kogg / hovercards

HoverCards is a chrome extension that lets you see what's behind links from youtube, twitter, reddit, soundcloud, imgur, & instagram — all with out ever leaving the web page you're currently on.
http://hovercards.com
227 stars 35 forks source link

[Snyk] Security upgrade open-graph-scraper from 2.5.5 to 3.5.1 #295

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Prototype Pollution
SNYK-JS-AJV-584908
Yes No Known Exploit
Commit messages
Package name: open-graph-scraper The new version differs by 116 commits.
  • 3c7d213 3.5.1
  • 8131254 fixing deps issues
  • 59a9ef4 backing down the version of eslint so that still works with node4
  • 5a86ba8 backing down the version of NYC so it still works with node4
  • 1603145 updating changelog
  • 4d2d9d2 updating dependencies
  • e839f4a fixing tests
  • bf7976d Merge pull request #67 from jshemas/snyk-fix-tjm6yj
  • 9465fea fix: package.json to reduce vulnerabilities
  • b856aa0 3.5.0
  • 6251d21 updating change log
  • 2c8bc88 Merge pull request #66 from karlsander/master
  • 84ba730 3.4.0
  • 07c4d3c updating change log
  • 352788b fixing tests
  • f3a5acb Merge pull request #64 from xr/master
  • ddd71c5 add tests for music:* tags and spotify
  • 596270c fix typo and some "multiple" values in music:album:* fields
  • a9588fc don't delete fields with "multiple: true" that are not processed as media
  • 2864c3c add music:song to media array logic
  • c2d0736 add music fields
  • 6a6a2aa update changed page title in test 'Valid Call - Test Name Cheap Page That Dose Not Have content-type=text/html - Should Return correct Open Graph Info'
  • ff8792a Global cookie jar disabled by default
  • fd92ae7 Merge pull request #62 from jshemas/es5
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic