kogg / hovercards

HoverCards is a chrome extension that lets you see what's behind links from youtube, twitter, reddit, soundcloud, imgur, & instagram — all with out ever leaving the web page you're currently on.
http://hovercards.com
228 stars 33 forks source link

[Snyk] Security upgrade open-graph-scraper from 2.5.5 to 4.0.0 #294

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-LODASH-567746
Yes Proof of Concept
Commit messages
Package name: open-graph-scraper The new version differs by 182 commits.
  • abf357b Merge pull request #86 from jshemas/snyk-fix-1a8577adadc73627e636aead82586a7c
  • f4c98a5 fix: package.json, package-lock.json & .snyk to reduce vulnerabilities
  • 5ace9a1 Merge pull request #85 from jshemas/got
  • fc1df2d 4.0.0
  • 8572d2b updating twitch tests
  • 49821e0 adding more unit tests
  • 1a411ab remove old eslint rules
  • ac7d946 fixing unit test import
  • cb3cf11 move the run function into the index
  • b2f6d3f clean up readme
  • 38f03c1 we should not have to retry this test anymore
  • 6eca6d0 setting options.retry
  • 2b01681 adding a timeout for the statusCode tests
  • cfebfbb fixing twitch tests
  • c92adc2 adding another utf-8 test
  • 578b276 updating how ogs checks url if its a mp3 or pdf
  • 809a73c remove .only
  • f8a8a8d fixing that twitch test for real this time
  • f8f6df5 fixing twitch name
  • 49326f7 fixing eslint issues
  • 0b1b93a stop using mocha done()
  • 0566197 spliting up call/promise stuff in the run function
  • 5cefc16 adding new errors and clean up error messageing
  • 205779e adding status code tests
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic