jinaga / starter-typescript

Starter project using TypeScript
0 stars 0 forks source link

[Snyk] Upgrade jimp from 0.16.1 to 0.16.2 #93

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade jimp from 0.16.1 to 0.16.2.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Denial of Service (DoS)
SNYK-JS-JPEGJS-2859218
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: jimp
  • 0.16.2 - 2022-09-15

    🐛 Bug Fix

    📝 Documentation

    Authors: 4

  • 0.16.2-canary.1094.1345.0 - 2022-08-02
  • 0.16.2-canary.1093.1332.0 - 2022-07-25
  • 0.16.2-canary.1086.1311.0 - 2022-05-21
  • 0.16.2-canary.1084.1305.0 - 2022-05-16
  • 0.16.2-canary.1082.1294.0 - 2022-04-28
  • 0.16.2-canary.1080.1288.0 - 2022-04-04
  • 0.16.2-canary.1073.1276.0 - 2022-02-21
  • 0.16.2-canary.1070.1265.0 - 2022-02-11
  • 0.16.2-canary.1052.1235.0 - 2021-10-27
  • 0.16.2-canary.1051.1228.0 - 2021-10-22
  • 0.16.2-canary.1045.1221.0 - 2021-09-01
  • 0.16.2-canary.1016.1185.0 - 2021-05-25
  • 0.16.2-canary.1008.1164.0 - 2021-04-29
  • 0.16.2-canary.984.1126.0 - 2021-01-25
  • 0.16.2-canary.969.1115.0 - 2020-12-11
  • 0.16.2-canary.964.1101.0 - 2020-11-24
  • 0.16.2-canary.956.1095.0 - 2020-10-23
  • 0.16.2-canary.947.1077.0 - 2020-10-03
  • 0.16.2-canary.938.1059.0 - 2020-09-07
  • 0.16.2-canary.934.1053.0 - 2020-08-28
  • 0.16.2-canary.919.1052.0 - 2020-08-28
  • 0.16.1 - 2020-08-28

    🐛 Bug Fix

    • @ jimp/jpeg
      • upgrade jpeg-js dependency #933 (vincentdufrasnes@vincent-dufrasnes @ Chupsy)

    Authors: 2

    • Vincent Dufrasnes (@ Chupsy)
    • vincent dufrasnes (vincentdufrasnes@vincent-dufrasnes)
from jimp GitHub release notes
Commit messages
Package name: jimp
  • e4d6af0 Bump version to: v0.16.2 [skip ci]
  • 29ac957 Update CHANGELOG.md [skip ci]
  • dad05fa Bump jpeg-js over 0.4.4 to avoid cve-2022-25851 (#1093)
  • 53ff9d1 docs: toc added for easier reading (#984)
  • 7d3fc67 added the "e" back to @ jimp/plugin-fisheye (#947)
  • 802918b feat: add handwritten.js project (#946)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs