dominique-mueller / angular-package-builder

[DEPRECATED] Packages your Angular 4+ library based on the Angular Package Format.
https://www.npmjs.com/package/angular-package-builder
MIT License
23 stars 2 forks source link

[Snyk] Fix for 3 vulnerabilities #202

Open dominique-mueller opened 9 months ago

dominique-mueller commented 9 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **696/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.5 | Denial of Service (DoS)
[SNYK-JS-DECODEURICOMPONENT-3149970](https://snyk.io/vuln/SNYK-JS-DECODEURICOMPONENT-3149970) | No | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **479/1000**
**Why?** Has a fix available, CVSS 5.3 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-MINIMATCH-3050818](https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818) | Yes | No Known Exploit ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **586/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.3 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-PATHPARSE-1077067](https://snyk.io/vuln/SNYK-JS-PATHPARSE-1077067) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: rollup-plugin-commonjs The new version differs by 51 commits.
  • 12a11c2 10.1.0
  • 82ca3a2 Update changelog
  • fcd9826 Normalize ids before looking up in named export map (#406)
  • e431c29 Update README.md with note on symlinks (#405)
  • de40daa 10.0.2
  • e741130 Update changelog
  • 8f91234 Support preserveSymlinks: false (fixes #400) (#401)
  • 1bc5896 10.0.1
  • 504ec54 Update changelog
  • 668d888 Update dependencies
  • 99d1ff5 Handle builins appropriately for resolve 1.11.0. Fixes #394. (#395)
  • 3bf824b Update changelog
  • 29cfe83 Make tests run with Node 6 again and update dependencies (#389)
  • a2f3ff4 10.0.0
  • 1fd9168 Update changelog
  • c8fabd7 Use new context functions, fix issue when resolveId returns an object (#387)
  • 851ed8e 9.3.4
  • 2c447af Update changelog
  • 5cb3b2d set same typing to include and exclude properties (#385)
  • 456a223 make "extensions" optional (#384)
  • 3921f28 9.3.3
  • 28421a0 Update changelog
  • e63e57f fix: remove colon from module prefixes (#371)
  • a34ebbc 9.3.2
See the full diff
Package name: rollup-plugin-node-resolve The new version differs by 72 commits.
See the full diff
Package name: rollup-plugin-sourcemaps The new version differs by 32 commits.
  • 22005d8 0.6.0
  • 004f060 Expose ES module through conditional exports
  • fd48749 chore(package): update @ rollup/pluginutils to version 3.0.9
  • f3d1c75 chore(package): update @ typescript-eslint/parser to version 2.25.0
  • d6881e5 chore(package): update @ typescript-eslint/eslint-plugin to version 2.25.0
  • 309098b fix(package): update source-map-resolve to version 0.6.0
  • d467770 chore(package): update prettier to version 2.0.5
  • fa9d2f2 Drop support for Node 8
  • c284f72 chore(package): update rollup to version 2.7.5
  • 4708173 chore(package): update @ rollup/plugin-typescript to version 4.1.1
  • ef6d6e8 Upgrade to Jest 25
  • 6a32f8a chore(package): update rollup to version 1.29.1
  • fe5892a 0.5.0
  • ad11f84 Format changelog with prettier
  • d0cde7c Remove david-dm references
  • 30cd4a8 Increase test coverage
  • eb0aa2f Add lts/erbium to TravisCI config
  • 72baf0f Update license
  • d394f74 Update build scripts
  • f720a8c Modernize
  • 3987494 chore(package): update rollup-plugin-babel to version 3.0.0 (#62)
  • d28d1c5 chore(package): update eslint-config-airbnb-base to version 12.1.0 (#71)
  • 9e0ded6 chore(package): update eslint to version 4.14.0 (#70)
  • f0bf3ae chore(package): update ava to version 0.24.0 (#69)
See the full diff
Package name: ts-simple-ast The new version differs by 250 commits.
  • 008d79b docs: Add links in "renaming" to information about moving files and directories.
  • f96fd74 chore(release): 21.0.3
  • 3889264 chore: Fix declarations for TS 3.3.
  • 686189c chore(release): 21.0.2
  • b5b9af8 fix: tsconfig.json with "include" and "rootDir" would not have files correctly resolved.
  • 30981c7 chore: Update CHANGELOG.md
  • 873a2b3 chore(release): 21.0.1
  • 811ce1c fix: Project.getSourceFileOrThrow - Improve error message when the source file can't be found.
  • 845d7cf chore: Update tests from 3.2.2 -> 3.2.4
  • b0a1f0f chore: Use @ types/ts-nameof
  • 684f240 chore(release): 21.0.0
  • 234bf85 chore: Update breaking changes.
  • 0bd6cff chore: Run code generation and verification.
  • 6cf2d40 feat: #523 - Resolved node_module source files or directories are no longer returned from Project#getSourceFiles() and getDirectories()
  • b200d35 chore: Update declaration file.
  • 73c5a39 feat: #522 - Project should not return implicitly resolved files and directories in most scenarios.
  • a12a92c perf: Make internal Es5HashSet O(1) instead of O(n) for lookups.
  • fc18a59 chore: Update license year.
  • 28d12e3 feat: #518 - Add SourceFile#fixMissingImports()
  • 8f383b6 chore: #519 - Also test that the target type is a tuple for a tuple type.
  • 85deec7 feat: Add FileTextChanges#getSourceFile()
  • ef9f3a3 feat: Add LanguageService#getCombinedCodeFix(...)
  • fb367bd chore: Fix compile error.
  • bee8c2b chore: Only run tests for #519 when ts >= 3.2
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/dominique-mueller/project/76db81d7-010c-4ad0-ac59-ae958782c56a?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/dominique-mueller/project/76db81d7-010c-4ad0-ac59-ae958782c56a?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"f067155c-c35e-4014-bdc0-381a8a6aaa63","prPublicId":"f067155c-c35e-4014-bdc0-381a8a6aaa63","dependencies":[{"name":"rollup-plugin-commonjs","from":"9.1.8","to":"10.1.0"},{"name":"rollup-plugin-node-resolve","from":"3.3.0","to":"5.2.0"},{"name":"rollup-plugin-sourcemaps","from":"0.4.2","to":"0.6.0"},{"name":"ts-simple-ast","from":"14.4.5","to":"21.0.4"}],"packageManager":"npm","projectPublicId":"76db81d7-010c-4ad0-ac59-ae958782c56a","projectUrl":"https://app.snyk.io/org/dominique-mueller/project/76db81d7-010c-4ad0-ac59-ae958782c56a?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-DECODEURICOMPONENT-3149970","SNYK-JS-MINIMATCH-3050818","SNYK-JS-PATHPARSE-1077067"],"upgrade":["SNYK-JS-DECODEURICOMPONENT-3149970","SNYK-JS-MINIMATCH-3050818","SNYK-JS-PATHPARSE-1077067"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[696,479,586],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Denial of Service (DoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr)