dwp / dwp-patterns

DWP pattern library
MIT License
4 stars 3 forks source link

[Snyk] Security upgrade xo from 0.14.0 to 0.22.0 #55

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: xo The new version differs by 160 commits.
  • be8c1d1 0.22.0
  • 142744a Bump dependencies
  • 8e4f435 Remove `**/bundle.js` as default ignore
  • f76c901 Fix CLI's `--space` option parsing (#342)
  • 98dee9a Respect `nodeVersion` option set in `override` block (#345)
  • e783704 Update dependencies and fix unit tests (#344)
  • 404d81b Fix links in documentation (#343)
  • 71d06a0 Upgrade to ESLint 5 (#333)
  • 00d6b7c Don't ignore fixture directories by default (#317)
  • 957b0d9 Add support for TypeScript and document usage with Flow (#326)
  • a28625a 0.21.1
  • 36f7f38 Fix `space`/`useTabs` conflict message (#327)
  • 0765998 0.21.0
  • b633e92 Do not override default options with absent CLI flags (#316)
  • cec0853 Update plugins and add some new rules
  • d1eb47c Require Node.js 6
  • 6254110 GitHub now natively supports SVG
  • 4fd6991 Disable number-literal-case rule when using Prettier (#311)
  • 7190640 Remove `import/prefer-default-export` rule
  • f67ff58 Default Prettier `trailingComma` conf to `none` (#305)
  • 11c35c8 Upgrade prettier to last version (#306)
  • f100021 0.20.3
  • 5f062e2 Simplify appveyor.yml
  • c62345c Make Prettier confing take precedence over XO (#301)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.