cds-snc / c19-benefits-node

Answer some questions to find which federal programs can help you https://covid-benefits.alpha.canada.ca/. - Répondez à quelques questions pour trouver quels programmes d’aide financière fédéraux s’offrent à vous https://covid-prestations.alpha.canada.ca/.
MIT License
2 stars 4 forks source link

[Snyk] Security upgrade notifications-node-client from 4.7.3 to 4.9.0 #547

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 405/1000
Why? CVSS 8.1
Prototype Pollution
SNYK-JS-AJV-584908
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: notifications-node-client The new version differs by 17 commits.
  • cff5295 Merge pull request #124 from alphagov/document-letter-contact-block
  • 4097ad6 Add letter_contact_block to the template responses
  • 729dcf3 Merge pull request #123 from alphagov/snyk-fix-dbbb05e241bcae1433740ec85d4c1fb1
  • 66f1665 fix: package.json to reduce vulnerabilities
  • bb8b750 Merge pull request #121 from alphagov/update-temporary-failure-description
  • 9b21838 Update content
  • 5e0ff1d Update temporary failure description
  • 8e4f177 Merge pull request #118 from alphagov/iscsv
  • 41e6ea3 Update variable name for `prepareUpload` to be more accurate
  • f682703 Add isCsv argument to prepareUpload function
  • 91aec89 Merge pull request #119 from alphagov/update-status-tables
  • 923f7ea Fix links
  • badb54c Merge pull request #120 from alphagov/guest-list
  • 4fd6e74 Rename whitelist to guest list
  • f3e61df Remove status table and add links
  • df8fad9 Update the status table for multiple messages
  • 54d8297 Update status tables
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic