Haulmont / jmix-frontend

Monorepo for Jmix Frontend Tools and Libraries
https://www.jmix.io
Apache License 2.0
17 stars 10 forks source link

[Snyk] Security upgrade jscodeshift from 0.13.0 to 0.14.0 #1070

Open cuba-frontend opened 4 months ago

cuba-frontend commented 4 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - packages/jmix-front-generator/package.json - packages/jmix-front-generator/package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (\*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | **768/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5 | Uncontrolled resource consumption
[SNYK-JS-BRACES-6838727](https://snyk.io/vuln/SNYK-JS-BRACES-6838727) | No | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Inefficient Regular Expression Complexity
[SNYK-JS-MICROMATCH-6838728](https://snyk.io/vuln/SNYK-JS-MICROMATCH-6838728) | No | No Known Exploit (\*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: jscodeshift The new version differs by 48 commits.
  • dbb56de 0.14.0
  • 8d0bf44 Removing evcodeshift references
  • cc9e3d3 Allow the j shortcut in testUtils
  • 514f8c3 add childNodesOFType to JSX traversalMethods (#415)
  • adef04b Removing dependency on args being in alphabetical order. (#507)
  • af38d01 Merge pull request #386 from anshckr/update_example_codemods
  • a045800 Merge branch 'main' into update_example_codemods
  • 2a97ca5 Update README.md
  • 561efa7 Merge pull request #504 from facebook/bablyon-renames
  • 5f78598 Add renameTo filters for Babel 6+ node types
  • bc2db1a Merge pull request #503 from facebook/ElonVolo-VSCode-Debugging-README
  • 04c35d4 Adding VSCode debugging setup
  • 9bc2dcd Updating generated docs and README instructions for running doc server
  • 3734917 Merge pull request #499 from facebook/dependabot/npm_and_yarn/ansi-regex-3.0.1
  • a602c5b Merge pull request #498 from facebook/dependabot/npm_and_yarn/acorn-6.4.2
  • 38bddb7 Merge pull request #496 from facebook/dependabot/npm_and_yarn/browserslist-4.20.2
  • 8a0eb94 Merge pull request #495 from facebook/dependabot/npm_and_yarn/minimist-1.2.6
  • 005de15 Merge pull request #483 from facebook/dependabot/npm_and_yarn/ajv-6.12.6
  • ee2abb2 Bump ajv from 6.6.1 to 6.12.6
  • affe237 Bump browserslist from 4.16.4 to 4.20.2
  • 65f60b6 Bump ansi-regex from 3.0.0 to 3.0.1
  • 46569ba Bump acorn from 6.3.0 to 6.4.2
  • be4a67a Merge pull request #497 from trivikr/bump-jest-26
  • d8150c8 fix: do worker import in each test
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: 🧐 [View latest project report](https://app.snyk.io/org/cuba-frontend/project/bc83caed-b043-4b2f-9283-c911d7a8c04d?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/cuba-frontend/project/bc83caed-b043-4b2f-9283-c911d7a8c04d?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"jscodeshift","from":"0.13.0","to":"0.14.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-BRACES-6838727","priority_score":768,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled resource consumption"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-MICROMATCH-6838728","priority_score":661,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Inefficient Regular Expression Complexity"}],"prId":"a1c17963-934f-480e-b353-de6af8b12ae1","prPublicId":"a1c17963-934f-480e-b353-de6af8b12ae1","packageManager":"npm","priorityScoreList":[768,661],"projectPublicId":"bc83caed-b043-4b2f-9283-c911d7a8c04d","projectUrl":"https://app.snyk.io/org/cuba-frontend/project/bc83caed-b043-4b2f-9283-c911d7a8c04d?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","priorityScore"],"type":"auto","upgrade":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"vulns":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}' --- **Note:** _This is a default PR template raised by Snyk. Find out more about how you can customise Snyk PRs in our [documentation.](https://docs.snyk.io/scan-using-snyk/snyk-open-source/automatic-and-manual-prs-with-snyk-open-source/customize-pr-templates-closed-beta)_ **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Uncontrolled resource consumption](https://learn.snyk.io/lesson/redos/?loc=fix-pr)