emptygalaxy / homebridge-comfoair

4 stars 1 forks source link

[Snyk] Upgrade comfoair from 1.0.3 to 1.0.4 #20

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade comfoair from 1.0.3 to 1.0.4.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Information Exposure
SNYK-JS-SIMPLEGET-2361683
547/1000
Why? Proof of Concept exploit, CVSS 8.8
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
547/1000
Why? Proof of Concept exploit, CVSS 8.8
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: comfoair from comfoair GitHub release notes
Commit messages
Package name: comfoair
  • b46809a 1.0.4
  • cab0ce6 add static function to list available commands
  • 99698f9 clear queue when closing connection and add function to reopen connection
  • e51d200 fix eslint warning
  • 529781e update package dependencies and eslint
  • 0b92573 Bump path-parse from 1.0.6 to 1.0.7
  • e864ca9 Bump glob-parent from 5.1.1 to 5.1.2
  • e3cbc83 Bump hosted-git-info from 2.8.8 to 2.8.9
  • 3aa11d6 Bump lodash from 4.17.20 to 4.17.21
  • 821d01b Bump y18n from 4.0.0 to 4.0.1
  • 5a2db62 Bump ini from 1.3.5 to 1.3.7
  • 4ab33f4 fix npm vulnerabilities
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs