commonality / generator-community

ไทค Generate README, CODE_OF_CONDUCT, CONTRIBUTING, LICENSE, ISSUE_TEMPLATE, and PULL_REQUEST_TEMPLATE repository docs to encourage consumption and invite contributions.
MIT License
9 stars 7 forks source link

[Snyk] Security upgrade git-url-parse from 7.0.1 to 13.0.0 #42

Open gregswindle opened 2 years ago

gregswindle commented 2 years ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=npm&package_name=git-url-parse&from_version=7.0.1&to_version=13.0.0&pr_id=ec9f1d4b-6762-4271-8ee4-fa4b926b3ad8&visibility=true&has_feature_flag=false) #### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **643/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5 | Improper Input Validation
[SNYK-JS-PARSEURL-3024398](https://snyk.io/vuln/SNYK-JS-PARSEURL-3024398) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: git-url-parse The new version differs by 137 commits.
  • 129677c Updated docs
  • 26cc5fe Fix shorthand urls
  • 4e3b1cc Merge branch 'custom-ssh-user-tests' of github.com:privatenumber/git-url-parse into new-version
  • 32ed275 :arrow_up: 13.0.0 :tada:
  • 7cce252 refactor: remove enterpriseSsh
  • c674528 test: failing test for custom SSH user
  • f4ea05e wip
  • 6c0ca07 Updated docs
  • 9746972 :arrow_up: 12.0.0 :tada:
  • 60011fb Update dependencies
  • 246c911 Updated docs
  • f3093dc Merge branch 'bugfix/parse-bitbucket-server-subpaths' of https://github.com/goober/git-url-parse into new-version
  • 263143f :arrow_up: 11.6.0 :tada:
  • 37f5c50 Fix parsing Bitbucket Server urls with files located in subfolders
  • f56cbc1 Updated docs
  • be1efb4 Merge branch 'feature/support-commits-url-for-bitbucket-server' of https://github.com/goober/git-url-parse into new-version
  • 1cb827f :arrow_up: 11.5.0 :tada:
  • 8e9bc4b Merge branch 'new-version' of github.com:IonicaBizau/git-url-parse into new-version
  • 4b61233 :arrow_up: 11.5.0 :tada:
  • 0abc5c1 Add support for Bitbucket Server repository root and commit endpoints
  • 49f5342 :arrow_up: 11.4.5 :tada:
  • 71c7298 Updated docs
  • c44df32 Merge branch 'azure_branch' of https://github.com/n2ygk/git-url-parse into new-version
  • 2003390 :arrow_up: 11.4.4 :tada:
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: ๐Ÿง [View latest project report](https://app.snyk.io/org/gregswindle-github-marketplace/project/91e9f3c7-4dde-45f1-90d9-c91e3f10fa0d?utm_source=github&utm_medium=referral&page=fix-pr) ๐Ÿ›  [Adjust project settings](https://app.snyk.io/org/gregswindle-github-marketplace/project/91e9f3c7-4dde-45f1-90d9-c91e3f10fa0d?utm_source=github&utm_medium=referral&page=fix-pr/settings) ๐Ÿ“š [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"ec9f1d4b-6762-4271-8ee4-fa4b926b3ad8","prPublicId":"ec9f1d4b-6762-4271-8ee4-fa4b926b3ad8","dependencies":[{"name":"git-url-parse","from":"7.0.1","to":"13.0.0"}],"packageManager":"npm","projectPublicId":"91e9f3c7-4dde-45f1-90d9-c91e3f10fa0d","projectUrl":"https://app.snyk.io/org/gregswindle-github-marketplace/project/91e9f3c7-4dde-45f1-90d9-c91e3f10fa0d?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-PARSEURL-3024398"],"upgrade":["SNYK-JS-PARSEURL-3024398"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore","merge-advice-badge-shown"],"priorityScoreList":[643]}) --- **Learn how to fix vulnerabilities with free interactive lessons:** ๐Ÿฆ‰ [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io?loc=fix-pr)