KayvanMazaheri / pillo

:pill: Simple medication reminder for an oblivious friend.
http://pillo.ir
MIT License
18 stars 6 forks source link

[Snyk] Fix for 1 vulnerabilities #59

Open KayvanMazaheri opened 3 years ago

KayvanMazaheri commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: nodemon The new version differs by 190 commits.
  • 9a67f36 feat: update chokidar to v3
  • 6781b40 docs: add license file
  • 0e6ba3c fix: wait for all subprocesses to terminate (fixes issue #1476)
  • b58cf7d chore: Merge branch 'master'
  • 95a4c09 docs: add to faq
  • 3a2eaf7 choe: merge master
  • 3d90879 chore: add logo to site
  • 7d6c1a8 fix: Replace `jade` references by `pug`
  • 74c8749 chore: test funding.yml change
  • c1a8b75 chore: update funding
  • d5b9891 test: ensure ignore relative paths
  • eead311 fix: to avoid confusion like in #1528, always report used extension
  • 12b66cd fix: langauge around "watching" (#1591)
  • 2e6e2c4 docs: README Grammar (#1601)
  • 5124ae9 Merge branch 'master' of github.com:remy/nodemon
  • 95fa05a chore: git card
  • d84f421 chore: adding funding file
  • 13afac2 fix: ensure signal is sent to exit event
  • d088cb6 chore: update stalebot
  • 20ccb62 feat: add message event
  • 886527f fix: disable fork only if string starts with dash
  • 64b474e feat: add TypeScript to default execPath (#1552)
  • 2973afb fix: Quote zero-length strings in arguments (#1551)
  • aa41ab2 fix: hard bump of chokidar@2.1.5
See the full diff
Package name: pm2 The new version differs by 250 commits.
  • e24fc12 pm2@4.0.0
  • 4c55d83 fix: test dependency
  • 8f954d0 pm2@4.0.0
  • ecfcf5d Merge pull request #4436 from niftylettuce/master
  • ff5d3be feat: added Lad to framework list
  • 4e933d2 pm2@4.0.0-beta-9
  • 869b1d3 chore: drop ADVANCED_README.md
  • 2c7765d Merge pull request #4391 from ykolbin/migrate-pm2-cli
  • 5b2f15f fix: adapt new pm2 register flow
  • 7d6ffef chore: upgrade pm2/io and chokidar
  • 01b2949 pm2@4.0.0-beta-8
  • daca87c Merge pull request #4377 from RiaanWest/fix/lodash-version
  • 474ac37 Merge pull request #4392 from mib008/patch/issue_4378
  • 76dfc07 fix: add property 'type' for compatible with old version.
  • 886c5c5 fix: remove garbage whitespace.
  • 5676974 refactor: Simplify bin/pm2 and move content to lib/binaries/CLI.js
  • f59911e fix: update lodash version
  • 21af03f chore: update README
  • 6bbee22 chore: change link
  • e44ac95 chore: upgrade logo
  • 9389dfe chore: upgrade systeminformation
  • 0c79406 Update package.json
  • cf20f15 chore: upgrade async to 3.1
  • 359c8c2 docs: update info links
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: šŸ§ View latest project report

šŸ›  Adjust project settings

šŸ“š Read more about Snyk's upgrade and patch logic