KazanExpress / frontend-commitlint

A shared commit message linter for frontend projects at KazanExpress
4 stars 0 forks source link

[Snyk] Security upgrade @commitlint/cli from 8.1.0 to 9.0.0 #14

Open alikhil opened 7 months ago

alikhil commented 7 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Missing Release of Resource after Effective Lifetime
[SNYK-JS-INFLIGHT-6095116](https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @commitlint/cli The new version differs by 182 commits.
  • 71f0194 v9.0.0
  • 5bb6907 docs(readme): add install husky example (#1699)
  • 0f0f95a chore: update dependency typescript to v3.8.2 (#1002)
  • 890df29 chore: update dependency @ types/node to v12.12.28 (#1001)
  • 6c9ab78 chore: update dependency @ types/jest to v25.1.3 (#1000)
  • 882e292 chore: update dependency ts-jest to v25.2.1 (#999)
  • c3eb1a7 fix: ignore empty commit messages #615 (#676)
  • 8b394c9 feat(config-conventional): footer/body-max-line (#436)
  • 4443062 feat: add async promise based rules methods into lint (#976)
  • 89168b8 chore: update typescript-eslint monorepo to v2.20.0 (#998)
  • 9d14792 chore: update dependency husky to v4.2.3 (#996)
  • 4ee307a fix: update dependency semver to v7.1.3 (#995)
  • c7cfe37 chore: remove unused configs (#991)
  • 0404c7d chore: update dependency @ types/node to v12.12.27 (#994)
  • 34c11b8 fix: incorrect use of when in getForcedCaseFn (#993)
  • 6f80f70 chore: align required globby between packages (#992)
  • f379dcc refactor: replace lodash/omit with spread (#988)
  • d5c601f test: add missing test cases for ensure and is-ignored (#987)
  • ec4af58 docs: update node version support (#986)
  • f74e036 chore: upgrade execa to 3.4.0 (#984)
  • c49a57c feat: passdown argv to lint command (#891)
  • 01c451c test(config-lerna-scopes): add regression tests (#979)
  • 21a91e7 test: eslint setup (#981)
  • f88f00d fix(config-lerna-scopes): correct lerna in peerDependencies (#980)
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/alikhil/project/ffbd5a41-0fe1-46c5-a191-b434027cc973?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/alikhil/project/ffbd5a41-0fe1-46c5-a191-b434027cc973?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"eb458ef2-a0e8-4c11-b21c-775d67dbe013","prPublicId":"eb458ef2-a0e8-4c11-b21c-775d67dbe013","dependencies":[{"name":"@commitlint/cli","from":"8.1.0","to":"9.0.0"}],"packageManager":"npm","projectPublicId":"ffbd5a41-0fe1-46c5-a191-b434027cc973","projectUrl":"https://app.snyk.io/org/alikhil/project/ffbd5a41-0fe1-46c5-a191-b434027cc973?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-INFLIGHT-6095116"],"upgrade":["SNYK-JS-INFLIGHT-6095116"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[661],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc=fix-pr)