dwp / dwp-patterns

DWP pattern library
MIT License
4 stars 3 forks source link

[Snyk] Security upgrade xo from 0.14.0 to 0.35.0 #43

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: xo The new version differs by 250 commits.
  • 4f40389 0.35.0
  • 0555859 Upgrade dependencies
  • b1012d3 Allow unassigned stylesheet imports (#502)
  • 6fa99cd Bump Prettier to ^2.1.2 (#505)
  • 33b769e 0.34.2
  • 35e6336 Fix the `extensions` option (#503)
  • 2346fef 0.34.1
  • 8afa1d9 Update dependencies
  • 77716e2 Disable the `unicorn/import-style` rule for TypeScript projects
  • 4c9909a 0.34.0
  • b0ebabd Update dependencies
  • ba547e7 Enable automatic annotations on GitHub Actions (#497)
  • a5ff341 0.33.1
  • ead63be Fix setting multiple of some CLI flags
  • 27549c2 0.33.0
  • 53fcb1a Update dependencies
  • f45ab80 Respect Prettier’s use of .editorconfig (#493)
  • 084e7a3 0.32.1
  • 7d015ac Update devDependency ava from v1.1.0 to v3.9.0 (#490)
  • 744090a Update meow from v5.0.0 to v7.0.1 (#489)
  • 522d264 Test on Node.js 14 (#488)
  • 245f7d3 0.32.0
  • 0dd4a9d Disable some problematic rules
  • d3abdb6 Add more extensions to `import/extensions` rule
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic