dbartholomae / middy-middleware-class-validator

A middy validation middleware using class-validator.
MIT License
13 stars 5 forks source link

[Snyk] Security upgrade @commitlint/config-conventional from 8.3.4 to 10.0.0 #25

Closed snyk-bot closed 4 months ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 422/1000
Why? Proof of Concept exploit, CVSS 6.3
Prototype Pollution
SNYK-JS-DOTPROP-543489
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @commitlint/config-conventional The new version differs by 225 commits.
  • 3982e5a v10.0.0
  • 0a70592 chore: update dependency eslint to v7.7.0 (#2063)
  • 5be34ec chore: update dependency @types/jest to v26.0.10 (#2064)
  • 7b7f9a8 chore: update dependency @types/semver to v7.3.2 (#2062)
  • 25d42f4 fix: update dependency find-up to v5 (#2060)
  • 74d54d0 chore: update dependency ts-jest to v26.2.0 (#2059)
  • 0772b27 chore: update typescript-eslint monorepo to v3.9.0 (#2058)
  • 4895d5f Use read dafult export - requiring with CommonJS (#2057)
  • da0c75d build(deps): bump prismjs from 1.20.0 to 1.21.0 (#2055)
  • 0329e09 chore: update dependency conventional-changelog-angular to v5.0.11 (#2056)
  • d8b6bd6 chore: update dependency @types/node to v12.12.54 (#2054)
  • 08bd3db chore: update dependency @types/lodash to v4.14.159 (#2053)
  • 13382ec chore: update dependency @types/jest to v26.0.9 (#2052)
  • 46c3982 chore: update babel monorepo (#2050)
  • 163a789 chore: update typescript-eslint monorepo to v3.8.0 (#2045)
  • f4db933 fix: update dependency cosmiconfig to v7 (#2044)
  • ca63602 chore: update dependency eslint to v7.6.0 (#2042)
  • 964876e chore: update dependency @types/jest to v26.0.8 (#2041)
  • 62f4772 chore: update babel monorepo (#2037)
  • ebb57d2 chore: update dependency eslint-plugin-jest to v23.20.0 (#2034)
  • 1efce79 chore: update dependency ts-jest to v26.1.4 (#2031)
  • 1784ef2 chore: use non-fixed lerna version (#2026)
  • 0b08b4d chore: update dependency eslint-plugin-jest to v23.19.0 (#2030)
  • 3beacfc chore: update typescript-eslint monorepo to v3.7.1 (#2029)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

codecov[bot] commented 4 years ago

Codecov Report

Merging #25 into master will not change coverage. The diff coverage is n/a.

Impacted file tree graph

@@            Coverage Diff            @@
##            master       #25   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            2         2           
  Lines           19        19           
  Branches         1         1           
=========================================
  Hits            19        19           

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update dee37c8...aef5cc0. Read the comment docs.