DemocracyOS / democracyos

Democracia en Red is focusing on specific implementations of DemocracyOS. We are working now working with governments and activists all over Latin America. If you are interested in our online participation tools you can check them out on our site.
https://democraciaos.org/en/
GNU General Public License v3.0
1.77k stars 616 forks source link

[Snyk] Security upgrade merge from 1.2.1 to 2.1.1 #1677

Open gvilarino opened 3 years ago

gvilarino commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 758/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-MERGE-1042987
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: merge The new version differs by 27 commits.
  • 56ca75b build: v2.1.1
  • 7b0ddc2 fix: prototype pollution
  • 8686d85 build: bump version
  • 80151be build
  • 0acaaf3 build: update dev dependencies
  • f571887 Merge pull request #38 from 418sec/master
  • 869927f Merge pull request #1 from alromh87/master
  • c2f8454 Fix Prototype Pollution
  • bf8b1ff build: include typings
  • ece8885 Merge pull request #32 from yeikos/develop
  • 43ffa43 build: include only needed files
  • 7bf0fc8 fix: export default function (typings)
  • 159e724 build: bump version
  • 21f4105 fix: default typings
  • 36d4b9c build: new npm scripts
  • eabfd6f build: CommonJS support
  • bf85170 test: add merge script
  • 75ba781 build: add editor config
  • 2d2b54a build: update ignored files
  • b36036a docs: remove license copyright
  • 1385593 build: update main script and description
  • 2b22e6b docs: update readme
  • 7cc6574 build: package-lock.json
  • 29e46a8 build: ts and webpack config
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic