atom-community / atom

:atom: Community build of the hackable text editor
https://atom-community.github.io/
MIT License
721 stars 30 forks source link

[Snyk] Upgrade nock from 13.0.2 to 13.3.0 #491

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to upgrade nock from 13.0.2 to 13.3.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-LODASHSET-1320032
472/1000
Why? Proof of Concept exploit, CVSS 7.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: nock
  • 13.3.0 - 2023-01-10

    13.3.0 (2023-01-10)

    Features

  • 13.2.9 - 2022-07-19

    13.2.9 (2022-07-19)

    Bug Fixes

    • README: Add notes about Scope vs Interceptor matchHeader calls (#2382) (d9bab65)
  • 13.2.8 - 2022-06-30

    13.2.8 (2022-06-30)

    Bug Fixes

    • types: allow regexp on Definition#scope and Definition#path (#2374) (2edf341)
  • 13.2.7 - 2022-06-15

    13.2.7 (2022-06-15)

    Bug Fixes

    • InterceptedRequestRouter.handleWrite arity issue (#2371) (7f21d0c)
  • 13.2.6 - 2022-06-03

    13.2.6 (2022-06-03)

    Reverts

    • Revert "chore(deps-dev): bump got from 11.8.3 to 12.1.0" (#2366) (f46b808), closes #2366
  • 13.2.5 - 2022-06-03

    13.2.5 (2022-06-03)

    Bug Fixes

  • 13.2.4 - 2022-02-04

    13.2.4 (2022-02-04)

    Bug Fixes

    • looking up timeout on agent with no options (#2299) (1b2933d)
  • 13.2.3 - 2022-02-03

    13.2.3 (2022-02-03)

    Bug Fixes

  • 13.2.2 - 2022-01-11

    13.2.2 (2022-01-11)

    Bug Fixes

    • allowUnocked not working with regex host + request body match (#2277) (ac7b4fd)
  • 13.2.1 - 2021-11-12

    13.2.1 (2021-11-12)

    Bug Fixes

  • 13.2.0 - 2021-11-08
  • 13.1.4 - 2021-10-19
  • 13.1.3 - 2021-08-25
  • 13.1.2 - 2021-08-20
  • 13.1.1 - 2021-07-04
  • 13.1.0 - 2021-05-31
  • 13.0.11 - 2021-03-07
  • 13.0.10 - 2021-03-02
  • 13.0.9 - 2021-02-27
  • 13.0.8 - 2021-02-25
  • 13.0.7 - 2021-01-30
  • 13.0.6 - 2021-01-20
  • 13.0.5 - 2020-11-11
  • 13.0.4 - 2020-08-11
  • 13.0.3 - 2020-07-27
  • 13.0.2 - 2020-07-01
from nock GitHub release notes
Commit messages
Package name: nock
  • 3375382 feat: support for WHATWG URLs (#2437)
  • 4318e35 chore(deps-dev): bump sinon from 14.0.1 to 15.0.1
  • 8c0af40 chore(deps): bump json5 from 1.0.1 to 1.0.2
  • b78ec8c chore(deps-dev): bump @ sinonjs/fake-timers from 10.0.0 to 10.0.2
  • c9cff34 chore(deps-dev): bump eslint from 8.24.0 to 8.29.0
  • c9944d8 chore(deps-dev): bump @ sinonjs/fake-timers from 9.1.2 to 10.0.0
  • 2752313 chore(deps-dev): bump eslint-plugin-promise from 6.0.1 to 6.1.1
  • a587c05 chore(deps-dev): bump sinon from 14.0.0 to 14.0.1
  • 63668b3 chore(deps-dev): bump typescript from 4.8.2 to 4.8.4
  • 9e76a3c chore(deps-dev): bump semantic-release from 19.0.3 to 19.0.5
  • 7946a6e chore(deps-dev): bump eslint from 8.23.0 to 8.24.0
  • 8553c5b chore(deps-dev): bump eslint-plugin-promise from 6.0.0 to 6.0.1
  • 7dd344e chore(deps-dev): bump typescript from 4.7.4 to 4.8.2
  • b0a47ee chore(deps-dev): bump eslint from 8.21.0 to 8.23.0
  • 824a414 chore(deps-dev): bump eslint from 8.18.0 to 8.21.0
  • aa4c572 chore(deps-dev): bump eslint-plugin-mocha from 10.0.5 to 10.1.0
  • d9bab65 fix(README): Add notes about Scope vs Interceptor matchHeader calls (#2382)
  • b4974fb chore(deps-dev): bump typescript from 4.7.2 to 4.7.4
  • 82ebfac chore(deps-dev): bump prettier from 2.6.2 to 2.7.1
  • 223f934 chore(deps-dev): bump sinon from 13.0.2 to 14.0.0
  • 7023294 chore(deps-dev): bump eslint from 8.16.0 to 8.18.0
  • 2edf341 fix(types): allow regexp on `Definition#scope` and `Definition#path` (#2374)
  • 44ee56f chore(deps-dev): bump got from 11.8.3 to 11.8.5
  • 7f21d0c fix: `InterceptedRequestRouter.handleWrite` arity issue (#2371)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs