KayvanMazaheri / pillo

:pill: Simple medication reminder for an oblivious friend.
http://pillo.ir
MIT License
18 stars 6 forks source link

[Snyk] Fix for 2 vulnerabilities #54

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-AJV-584908
Yes No Known Exploit
medium severity Prototype Pollution
SNYK-JS-I18NEXT-585930
Yes Proof of Concept
Commit messages
Package name: i18next The new version differs by 250 commits.
  • 8c63160 19.6.0
  • 2a6d7e7 changelog
  • 26d5719 introduce new option skipOnVariables to fix #1479 (#1483)
  • 44c2e76 fix prototype pollution (#1482)
  • 8a3b93b 19.5.6
  • 1b32fc1 fix local usage of nsSeparator option
  • c9be7ad 19.5.5
  • 41431ba changelog
  • 360c8a9 fix nesting recursion #1479 (#1480)
  • 2108da8 additional interpolation with nesting test case
  • 457768b 19.5.4
  • 93f17d9 changelog
  • 9be2ed6 fix type declarion of exposed EventEmitter#off methods (#1460)
  • c883ddb fix: getDataByLanguage typings & test (#1472)
  • 4bfa7a3 19.5.3
  • 39b09ed changelog
  • e3ad1ad fix: Macedonian plural formula - *11 (11, 111, 211, 311, 58711...) is plural (#1476)
  • 72c5009 19.5.2
  • 6dc82bb changelog
  • 1b78398 fix nesting interpolation with prepended namespace, fixes #1474 (#1475)
  • 67e2569 19.5.1
  • 0e1ba26 rebuild
  • 80a3810 Merge pull request #1471 from i18next/fix-getBestMatchFromCodes
  • ba5c120 getBestMatchFromCodes: use fallbackLng if nothing found, fixes #1470
See the full diff
Package name: less The new version differs by 127 commits.
  • b873737 Merge pull request #3177 from Kartoffelsalat/master
  • bd2a93f chore(package): update request to 2.83.0
  • 3699921 Merge pull request #3170 from thorn0/patch-1
  • 6985541 Having `inline` and `less` imports of the same name lead to a race condition
  • 2f1386f Merge pull request #3168 from matthew-dean/master
  • 4272871 Fixes #3116 - lessc not loading plugins in 3.0
  • ba5ad9c Point badges at master branch
  • 4962988 Update CHANGELOG.md
  • 12fe0c6 Update README.md
  • 45d06b9 Merge pull request #3163 from matthew-dean/master
  • 9590b7b Add dist files
  • 0b6536b Merge branch '3.x'
  • a48c24c calc() fix - fixes #974 (partially #1880)
  • 367b46a Merge pull request #3161 from matthew-dean/3.x
  • 4508495 Remove legacy upgrade
  • 2a4a63a Update CHANGELOG.md with 3.x list
  • bb6da28 Update README.md
  • f80a021 Merge pull request #3159 from matthew-dean/3.x
  • 8b4524f Bump to 3.0.0-RC.1
  • d30e3a6 Merge pull request #3150 from anthony-redFox/3.x
  • 0b7c81c Removed install npm 2 version for appveyor. It was hotfix for old node version.
  • 5d230dd Drop node 0.10 and 0.12 and added node 9 matrix testing
  • 385da8f Update stale.yml
  • d384779 Create stale.yml
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic