forcedotcom / dependencies-cli

SFDX plugin for metadata dependencies tooling API
BSD 3-Clause "New" or "Revised" License
106 stars 18 forks source link

[Snyk] Security upgrade http-server from 0.11.1 to 0.12.0 #13

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Override Protection Bypass
npm:qs:20170213
No No Known Exploit
Commit messages
Package name: http-server The new version differs by 86 commits.
  • e6f6358 0.12.0
  • fee644f fix repo urls
  • cd0bbc8 SSL Certificate Checking and Grammar Fixes (#479)
  • 3c5dfc6 Test on osx (#576)
  • 9fa7e93 Merge pull request #575 from http-party/update-readme-badges
  • 6b2fe25 test on osx
  • 0f65fc6 update readme badges to use new repo
  • a306ebc Merge pull request #573 from Xmader/test-on-windows
  • 9a0f64f force to use ecstatic v3.3.2 in tests (#574)
  • 5f06ac8 bump ecstatic in package.json to ^3.3.2
  • f96fc99 Merge branch 'master' into test-on-windows
  • c1ea830 do a hacky workaround directly to the http-server package to fix… (#569)
  • e708c79 force to install ecstatic v3.3.2 in tests
  • 8028337 force to check out files with LF EOL
  • 3addf09 test on Windows
  • a2e7721 Merge branch 'master' into hacky-fix
  • 6260536 Merge pull request #510 from ebiiim/patch-1
  • dbf4881 -t flag to control timeout (#295)
  • 901ca49 Merge pull request #557 from epugh/master
  • a0db8f9 add process title (#515)
  • da111d6 Update travis node versions (#507)
  • afb8f4f Merge pull request #516 from http-party/specify_engines
  • de7cf70 Merge branch 'master' into update-travis-node-versions
  • 1755478 Merge pull request #572 from Xmader/fix-tests
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic