adamkeinan / Metro-Desktop

React Webpack Babel full stack Metro multi-app environment
MIT License
2 stars 0 forks source link

[Snyk] Security upgrade babel-jest from 24.9.0 to 25.1.0 #130

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

⚠️ Warning ``` Failed to update the package-lock.json, please update manually before merging. ```

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: babel-jest The new version differs by 209 commits.
  • 170eee1 fix: expose vm context directly from test envs (#9428)
  • e818dca feat: add support for .mjs config (#9431)
  • 8236779 Fix: Prevent maintaining RegExp state between multiple tests (#9289)
  • f19adb1 chore: bump babel (#9427)
  • 2ece4f9 Do not highlight matched asymmetricMatcher in diffs (#9257)
  • 2839036 chore: sort entries in changelog
  • 7ee717d Fix pretty-format to respect displayName on forwardRef. (#9422)
  • abaea37 Normalize --findRelatedTests paths on win32 platforms (#8961)
  • c8c4c4e jest-snapshot: Fix regression in diff for jest-snapshot-seriali… (#9419)
  • 17f6c83 jest-reporters: Use global coverage thresholds as high watermarks (#9416)
  • 72040d9 Avoid clashes with other globals in type declaration (#9415)
  • 5e5db14 Images of snapshot colors for Jest 25 blog (#9410)
  • a31fc41 jest-core: optimize collecting collectCoverageFrom (#9399)
  • 7f69176 chore: bump deps (#9394)
  • 5236155 chore: fix supporter fetching script on node 8
  • 282f400 chore: fetch open collective supporters via gql api (#9377)
  • 8c20a8d chore: deploy website when website deploy script changes (#9375)
  • 4425a1f fix(website): make sure to fetch supporters when deploying the website
  • 5014025 chore: bump @ types/micromatch to ^4.0.0 (#9369)
  • 9419034 Resolve dynamic dependencies correctly when a mapping exists (#9303)
  • a2fcda6 docs: Use `Object.defineProperty()` for stubbing global propert… (#9288)
  • acb9c09 chore: fix examples dependencies (#9344)
  • bc86f50 Add helpful link to custom transformer in the 'transform' confi… (#9309)
  • 75843e3 chore: refresh lockfile (#9338)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic