dickschoeller / gedbrowser

Application for displaying genealogy data read from GEDCOM files.
http://www.schoellerfamily.org/
Apache License 2.0
1 stars 1 forks source link

[Snyk] Fix for 1 vulnerabilities #996

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 556/1000
Why? Recently disclosed, Has a fix available, CVSS 5.4
Open Redirect
SNYK-JS-GOT-2932019
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: npm The new version differs by 250 commits.
  • 3b4ba65 7.0.0
  • bbfc75d chore: fix weird .gitignore thing that happened somehow
  • 8a2d375 docs: changelog for v7.0.0
  • 365f2e7 read-package-json@3.0.0
  • fafb348 npm-package-arg@8.1.0
  • 9306c68 libnpmfund@1.0.1
  • 569cd64 libnpmfund@1.0.0
  • ac9fde7 Integration code for @ npmcli/arborist@1.0.0
  • 704b9cd @ npmcli/arborist@1.0.0
  • 3955bb9 hosted-git-info@3.0.6
  • da240ef fix: patch config.js to remove duplicate values
  • 9ae45a8 init-package-json@2.0.0
  • 41ab36d eslint@7.11.0
  • c474a15 npm-registry-fetch@8.1.5
  • efc6786 fix: make sure publishConfig is passed through
  • 1e4e6e9 docs: v7 using npm config refresh
  • 5c1c2da fix: init config aliases
  • 5bc7eb2 docs: v7 npm-install refresh
  • 1a35d87 7.0.0-rc.4
  • 7a5a557 docs: changelog for v7.0.0-rc.4
  • f0cf859 chore: dedupe deps
  • 0273745 make-fetch-happen@8.0.10
  • 7bd47ca @ npmcli/arborist@0.0.33
  • 9320b8e only escape arguments, not the command name
See the full diff
Package name: snyk The new version differs by 250 commits.
  • 34c9347 Merge pull request #2161 from snyk/chore/fix-lerna-release
  • faaaa85 chore: update release to use local lerna installation
  • bf56735 Merge pull request #2159 from snyk/fix/use-oauth-token-for-analytics
  • 14a0b76 fix: use OAUTH token if set for analytics
  • 2f32793 Merge pull request #2156 from snyk/test/json-file-output-cleanup
  • 271a052 Merge pull request #2160 from snyk/test/flakey-test-232
  • a898dfb Merge pull request #2158 from snyk/test/deprecated-mock-server-option
  • 37a1fa1 Merge pull request #2152 from snyk/chore/remove-update-notifier
  • 25b201c test: use common test setup
  • fa5bc2e Merge pull request #2155 from snyk/chore/document-uselocalpackage
  • 01e348d Merge pull request #2157 from snyk/test/analytics-fix
  • 1fec66e test: use async/await instead of callbacks
  • 6b91de7 chore: remove update notifier
  • 8e296a6 test: simplify fixture paths
  • 39da98f test: remove deprecated option from fake server
  • 97f1dc3 test: increase analytics test timeout
  • 6573d1b test: remove spy from acceptance test
  • aed2812 chore: document useLocalPackage
  • 104b07d Merge pull request #2148 from snyk/chore/ci-optimization
  • 04d18cd Merge pull request #2121 from snyk/test/color-text-by-severity-test
  • 906e766 chore: use lerna from devDeps
  • 28b1197 chore: use large resource class
  • 338f7a9 Merge pull request #1968 from snyk/chore/jest-27
  • f1d45a0 Merge pull request #2145 from snyk/feat/enable-iac-analytics-for-ignore
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Open Redirect