DeviaVir / zenbot

Zenbot is a command-line cryptocurrency trading bot using Node.js and MongoDB.
MIT License
8.21k stars 2.04k forks source link

[Snyk] Upgrade snyk from 1.518.0 to 1.622.0 #2698

Closed snyk-bot closed 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade snyk from 1.518.0 to 1.622.0.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NORMALIZEURL-1296539
446/1000
Why? Recently disclosed, CVSS 7.5
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: snyk
  • 1.622.0 - 2021-06-04

    1.622.0 (2021-06-04)

    Features

    • add CodePipeline integration to allow list (ef2de3c)
    • protect analytics (346a6be)
    • re-introduce snyk code feature flags (a5d7def)
  • 1.621.0 - 2021-06-02

    1.621.0 (2021-06-02)

    Features

    • use latest @ snyk/fix with child_process package (d44681a)
  • 1.620.0 - 2021-06-01

    1.620.0 (2021-06-01)

    Features

    • use latest pipfile fix package (9bc0207)
  • 1.619.0 - 2021-06-01

    1.619.0 (2021-06-01)

    Features

    • handle new monitor response from registry (f3511b5)
  • 1.618.0 - 2021-05-28

    1.618.0 (2021-05-28)

    Bug Fixes

    • snyk code performance improvement (2e52ba9)
  • 1.617.0 - 2021-05-28

    1.617.0 (2021-05-28)

    Bug Fixes

    • Skip empty files on IaC scanning (0fd970f)
  • 1.616.0 - 2021-05-27

    1.616.0 (2021-05-27)

    Features

    • add support for resolutions in yarn2 (d2a23e0)
  • 1.615.0 - 2021-05-27

    1.615.0 (2021-05-27)

    Bug Fixes

    • Update IaC help docs with CloudFormation (e5070a0)
  • 1.614.0 - 2021-05-27

    1.614.0 (2021-05-27)

    Bug Fixes

    • code test json output should not print stack trace (f1b665c)
  • 1.613.0 - 2021-05-26

    1.613.0 (2021-05-26)

    Bug Fixes

    • Analytics show correct number of issues found by cloudformationconfig. (cd03695)
  • 1.612.0 - 2021-05-26
  • 1.611.0 - 2021-05-26
  • 1.610.0 - 2021-05-26
  • 1.609.0 - 2021-05-26
  • 1.608.0 - 2021-05-25
  • 1.607.0 - 2021-05-25
  • 1.606.0 - 2021-05-23
  • 1.605.0 - 2021-05-20
  • 1.604.0 - 2021-05-19
  • 1.603.0 - 2021-05-19
  • 1.602.0 - 2021-05-18
  • 1.601.0 - 2021-05-18
  • 1.600.0 - 2021-05-18
  • 1.599.0 - 2021-05-18
  • 1.598.0 - 2021-05-18
  • 1.597.0 - 2021-05-18
  • 1.596.0 - 2021-05-17
  • 1.595.0 - 2021-05-13
  • 1.594.0 - 2021-05-12
  • 1.593.0 - 2021-05-12
  • 1.592.0 - 2021-05-11
  • 1.591.0 - 2021-05-11
  • 1.590.0 - 2021-05-10
  • 1.589.0 - 2021-05-10
  • 1.588.0 - 2021-05-10
  • 1.587.0 - 2021-05-09
  • 1.586.0 - 2021-05-07
  • 1.585.0 - 2021-05-07
  • 1.584.0 - 2021-05-06
  • 1.583.0 - 2021-05-05
  • 1.582.0 - 2021-05-04
  • 1.581.0 - 2021-05-04
  • 1.580.0 - 2021-05-04
  • 1.579.0 - 2021-05-04
  • 1.578.0 - 2021-05-04
  • 1.577.0 - 2021-05-04
  • 1.576.0 - 2021-05-03
  • 1.575.0 - 2021-05-02
  • 1.574.0 - 2021-04-30
  • 1.573.0 - 2021-04-29
  • 1.572.0 - 2021-04-29
  • 1.571.0 - 2021-04-28
  • 1.570.0 - 2021-04-27
  • 1.569.0 - 2021-04-27
  • 1.568.0 - 2021-04-27
  • 1.567.0 - 2021-04-27
  • 1.566.0 - 2021-04-26
  • 1.565.0 - 2021-04-26
  • 1.564.0 - 2021-04-25
  • 1.563.0 - 2021-04-20
  • 1.562.0 - 2021-04-20
  • 1.561.0 - 2021-04-20
  • 1.560.0 - 2021-04-20
  • 1.559.0 - 2021-04-20
  • 1.558.0 - 2021-04-20
  • 1.557.0 - 2021-04-19
  • 1.556.0 - 2021-04-19
  • 1.555.0 - 2021-04-19
  • 1.554.0 - 2021-04-19
  • 1.553.0 - 2021-04-19
  • 1.552.0 - 2021-04-19
  • 1.551.0 - 2021-04-18
  • 1.550.0 - 2021-04-16
  • 1.549.0 - 2021-04-16
  • 1.548.0 - 2021-04-16
  • 1.547.0 - 2021-04-16
  • 1.546.0 - 2021-04-16
  • 1.545.0 - 2021-04-16
  • 1.544.0 - 2021-04-16
  • 1.543.0 - 2021-04-15
  • 1.542.0 - 2021-04-15
  • 1.541.0 - 2021-04-14
  • 1.540.0 - 2021-04-14
  • 1.539.0 - 2021-04-14
  • 1.538.0 - 2021-04-13
  • 1.537.0 - 2021-04-13
  • 1.536.0 - 2021-04-13
  • 1.535.0 - 2021-04-13
  • 1.534.0 - 2021-04-13
  • 1.533.0 - 2021-04-13
  • 1.532.0 - 2021-04-12
  • 1.531.0 - 2021-04-12
  • 1.530.0 - 2021-04-09
  • 1.529.0 - 2021-04-08
  • 1.528.0 - 2021-04-07
  • 1.527.0 - 2021-04-07
  • 1.526.0 - 2021-04-06
  • 1.525.0 - 2021-04-06
  • 1.524.0 - 2021-04-06
  • 1.523.0 - 2021-04-06
  • 1.522.0 - 2021-04-04
  • 1.521.0 - 2021-04-01
  • 1.520.0 - 2021-03-31
  • 1.519.0 - 2021-03-31
  • 1.518.0 - 2021-03-30
from snyk GitHub release notes
Commit messages
Package name: snyk
  • f1c1b24 Merge pull request #2002 from snyk/chore/improve-npm-detection
  • 8088b55 chore: don't enforce npm version when unknown
  • 6ab09c0 chore: improve npm version detection
  • 4a6b268 Merge pull request #1996 from snyk/feat/re-introduce-snyk-code-ff
  • e41a3ad Merge pull request #1998 from snyk/add-codepipeline-integration
  • efc3a2a Merge pull request #1989 from snyk/feat/protect-analytics
  • 346a6be feat: protect analytics
  • ef2de3c feat: add CodePipeline integration to allow list
  • 3bddce8 refactor: create postJson for easier POSTs
  • 5533531 Merge pull request #1997 from snyk/test/jest-missing-node-modules
  • 43698d7 Merge pull request #1995 from snyk/test/jest-migrate-alert
  • 87fd43c test: migrate missing-node-modules test to jest
  • 9ad7f49 Merge pull request #1960 from snyk/chore/enforce-npm-7
  • f5a73e2 Merge pull request #1973 from snyk/chore/check-engines-in-tests
  • a5d7def feat: re-introduce snyk code feature flags
  • 4b0139b test: migrate alerts tests to jest
  • 2ad30ad refactor: extract getApiBaseUrl to module for re-use
  • 0f91de0 test: apply prettier formatting
  • 444a69f Merge pull request #1977 from snyk/chore/remove-tslint
  • 3eaade9 Merge pull request #1986 from snyk/feat/bump-snyk-fix
  • 4cdf3aa Merge pull request #1982 from snyk/chore/fix-tap-test-warning-in-danger-js
  • d44681a feat: use latest @ snyk/fix with child_process package
  • adba5f1 chore: type credit field on Vulenrabilities
  • 2f12a2f Merge pull request #1985 from snyk/feat/use-latest-pipfile-pkg
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs