chadxz / my-api

a personal proxy api for various 3rd-party api services across the web
5 stars 0 forks source link

[Snyk] Upgrade config from 3.0.0 to 3.3.1 #79

Closed snyk-bot closed 1 year ago

snyk-bot commented 4 years ago

Snyk has created this PR to upgrade config from 3.0.0 to 3.3.1.

merge advice

✨What is Merge Advice? We check thousands of dependency upgrade pull requests and CI tests every day to see which upgrades were successfully merged. After crunching this data, we give a recommendation on how safe we think the change is for you to merge without causing issues. Learn more, and share your feedback to help improve this feature. 🙏

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue Exploit Maturity
Prototype Pollution
SNYK-JS-MINIMIST-559764
Proof of Concept
Release notes
Package name: config
  • 3.3.1 - 2020-03-25
  • 3.3.0 - 2020-02-27
  • 3.2.6 - 2020-02-21
  • 3.2.5 - 2020-01-16
  • 3.2.4 - 2019-10-25
  • 3.2.3 - 2019-10-03
  • 3.2.2 - 2019-07-21
  • 3.2.1 - 2019-07-18
  • 3.2.0 - 2019-07-11
  • 3.1.0 - 2019-04-07
  • 3.0.1 - 2018-12-17
  • 3.0.0 - 2018-11-20
from config GitHub release notes
Commit messages
Package name: config
  • c86ba2a Resolved security vulnerability in json5
  • dfcd2de Delete _config.yml
  • 0ba1d51 Set theme jekyll-theme-minimal
  • 080d9f9 Prepare for 3.3.0 publish
  • 945aed3 Merge pull request #582 from fostyfost/master
  • c42e3fa Allow all defined values in `substituteDeep`
  • 9fa7022 Updated copyright dates
  • d3616e6 Updated copyright dates
  • 21d3094 Prepare for 3.2.5 publish
  • 3268b40 Merge pull request #585 from dekelev/master
  • dbcddbb Fixed issue with getCustomEnvVars method and multiple config dirs
  • 58f8f89 Merge pull request #581 from JMackie80/master
  • 9ba0aa0 Update README.md
  • 1c59823 Update for 3.2.4 publish
  • e8539b7 Merge pull request #579 from leonardovillela/master
  • c8d815c Improved error handling of env variables value parse
  • 7292a77 For 3.2.3 publish
  • e334cfa Improve diagnostic when custom env file can't be read.
  • 2565a3f Updates for 3.2.2 publish
  • 05fa30c Merge pull request #568 from iMoses/master
  • c38a447 Fix #567 - Missing path.delimiter breaks windows absolute paths
  • 9b73f6a Prep for 3.2.1 publish
  • ced8854 Merge pull request #565 from leosuncin/fix/lorenwest-node-config-564
  • df30f74 test: Update util.js to check object with `__proto__ = null` and Map objects
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

codecov[bot] commented 4 years ago

Codecov Report

Merging #79 into master will not change coverage. The diff coverage is n/a.

Impacted file tree graph

@@          Coverage Diff           @@
##           master     #79   +/-   ##
======================================
  Coverage    5.92%   5.92%           
======================================
  Files          31      31           
  Lines         625     625           
  Branches       90      90           
======================================
  Hits           37      37           
  Misses        503     503           
  Partials       85      85           

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update e0533f5...dd7779a. Read the comment docs.