Glavin001 / atom-beautify

:mega: Help Wanted - Looking for Maintainer: https://github.com/Glavin001/atom-beautify/issues/2572 | :lipstick: Universal beautification package for Atom editor (:warning: Currently migrating to https://github.com/Unibeautify/ and have very limited bandwidth for Atom-Beautify Issues. Thank you for your patience and understanding :heart: )
http://unibeautify.com/
MIT License
1.5k stars 453 forks source link

[Snyk] Security upgrade csscomb from 4.2.0 to 4.3.0 #2634

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: csscomb The new version differs by 17 commits.
  • 5c69a07 v4.3.0
  • 842e9f9 Fix sort-order-fallback keep order
  • db0946f Perform npm audit fix
  • 08afce5 Update package-lock
  • d7f40ee Fix line-between broking when file start with comment
  • 38cd55e Fix sort-order test
  • 565a16f Update versions of dependencies
  • 3e029fc Fix ast.remove is not a function error
  • 55d58f4 Duplicate #576 without dependencies
  • 15a5459 Update list of support Node versions
  • db14fce Update GPE version
  • 19b9799 [cli] TTY-option type set to boolean
  • adcfc01 Ignore leading combinators
  • 269e854 Merge pull request #531 from romanlex/patch-1
  • 9b31811 Merge pull request #541 from Yurickh/fix-contributing-guide-markdown
  • a8e3be8 Fix CONTRIBUTING.md markdown
  • a60cb60 Update core.js
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)