WoTTsecurity / api

API and Dashboard
https://dash.wott.io
MIT License
0 stars 2 forks source link

[Snyk] Security upgrade jquery-validation from 1.19.1 to 1.19.3 #878

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-JQUERYVALIDATION-1056868
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: jquery-validation The new version differs by 13 commits.
  • 45b9e28 Release:1.19.3
  • 5d8f29e Core: fixed Regular Expression Denial of Service vulnerability (#2371)
  • b8d6646 Localization: Add "pattern" translation for French (#2363)
  • b9c793c docs: Fix simple typo, atteched -> attached (#2345)
  • 8319330 Update messages_tr.js (#2343)
  • b0e3b11 Add Accessibility section to Readme (#2149)
  • 79bed39 Core: Replaced deprecated jQuery functions
  • af445b3 chore: added more release tasks
  • cd1ce52 Build: Updating the master version to 1.19.3-pre.
  • d3748a2 Core: Fixes deprecated calls to jQuery trim (#2328)
  • 25a0f14 Create FUNDING.yml
  • 5426dcb chore: updated build docs (#2288)
  • 05e35ea Build: Updating the master version to 1.19.2-pre.
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: šŸ§ View latest project report

šŸ›  Adjust project settings

šŸ“š Read more about Snyk's upgrade and patch logic