jazyx / vdvoyom

Meteor app for language teachers to play interactive games online with students
0 stars 0 forks source link

[Snyk] Upgrade meteor-node-stubs from 1.0.0 to 1.0.3 #148

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade meteor-node-stubs from 1.0.0 to 1.0.3.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Cryptographic Issues
SNYK-JS-ELLIPTIC-571484
492/1000
Why? Proof of Concept exploit, CVSS 7.7
Proof of Concept
Timing Attack
SNYK-JS-ELLIPTIC-511941
492/1000
Why? Proof of Concept exploit, CVSS 7.7
No Known Exploit
Cryptographic Issues
SNYK-JS-ELLIPTIC-1064899
492/1000
Why? Proof of Concept exploit, CVSS 7.7
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: meteor-node-stubs from meteor-node-stubs GitHub release notes
Commit messages
Package name: meteor-node-stubs
  • ae2b43f Merge pull request #27 from xet7/master
  • 1fb58b3 Update elliptic to 6.5.4
  • 5171594 v1.0.2
  • 4310b30 Merge pull request #25 from meteor/dependabot/npm_and_yarn/elliptic-6.5.4
  • 45bfafe Bump elliptic from 6.5.3 to 6.5.4
  • 80ae689 v1.0.1
  • 0e28a76 Merge pull request #21 from meteor/dependabot/npm_and_yarn/elliptic-6.5.3
  • 8f45cd1 Bump elliptic from 6.4.1 to 6.5.3
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs