arrowheadapps / strapi-connector-firestore

Strapi database connector for Firestore database on Google Cloud Platform.
MIT License
166 stars 15 forks source link

[Snyk] Security upgrade lodash from 4.17.20 to 4.17.21 #50

Closed brettwillis closed 3 years ago

brettwillis commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
No Proof of Concept
high severity 753/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.2
Command Injection
SNYK-JS-LODASH-1040724
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: lodash The new version differs by 1 commits.
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

github-actions[bot] commented 3 years ago

Test results

Test suite flatten_all flatten_mixed_src flatten_mixed_target flatten_none
Total 121 / 1480) 33 / 580) 33 / 580) 121 / 1480)
codecov[bot] commented 3 years ago

Codecov Report

Merging #50 (c380510) into master (1fd2203) will not change coverage. The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master      #50   +/-   ##
=======================================
  Coverage   74.69%   74.69%           
=======================================
  Files          27       27           
  Lines        1861     1861           
  Branches      540      540           
=======================================
  Hits         1390     1390           
  Misses        471      471           

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update 1fd2203...fadda58. Read the comment docs.