jfoclpf / form-for-parking-violation

APP para submissão de queixa de estacionamento ilegal
https://play.google.com/store/apps/details?id=com.form.parking.violation
GNU General Public License v3.0
52 stars 16 forks source link

[Snyk] Security upgrade cordova-set-version from 10.0.0 to 11.0.1 #87

Closed snyk-bot closed 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: cordova-set-version The new version differs by 65 commits.
  • 52aac54 fix(deps): update dependency meow to v8 (#306)
  • 9b6e5f9 chore(deps): update dependency eslint-config-prettier to v6.15.0
  • d09a9ac chore(deps): update dependency eslint to v7.12.1
  • 277da48 chore(deps): update dependency eslint to v7.12.0
  • 4bba025 chore(deps): update jest monorepo to v26.6.1
  • 0610331 chore(deps): update dependency eslint-config-prettier to v6.14.0
  • 5173252 chore(deps): update jest monorepo to v26.6.0
  • d8d5295 chore(deps): update dependency @ babel/core to v7.12.3
  • f1aafbb chore(deps): update dependency eslint-config-prettier to v6.13.0
  • 6098ded chore(deps): update babel monorepo to v7.12.1
  • 747f760 chore(deps): update babel monorepo to v7.12.0
  • 58ff9b4 chore(deps): update dependency semantic-release to v17.2.1
  • 12e1afc chore(deps): update dependency semantic-release to v17.2.0
  • 19930a5 chore(deps): update dependency jest to v26.5.3
  • 07d3947 chore(deps): update dependency eslint to v7.11.0
  • b4cdfc6 chore(deps): update dependency jest to v26.5.2
  • b1df93a chore(deps): update dependency babel-jest to v26.5.2
  • 87c232a chore(deps): update dependency codecov to v3.8.0
  • 9d2d7dc chore(deps): update dependency jest to v26.5.0
  • 20ff23a chore(deps): update dependency babel-jest to v26.5.0
  • ba6216d chore(deps): update dependency eslint-plugin-import to v2.22.1
  • 43a4327 chore(deps): update dependency eslint to v7.10.0
  • a1e9272 chore(deps): update dependency eslint-config-prettier to v6.12.0
  • 3b3de88 chore(deps): update dependency semantic-release to v17.1.2
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic