cdunnnnnnn / rhubarb

https://getrhubarb.org
MIT License
0 stars 0 forks source link

[Snyk] Fix for 2 vulnerabilities #33

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-DOTPROP-543489
No Proof of Concept
With a Snyk patch:
Severity Issue Exploit Maturity
high severity Command Injection
SNYK-JS-TREEKILL-536781
Proof of Concept

Note that some vulnerabilities couldn’t be fully fixed, and so will still fail the Snyk test report.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic