cloudfoundry / stratos

Stratos: Web-based Management UI for Cloud Foundry and Kubernetes
Apache License 2.0
244 stars 131 forks source link

[Snyk] Security upgrade @swimlane/ngx-charts from 10.1.0 to 20.1.2 #5025

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-D3COLOR-1076592
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @swimlane/ngx-charts The new version differs by 170 commits.
  • 997450f (release): 20.1.2
  • 040c095 Bump d3-color from 2.0.0 to 3.1.0 in /projects/swimlane/ngx-charts (#1800)
  • 9577111 (release): 20.1.1 (#1823)
  • a5f4b6d Bump d3-color from 2.0.0 to 3.1.0 (#1798)
  • 91acd8d Setting height for container (#1796)
  • e3286d2 change ios timeout (#1784)
  • 1844e80 Replace deep clone (#1771)
  • 19ecf6f pass through minVal of zero (#1518)
  • e2f94ac Add roundEdges (#1682)
  • 5e9be4e Bump async from 2.6.3 to 2.6.4 (#1772)
  • 2e17a04 Bump ejs from 3.1.6 to 3.1.8 (#1770)
  • 706a4eb Bump karma from 6.3.4 to 6.3.16 (#1740)
  • 2998669 Bump minimist from 1.2.5 to 1.2.6 (#1747)
  • 2ff7d01 Bump shell-quote from 1.7.2 to 1.7.3 (#1761)
  • 940f6e6 Bump moment from 2.29.1 to 2.29.4 (#1767)
  • 0072792 add eslint (#1738)
  • dd197db (release): 20.1.0 (#1739)
  • 1e0d683 Bump nth-check from 2.0.0 to 2.0.1 (#1677)
  • e804a25 Bump path-parse from 1.0.6 to 1.0.7 (#1712)
  • 215f81e Bump log4js from 6.3.0 to 6.4.0 (#1729)
  • b88887c Bump nanoid from 3.1.30 to 3.2.0 (#1730)
  • f2cbd44 Bump follow-redirects from 1.14.1 to 1.14.8 (#1736)
  • ec21b24 Remove angular animations when SSR on charts with series (#1734)
  • f22f9b6 Fix: cyclic import error (#1722)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)