MailOnline / libreact

NO LONGER MAINTAINED - SEE https://github.com/streamich/libreact INSTEAD
The Unlicense
97 stars 6 forks source link

[Snyk] Security upgrade semantic-release from 15.14.0 to 17.0.1 #112

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: semantic-release The new version differs by 132 commits.
  • 45695b9 fix(package): update @ semantic-release/commit-analyzer to version 8.0.0
  • 3c7b114 fix(package): update @ semantic-release/release-notes-generator to version 9.0.0
  • f2b5826 fix(package): update @ semantic-release/npm to version 7.0.0
  • c48bd3a fix(package): update @ semantic-release/github to version 7.0.0
  • bc97537 test: fix copy/paste typo in test titles
  • c7e461d docs: add `@ saithodev/semantic-release-gitea` to community plugins
  • ef1b8a0 chore(package): update ava to version 3.1.0
  • bec57cd chore: require Node.js >=10.18
  • c6b1076 fix: correct error when remote repository has no branches
  • b54b20d fix: use `--no-verify` when testing the Git permissions
  • 88fe819 docs: fix typo
  • 559c152 docs(README): update minimal required Node version / FAQ link (#1422)
  • 31e7876 docs(travis): build on all branches by default
  • 8c0490d docs: replacing firefox plugin in the list (#1416)
  • 6b5b02e fix: fetch tags on repo cached by the CI
  • 28b5480 docs: correct plugin execution order
  • 3739ab5 fix(package): update env-ci to version 5.0.0
  • 11665b2 chore(package): update dependencies
  • 0785a84 fix: update plugin versions
  • 152bf45 Merge remote-tracking branch 'origin/beta'
  • 3ba8f2a Merge remote-tracking branch 'origin/master' into beta
  • 9772563 fix: look also for previous prerelease versions to determine the next one
  • 61665be fix: correct log when adding channel to tag
  • a8747c4 fix: verify is branch is up to date by comparing remote and local HEAD
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)