inrupt / wac-ldp

A central component for Solid servers, handles Web Access Control and Linked Data Platform concerns.
MIT License
12 stars 5 forks source link

[Snyk] Upgrade rdflib from 1.0.4 to 1.3.1 #193

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to upgrade rdflib from 1.0.4 to 1.3.1.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Cryptographic Issues
SNYK-JS-ELLIPTIC-571484
492/1000
Why? Proof of Concept exploit, CVSS 7.7
Proof of Concept
Timing Attack
SNYK-JS-ELLIPTIC-511941
492/1000
Why? Proof of Concept exploit, CVSS 7.7
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: rdflib from rdflib GitHub release notes
Commit messages
Package name: rdflib
  • 2c1aac6 1.3.1
  • 4166863 Fix npm run build:types
  • a7230f8 1.3.0
  • f6f8b0b Update dependencies (#425)
  • 7c17060 Merge pull request #431 from linkeddata/updateMany
  • c179ce0 Merge branch 'master' into updateMany
  • a913bc8 merge in master branch
  • c07c4f9 Tweak a console log
  • acdc501 getHeader: look for the URI (AS A STRING NOT A NODE) for a stored request - was accidentally changed to a named node
  • a40889d Make fetcher optional for Query -- don't force link following
  • 91a56c9 1.2.3
  • 13e2a78 Merge pull request #427 from linkeddata/requestedURI-as-NamedNode
  • 0c7ef5c docuri as string
  • 38ab9b7 Store requestedURI as NamedNode
  • 4d4db8e npm run watch and fix small typos
  • 84b75b6 Merge pull request #421 from linkeddata/fix/patch-parser
  • 4c25a80 Fix SPARQL patch parsing.
  • 65bc393 1.2.2
  • 9d87139 Merge pull request #412 from linkeddata/editable
  • f5a7b24 remove source trace line
  • a169a68 Added a test for the case
  • 3a0756b Merge remote-tracking branch 'origin/master' into editable
  • d6e59a4 1.2.1
  • 10e8ed6 Merge pull request #415 from linkeddata/feature/types-store
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs