This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade nanoid from 3.1.25 to 3.3.4.
![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=npm&package_name=nanoid&from_version=3.1.25&to_version=3.3.4&pr_id=90e830e1-4016-46e7-bc6d-02e8d2953f83&visibility=true&has_feature_flag=false)
As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.
:sparkles: Snyk has automatically assigned this pull request, [set who gets assigned](https://app.snyk.io/org/aporia/project/e325e2e0-2f76-484e-9926-f5229e0dd505/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr/settings/integration).
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **13 versions** ahead of your current version.
- The recommended version was released **a month ago**, on 2022-05-03.
The recommended version fixes:
Severity | Issue | PriorityScore (*) | Exploit Maturity |
:-------------------------:|:-------------------------|-------------------------|:-------------------------
| Information Exposure [SNYK-JS-NANOID-2332193](https://snyk.io/vuln/SNYK-JS-NANOID-2332193) | **521/1000** **Why?** Proof of Concept exploit, Has a fix available, CVSS 4 | Proof of Concept
(*) Note that the real score may have changed since the PR was raised.
Release notes Package name: nanoid
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade nanoid from 3.1.25 to 3.3.4.
![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=npm&package_name=nanoid&from_version=3.1.25&to_version=3.3.4&pr_id=90e830e1-4016-46e7-bc6d-02e8d2953f83&visibility=true&has_feature_flag=false) As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user. :sparkles: Snyk has automatically assigned this pull request, [set who gets assigned](https://app.snyk.io/org/aporia/project/e325e2e0-2f76-484e-9926-f5229e0dd505/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr/settings/integration). :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.- The recommended version is **13 versions** ahead of your current version. - The recommended version was released **a month ago**, on 2022-05-03. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Information Exposure
[SNYK-JS-NANOID-2332193](https://snyk.io/vuln/SNYK-JS-NANOID-2332193) | **521/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 4 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: nanoid
3.3.4
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
π§ View latest project report
π©βπ» Set who automatically gets assigned
π Adjust upgrade PR settings
π Ignore this dependency or unsubscribe from future upgrade PRs