adobe / create-aio-lib

CLI tool to create Adobe I/O Libs (npm init @adobe/aio-lib)
Apache License 2.0
2 stars 5 forks source link

[Snyk] Security upgrade isomorphic-git from 1.7.8 to 1.8.2 #30

Closed snyk-bot closed 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 741/1000
Why? Recently disclosed, Has a fix available, CVSS 9.1
Directory Traversal
SNYK-JS-ISOMORPHICGIT-1535213
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: isomorphic-git The new version differs by 7 commits.
  • 1316820 fix(checkout): throw error on malicious filepaths (#1339)
  • 89c0da7 fix(merge): Cannot set property 'oid' of undefined (#1312)
  • b102e1d fix(website): try it out (#1290)
  • 03846e1 fix(react-native): fix for "<Intermediate Value>.stream is not a function" errors in React Native (#1156)
  • 153679f chore: fix broken link in README.md (#1154)
  • baf668b fix(merge): "Cannot read property 'Symbol(PackfileCache)' of undefined" error (#1289)
  • 26f761e feat: Added 'cache' parameter; an opt-in solution to performance regressions caused by #1217 (#1255)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic