kevinuulong / link-shortener

A serverless URL shortener using Airtable.
https://link.kevinuulong.com
MIT License
2 stars 0 forks source link

[Snyk] Security upgrade netlify-cli from 6.13.2 to 12.2.11 #14

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Open Redirect
SNYK-JS-GOT-2932019
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: netlify-cli The new version differs by 250 commits.
  • 743b4d6 chore(main): release 12.2.11 (#5310)
  • acdcbb6 fix: allow for in-source-config internal edge functions in proxy (#5311)
  • 6214768 fix(deps): update dependency @ netlify/edge-bundler to v6 (#5308)
  • a49e5fc fix(deps): update dependency @ netlify/build to v29 (#5297)
  • 35123df chore: migrate more to ESM (#5298)
  • e65f97c chore(main): release 12.2.10 (#5300)
  • 0041559 chore(deps): update vitest monorepo to v0.25.6 (#5306)
  • 345ce9c chore(deps): update dependency vite to v3.2.5 (#5305)
  • 62930d8 fix: always look for internal edge functions (#5302)
  • 869c5a8 fix: discard edge function declarations without a path or pattern (#5299)
  • 990da12 chore(main): release 12.2.9 (#5287)
  • ff1eecb fix(deps): update dependency @ netlify/edge-bundler to ^5.3.1 (#5296)
  • 38f548f chore(deps): bump express from 4.17.2 to 4.18.2 in /site (#5295)
  • 26c409d chore: introduce vitests for tests (#5269)
  • 57ee933 fix: detect requests without body correctly (#5290)
  • fd7db45 fix(deps): update dependency @ types/node to v14.18.34 (#5292)
  • be5098e chore(deps): update dependency supertest to v6.3.2 (#5291)
  • d3be8a1 chore(deps): bump decode-uri-component in /tests/integration/hugo-site (#5289)
  • 90a357d chore(deps): bump engine.io and browser-sync (#5258)
  • 67e4e39 chore(deps): bump decode-uri-component from 0.2.0 to 0.2.2 in /site (#5288)
  • fb6d84a fix(deps): update dependency cron-parser to v4.7.0 (#5273)
  • bd03505 chore: trim snapshots so newlines at the end do not fail tests (#5285)
  • 82a2824 chore(main): release 12.2.8 (#5274)
  • c788701 fix(deps): update dependency @ netlify/edge-bundler to v5 (#5284)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Open Redirect