dwp / dwp-patterns

DWP pattern library
MIT License
4 stars 3 forks source link

[Snyk] Security upgrade xo from 0.14.0 to 0.25.0 #27

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ACORN-559469
No No Known Exploit
Commit messages
Package name: xo The new version differs by 206 commits.
  • 1c8e762 0.25.0
  • 042b726 Disable some problematic rules
  • 97e32b9 Upgrade dependencies
  • 5cde9aa Fix lint test error on Windows (#401)
  • f6bf4c0 Respect `.eslintignore` (#377)
  • 05c30e2 Disable the `unicorn/prevent-abbreviations` rule temporarily
  • 97aa2b0 Upgrade dependencies
  • ee145cb Disable the `import/named` rule for now
  • 03daca9 Minor code refactor (#397)
  • d09f87c Readme tweaks
  • c55f962 Make the `unicorn/prevent-abbreviations` rule less strict
  • 8a213ef Require Node.js 8
  • 4f50816 Lint fixes
  • 8d6c5c5 Add option to `import/no-useless-path-segments` rule
  • 77e9e93 Update `eslint-plugin-unicorn`
  • a3d74a6 Add `node/prefer-promises/fs` rule
  • 8f8fc94 Add `node/prefer-promises/dns` rule
  • 698b043 Upgrade to ESLint 6
  • 0216305 Fix typo in eslint-config-xo-vue link (#393)
  • 5090c39 Mention eslint-config-xo-vue in the readme (#388)
  • f069a21 Disable some problematic `import` rules
  • b73b11b Add `tap-snapshots/*.js` to default ignore list (#385)
  • 2ab0a69 Update project tagline
  • 3033fcd Turn all paths `cwd`-relative before linting (#372)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic