 44bdd70 Update dependency rimraf to v3.0.1
  • 04cd64f Update babel monorepo to v7.8.4
  • 66529fc Update dependency codecov to v3.6.2
  • 855fbc3 Update dependency @types/yargs to v15.0.1
  • 9e66344 Update dependency rollup to v1.29.1
  • ccd7ab1 Update package.json
  • 2ef5a30 Update dependency @types/yargs to v15
  • 19484d6 Update dependency typescript to v3.7.5
  • d437bce Update dependency @types/yargs to v13.0.5
See the full diff
Package name: yargs The new version differs by 250 commits.
  • 1ffb927 chore: v16.0.0 release
  • 5e5e5d0 chore: release 16.0.0 (#1698)
  • b215fba feat: adds strictOptions() (#1738)
  • c7debe8 feat(helpers): rebase, Parser, applyExtends now blessed helpers (#1733)
  • c71783a feat: i18n for ESM and Deno (#1735)
  • d360577 build: use release-please action (#1736)
  • 4151fee feat: tweaks to API surface based on user feedback (#1726)
  • 60234a4 deps(typescript): upgrade to typescript@4.x (#1728)
  • bad6f76 docs: use URL to images, for benefit of Deno (#1727)
  • b1f647b chore: add back yargs logo
  • ac6d5d1 feat: adds support for ESM and Deno (#1708)
  • 0f81024 fix(yargs): add missing command(module) signature (#1707)
  • a552990 feat(usage)!: single char aliases first in help (#1574)
  • f5997e8 refactor(ts): move to TypeScript release of yargs-parser (#1696)
  • c06f886 refactor(ts)!: ship yargs.d.ts (#1671)
  • 56a589f chore(deps): update dependency @types/mocha to v8 (#1689)
  • df283d3 chore(deps): update dependency mocha to v8 (#1674)
  • 863937f feat!: drop support for EOL Node 8 (#1686)
  • 028b50d chore: release 15.4.0 (#1635)
  • 225ab82 feat: support array of examples (#1682)
  • e68334b refactor(ts): move and tsify most of root yargs.js to lib/yargs (#1670)
  • cb7fbb8 chore: remove old entries from `files` field in `package.json (#1677)
  • 34949f8 Revert "chore(deps): update dependency eslint to v7 (#1656)" (#1673)
  • 18c2efd docs(api): clarify process.argv handling and the order of API methods (#1644)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic