devilesk / dota-ihl-bot

A Discord bot for hosting Dota 2 inhouse leagues.
https://devilesk.github.io/dota-ihl-bot/
ISC License
8 stars 8 forks source link

[Snyk] Security upgrade sequelize-cli from 5.4.0 to 5.5.0 #44

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

⚠️ Warning ``` Failed to update the package-lock.json, please update manually before merging. ```

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-YARGSPARSER-560381
No Proof of Concept
Commit messages
Package name: sequelize-cli The new version differs by 9 commits.
  • c46f744 5.5.0
  • 3d1c41e docs: changelog for next release
  • a04ff93 chores: remove extra build from ci
  • cd57b40 fix: special characters in password are not escaped (#722)
  • 0828c1f chore(package): update mocha to version 6.0.0 (#745)
  • c15c81f change: default config for operator aliases (#743)
  • 8dc5a20 fix(package): update yargs to version 13.1.0 (#744)
  • 77a9a76 chore(package): update gulp to version 4.0.0 (#726)
  • c19149f docs: enum type (#728)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic