jy95 / mediaScan

A scanner for media files that follows a user-provided naming convention
https://github.com/jy95/torrent-files-library
MIT License
10 stars 2 forks source link

[Snyk] Upgrade filehound from 1.16.3 to 1.17.6 #117

Closed jy95 closed 1 year ago

jy95 commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade filehound from 1.16.3 to 1.17.6.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **10 versions** ahead of your current version. - The recommended version was released **a year ago**, on 2022-04-24. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Directory Traversal
[SNYK-JS-MOMENT-2440688](https://snyk.io/vuln/SNYK-JS-MOMENT-2440688) | **375/1000**
**Why?** CVSS 7.5 | No Known Exploit | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-MOMENT-2944238](https://snyk.io/vuln/SNYK-JS-MOMENT-2944238) | **375/1000**
**Why?** CVSS 7.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: filehound
  • 1.17.6 - 2022-04-24

    Fixes #90 #91

      </li>
      <li>
        <b>1.17.5</b> - <a href="https://snyk.io/redirect/github/nspragg/filehound/releases/tag/v1.17.5">2021-09-21</a></br><ul>
  • Upgrade lodash, moment and bluebird

  • 1.17.4 - 2020-02-12
  •   <li>
        <b>1.17.3</b> - <a href="https://snyk.io/redirect/github/nspragg/filehound/releases/tag/v1.17.3">2019-07-16</a></br><ul>
  • Patch type definition for addFilter.
  • 1.17.2 - 2019-07-16
    • Patches TS definition for .create
  •   <li>
        <b>1.17.1</b> - <a href="https://snyk.io/redirect/github/nspragg/filehound/releases/tag/v1.17.1">2019-07-09</a></br><ul>
  • Add type declarations
  • 1.17.0 - 2019-01-28

    Addresses the following issues:
    #78
    #64

    Add support for configuring file info to be returned (with path).

  •   <li>
        <b>1.16.7</b> - <a href="https://snyk.io/redirect/github/nspragg/filehound/releases/tag/v1.16.7">2019-01-21</a></br><p>Add varargs support for <code>.glob</code></p>
      </li>
      <li>
        <b>1.16.5</b> - <a href="https://snyk.io/redirect/github/nspragg/filehound/releases/tag/v1.16.5">2018-12-04</a></br><p>fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="377109108" data-permission-text="Title is private" data-url="https://github.com/nspragg/filehound/issues/74" data-hovercard-type="issue" data-hovercard-url="/nspragg/filehound/issues/74/hovercard" href="https://snyk.io/redirect/github/nspragg/filehound/issues/74">#74</a></p>
      </li>
      <li>
        <b>1.16.4</b> - <a href="https://snyk.io/redirect/github/nspragg/filehound/releases/tag/v1.16.4">2018-06-06</a></br><ul>
  • Optimise matcher
  • 1.16.3 - 2018-05-01
    • Update deps
  • </ul>
    from <a href="https://snyk.io/redirect/github/nspragg/filehound/releases">filehound GitHub release notes</a>


    Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

    For more information:

    šŸ§ View latest project report

    šŸ›  Adjust upgrade PR settings

    šŸ”• Ignore this dependency or unsubscribe from future upgrade PRs