Loghorn / ant-plus

A node module for ANT+
MIT License
138 stars 67 forks source link

[Snyk] Security upgrade usb from 1.6.0 to 1.8.0 #46

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 833/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.8
Information Exposure
SNYK-JS-SIMPLEGET-2361683
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: usb The new version differs by 79 commits.
  • b8b3a6a v1.8.0
  • a0da058 Introduce prebuildify (#450)
  • a6db778 Use libusb with sleep crash fix (#451)
  • 354287f Merge pull request #445 from mildsunrise/patch-2
  • 4179e43 Merge pull request #447 from tessel/libusb-move
  • 3d94f4b Update libusb submodule URL
  • 84dcb72 fix invalid initial refs
  • e336b03 v1.7.1
  • 6353add Merge pull request #440 from danielmain/master
  • cafde3c destruction of hotplugThis when unsubscribing
  • c882d34 Bump version
  • 986ebef Merge pull request #422 from joelpurra/update-test-instructions
  • c6e93b8 Merge pull request #421 from joelpurra/ignore-compiled-test-file
  • d217ea5 Update test instructions
  • 6206001 Ignore compiled test file
  • 4202670 Merge pull request #428 from tessel/thegecko-patch-1
  • 0907f19 Update node version
  • ca9d35a v1.7.1
  • a6b83fb Bumped lodash dependency
  • c00ed65 Merge pull request #419 from joelpurra/fix-build-warnings
  • 728c257 Merge pull request #359 from penx/patch-1
  • c3d4d1d Merge pull request #420 from joelpurra/update-repository-reference
  • 5f8e3fc v1.7.1-alpha.1
  • c43d4c8 Merge pull request #424 from tessel/prebuild-ubuntu-18.04
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic