SimenB / stylint

Improve your Stylus code with Stylint
https://simenb.github.io/stylint/
GNU General Public License v2.0
348 stars 62 forks source link

[Snyk] Security upgrade stampit from 1.2.0 to 2.0.1 #472

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-MOUT-1014544
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: stampit The new version differs by 111 commits.
  • 51f4d5f 2.0.1
  • 8e298be Merge pull request #98 from ericelliott/fix-prepublish
  • f551ca6 [Fixes #97] Run the build before running tests.
  • 406afa4 Merge pull request #96 from ericelliott/stamp-function-accept-refs
  • 7036c87 Typos in the updated test comments.
  • 8c3004c Typos in the README.md
  • df181eb Detailed unit test error messages.
  • 1e883ab Little precaution code.
  • 95efa87 Fix typos and readability. Remove debug leftovers.
  • 6a47f5e Misplaced comment.
  • 0b91484 Remove old code leftovers.
  • 36698a0 Reflect that stamp factory functions always accepts refs as the first argument.
  • 8dabdef JSDoc improvements for stamps.
  • 30acfa3 Make stamp factory to accept refs not props. Make the props safely merged into the refs when possible.
  • 0bfa98e Update README.md
  • e508c8e Merge pull request #92 from unstoppablecarl/master
  • d8329b7 init tests
  • 27bf661 Move misplaced comments, - the leftovers from `static` feature implementation.
  • 7a3a118 Document (JSDoc) the static stuff of stampit and factories.
  • 8b232dc Merge pull request #89 from troutowicz/conflicts
  • 08cf083 Fix silly merge conflicts
  • 9b19ead Resolve 2.0 merge conflicts.
  • f21ea73 Merge pull request #83 from ericelliott/README_v2_0
  • cd74356 Merge pull request #84 from ericelliott/options-API
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic