ansble / monument-cli

The CLI for monument projects
http://monument.ansble.com
2 stars 5 forks source link

[Snyk] Security upgrade prompt from 1.0.0 to 1.2.0 #183

Open designfrontier opened 9 months ago

designfrontier commented 9 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **703/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.2 | Missing Release of Resource after Effective Lifetime
[SNYK-JS-INFLIGHT-6095116](https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116) | No | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: prompt The new version differs by 33 commits.
  • fbf6dac 1.2.0
  • fef3933 Move off abandoned utile dependency #213
  • 33febea add eslint
  • c071b85 Merge pull request #198 from caub/1.1
  • 88c403e 1.1.0
  • 756fa65 Fix inconsistent options.noHandleSIGINT for windows
  • 8d5495c Merge pull request #196 from caub/promisify
  • 33ddf56 prompt.get promise: add test, update readme
  • b92a9a9 promisify prompt.get
  • 0ff93b6 Merge pull request #184 from dsych/windows-sigint
  • 9e80863 triggering sigint on windows
  • 1c95d1d Merge pull request #171 from blahah/master
  • 65ac6e2 Merge pull request #172 from Shank09/Shank09-package.json
  • d03edd0 Added missing keywords in package.json
  • df42a26 Respect falsy overrides (fixes #151)
  • b732102 Merge pull request #169 from jordanyaker/master
  • 6ebf54a Removed the pkginfo dependency. Updated the required version of winston.
  • 7d1a28f Removed the pkginfo dependency.
  • d550674 Merge pull request #163 from Eagerod/fixer/add-properties
  • 9b5f65b Added a test addProperties() with no parameters.
  • fb83773 Fixed an issue where the first parameter in a callback would not be the
  • e7b5449 Merge pull request #121 from rubbingalcoholic/master
  • e493cb8 Merge pull request #153 from devrelm/devrelm.function-defaults
  • 3046431 Merge pull request #156 from littleguga/master
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/designfrontier/project/4f2d43f1-89e8-4412-8b3e-d6ea2a76438f?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/designfrontier/project/4f2d43f1-89e8-4412-8b3e-d6ea2a76438f?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"62ddb192-11a6-4399-8c58-305deedcb36f","prPublicId":"62ddb192-11a6-4399-8c58-305deedcb36f","dependencies":[{"name":"prompt","from":"1.0.0","to":"1.2.0"}],"packageManager":"npm","projectPublicId":"4f2d43f1-89e8-4412-8b3e-d6ea2a76438f","projectUrl":"https://app.snyk.io/org/designfrontier/project/4f2d43f1-89e8-4412-8b3e-d6ea2a76438f?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-INFLIGHT-6095116"],"upgrade":["SNYK-JS-INFLIGHT-6095116"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[703],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc=fix-pr)