derhuerst / db-cli

A CLI for Deutsche Bahn.
https://github.com/derhuerst/db-cli#db-cli
ISC License
6 stars 1 forks source link

[Snyk] Security upgrade hafas-cli from 0.2.3 to 2.0.0 #3

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: hafas-cli The new version differs by 12 commits.
  • 3dff342 minor tweaks; 2.0.0
  • 99c0fd9 example script πŸ“
  • c27567b upgrade deps: chalk@4, cli-table3@0.6, date-prompt@1, pify@5
  • 1be1f82 hafas-client@5, Node 14+ πŸ’₯πŸ’š
  • f929173 so coroutine -> async/await
  • bd3682e renderTime: add onTimeWithColor option
  • ce08c8a fix renderTime πŸ›βœ…πŸ’š
  • b137582 readme: update badges πŸ“; minor tweaks; 1.0.1
  • 80968f7 chalk@3
  • 706a1d6 cleanup, 1.0.0
  • 76e2aee cfg.results -> cfg.nrOfResults :boom:
  • c3a6672 hafas-client@4 :boom:, Node 8+ :boom:
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

πŸ›  Adjust project settings

πŸ“š Read more about Snyk's upgrade and patch logic