akonwi / git-plus

vim-fugitive like package for atom. make commits and other git things without the terminal
MIT License
537 stars 163 forks source link

[Snyk] Security upgrade underscore-plus from 1.6.6 to 1.7.0 #808

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 883/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 9.8
Arbitrary Code Execution
SNYK-JS-UNDERSCORE-1080984
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: underscore-plus The new version differs by 19 commits.
  • f34bd44 1.7.0
  • ac0a8a8 Merge pull request #20 from atom/upgrade-underscore
  • af8a026 ⬆️ underscore@1.9.1
  • 65e2a43 Merge pull request #15 from t9md/patch-1
  • 57a3f19 1.6.8
  • 735b4f0 Restore escaping of dashes in regexes
  • ad6b0f4 1.6.7
  • 70e8062 Ignore package-lock file
  • 7264365 Merge pull request #19 from atom/mb-fix-escape-regex-with-uncode-flag
  • ab5b5b4 Update generated JS file
  • 1997556 Use node 8 on travis
  • bc58e29 Don't put backslashes before dashes in escapeRegExp
  • 4a022cf Update appveyor.yml
  • 8d69dd1 Remove redundant atom install step
  • 5bc964e :arrow_up: underscore
  • 3536749 Switch appveyor from apm to npm
  • 006fd0d Enable Windows builds on AppVeyor
  • 7a1a24e Remove invalid homepage field
  • a0f33b9 canceling adviseBefore need returning false
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic