bgoonz / sorting-algorithms

5 stars 1 forks source link

[Snyk] Upgrade mocha from 7.1.1 to 7.2.0 #8

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade mocha from 7.1.1 to 7.2.0.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-Y18N-1021887
472/1000
Why? Proof of Concept exploit, CVSS 7.3
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-608086
472/1000
Why? Proof of Concept exploit, CVSS 7.3
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-590103
472/1000
Why? Proof of Concept exploit, CVSS 7.3
No Known Exploit
Command Injection
SNYK-JS-LODASH-1040724
472/1000
Why? Proof of Concept exploit, CVSS 7.3
Proof of Concept
Prototype Pollution
SNYK-JS-LODASH-567746
472/1000
Why? Proof of Concept exploit, CVSS 7.3
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
472/1000
Why? Proof of Concept exploit, CVSS 7.3
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
472/1000
Why? Proof of Concept exploit, CVSS 7.3
No Known Exploit
Prototype Pollution
SNYK-JS-FLAT-596927
472/1000
Why? Proof of Concept exploit, CVSS 7.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: mocha from mocha GitHub release notes
Commit messages
Package name: mocha
  • 2aab607 Release v7.2.0
  • d525345 update CHANGELOG for v7.2.0 [ci skip]
  • c6b7b61 Downgrade fs-extra for v7.x release branch
  • c967789 fetch sponsors at build time, show ALL non-skeevy sponsors; closes #4271 (#4272)
  • 19f1841 Bump linters ecma version
  • 08c3124 Test spec fixes
  • 1edfb70 Fix for runnable.spec.js
  • 792292a multiple async done() calls result in failure; closes #4151 (#4152)
  • 5fd44cc add Root Hook Plugins
  • e07cf0f do not commit generated content to VCS; closes #3713 (#4289)
  • 137ba18 smart quotes and such on website; closes #3716
  • 23c28e0 add javascript in docs to eslint
  • ab59bfa fix improper warnings for invalid reporters (#4275)
  • 80c1a1a fix test/unit/hook.spec.js (#4288)
  • d4fd2a6 --forbid-only doesn't recognize `it.only` when `before` crashes (#4256); closes #3840
  • 39f4210 Add ability to run tests in a mocha instance multiple times (#4234); closes #2783
  • 8605a28 fix: check if module.paths really exists (#4194); closes #2505
  • 5a1f836 rename fixtures to have .fixture.js extension
  • 4b17207 test helper improvements (#4241)
  • 8b9ce08 assorted test fixes & refactors (#4240)
  • 032f586 Exposing filename in JSON, doc, and json-stream reporters (#4219)
  • 75241bd adds a bunch of keywords
  • 42b78eb Fix missing dot in name of configuration file
  • 73c1a3e refactor validatePlugins to throw coded errors
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs