cblanc / sws_gathers

NSL Gathers App
http://gathers.ensl.org
8 stars 9 forks source link

[Snyk] Fix for 1 vulnerabilities #204

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: discord.js The new version differs by 250 commits.
  • 2338594 Merge branch 'master' into stable
  • 3142d8c v12.0.0
  • a133768 v12.0.0
  • 7d40c43 chore: merge v12-dev master into stable
  • d7c5baf chore: update discordjs/discord.js references
  • f4b1b39 feat: document intent error code messages (#3871)
  • 2d67fbb docs: clarify which checks GuildMember#manageable does (#3870)
  • 544bb78 refactor: make LimitedCollection an implementation detail (#3872)
  • c7f4485 docs(PartialRoleData): id is optional (#3866)
  • 713309e fix(playinterface): lazy require VoiceBroadcast to avoid circul… (#3864)
  • acdd832 fix(typings): enum values for ChannelType (#3861)
  • 09e4912 fix(typings): remove duplicate VerificationLevels (#3862)
  • a6d3501 fix(typings): for intents (#3860)
  • 8a2f893 feat: Intents bitfield (#3844)
  • b58813a chore(*): update node version mention & use strict
  • d33fc74 typings: Refactor how channel types are done (#3808)
  • a04b4ca docs(TextBasedChannel): fix typo (#3858)
  • 31ee0d8 docs(shard): add .cache to GuildManager in fetchClientValue exa… (#3857)
  • d9e12b8 fix(guild): import paths
  • c065156 chore: consistency/prettier (#3852)
  • 6650d50 feat(MessageEmbed): Support EmbedFieldData[] instead of EmbedFi… (#3845)
  • 9c8aaf1 feat: reimplement disableEveryone into disableMentions
  • bbe169d fix(MessageEmbed): prevent possible destructuring error
  • e4f567c refactor(GuildChannel): change overwritePermisions to accept an… (#3853)
See the full diff
Package name: socket.io The new version differs by 21 commits.
  • 873fdc5 chore(release): 2.4.0
  • f78a575 fix(security): do not allow all origins by default
  • d33a619 fix: properly overwrite the query sent in the handshake
  • 3951a79 chore: bump engine.io version
  • 6fa026f ci: migrate to GitHub Actions
  • 47161a6 [chore] Release 2.3.0
  • cf39362 [chore] Bump socket.io-parser to version 3.4.0
  • 4d01b2c test: remove deprecated Buffer usage (#3481)
  • 8227192 [docs] Fix the default value of the 'origins' parameter (#3464)
  • 1150eb5 [chore] Bump engine.io to version 3.4.0
  • 9c1e73c [chore] Update the license of the chat example (#3410)
  • df05b73 [chore] Release 2.2.0
  • b00ae50 [feat] Add cache-control header when serving the client source (#2907)
  • d3c653d [docs] Add Touch Support to the whiteboard example (#3104)
  • a7fbd1a [fix] Throw an error when trying to access the clients of a dynamic namespace (#3355)
  • 190d22b [chore] Bump dependencies
  • 7b8fba7 [test] Update Travis configuration
  • e5f0cea [docs] Use new JavaScript syntax inside the README (#3360)
  • 7e35f90 [docs] fix `this` scope in the chat example
  • 2dbec77 [chore] Update issue template
  • d97d873 [docs] update README.md (#3309)
See the full diff
Package name: socket.io-client The new version differs by 25 commits.
  • de2ccff chore(release): 2.4.0
  • e9dd12a chore: bump engine.io-client version
  • 7248c1e ci: migrate to GitHub Actions
  • 4631ed6 chore(release): 2.3.1
  • 7f73a28 test: fix tests in IE
  • 67c54b8 chore: bump engine.io-parser and socket.io-parser
  • 15a52ab test: remove arrow function (for now)
  • 050108b fix: fix reconnection after opening socket asynchronously (#1253)
  • b570025 chore: bump engine.io-client and downgrade debug
  • 1fb1b78 chore: remove unused dependencies
  • 0c39f14 docs: add section about Debug / logging on the client side (#1278)
  • 6ce02ee docs: add server port in the example (#1359)
  • f4a4d89 chore: update package-lock.json file
  • 3c1d860 chore: bump component-emitter dependency (#1376)
  • b7dbbd2 test: fix race condition in the tests
  • 661f1e7 [chore] Release 2.3.0
  • 71d7b79 [chore] Bump engine.io-client to version 3.4.0
  • 8b4a539 [docs] Add CDN link (#1318)
  • 40cf185 [ci] use Node.js 10 for compatibility with Gulp v3
  • 3020e45 [chore] Release 2.2.0
  • 06e9a4c [chore] Bump dependencies
  • 4a93871 [chore] Update the Makefile
  • eeafa44 [fix] Remove any reference to the `global` variable
  • dfc34e4 [chore] Pin zuul version
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic