Watemlifts / hydrogen

:atom: Run code interactively, inspect data, and plot. All the power of Jupyter kernels, inside your favorite text editor.
https://nteract.gitbooks.io/hydrogen/
MIT License
1 stars 0 forks source link

[Snyk] Security upgrade @jupyterlab/services from 3.2.1 to 6.0.0 #23

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Open Redirect
SNYK-JS-URLPARSE-1533425
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @jupyterlab/services The new version differs by 250 commits.
  • bdee06a bump version
  • 8c97d20 New version
  • 12e22df Update milestone git commit range
  • 36e0512 Merge pull request #9505 from jasongrout/linkcheck
  • 14cf824 Fix another broken link
  • 2fc3c9c Add back in the changelog link checks
  • 146ffe2 Fix broken link
  • 136d2ec Merge pull request #9252 from jasongrout/extdevdocs
  • e76cf90 Prime link cache by ignoring changelog
  • e2a7951 Cache requests when doing the linkcheck ci test.
  • 6b245e5 Merge pull request #9503 from jasongrout/jlabserver
  • 86d336c Fix typo
  • 3fdb311 Update jupyterlab_server dependency to 2.0 final release.
  • 85f84ee Mention property inspector moved to right sidebar.
  • 1d07008 Delete duplicate docs.
  • 0378597 Fix JLab docs to point to new generated typedoc docs.
  • 4d0d373 Add typedoc module names in ensure-package script.
  • 64fbeaa Add blank line after copyright
  • 717266d Fix typo
  • a45b789 Edit user-level documentation to consistently use source and prebuilt terms.
  • 642a906 Change user-facing terminology from federated to prebuilt.
  • 04c32ef More editing about prebuilt workflow
  • c0316e3 Delete outdated information on packaging extensions
  • ecda1b7 Continuing editing about css files and prebuilt extensions.
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic