julesbonnard / afpnews-deck

My dream reader for AFP feeds
https://afpdeck.app
0 stars 4 forks source link

[Snyk] Security upgrade afpnews-api from 1.12.5 to 1.13.1 #102

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NODEFETCH-2964180
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: afpnews-api The new version differs by 9 commits.
  • d8cd8cc fix package lock with node v16
  • 7e8b81c fix test with multiple languages
  • ab72be4 update version
  • 4727cff Update deps, refactor multilanguages to simplify request, add fields, switch node-fetch with cross-fetch
  • 3c695e7 fix eslint config
  • c479fb7 conditionnal loading fetch for umd package
  • af21305 update deps
  • c2bea4e update deps
  • a4a4c02 update deps
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

vercel[bot] commented 2 years ago

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Updated
afpnews-deck ✅ Ready (Inspect) Visit Preview Sep 1, 2022 at 1:25AM (UTC)