latticejs / lattice

Framework integration
17 stars 5 forks source link

[Snyk] Security upgrade systeminformation from 3.54.0 to 4.26.2 #435

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 651/1000
Why? Recently disclosed, Has a fix available, CVSS 7.3
Command Injection
SNYK-JS-SYSTEMINFORMATION-1023168
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: systeminformation The new version differs by 250 commits.
  • 26be10b 4.26.2
  • 3e54211 processes() memory leak fix, security issue fix
  • 5559591 smaller corections memory leak fix
  • bad372e improved shell sanitation
  • 1475505 Merge branch 'master' of https://github.com/sebhildebrandt/systeminformation
  • f89a2ec security fix exploits, memory leak fix
  • d4f29c9 4.26.1
  • 269b928 code cleanup
  • dc88096 4.26.0
  • 586065f merged get full S.M.A.R.T data, updated docs
  • 2db0a99 Merge pull request #368 from mily20001/feature/smartctl
  • bafcb0f 4.25.2
  • fd8e7ff getAllData() added wifiNetworks
  • 3fbd712 Merge branch 'master' of https://github.com/sebhildebrandt/systeminformation
  • 5f2beb7 getAllData() added wifiNetworks
  • b179560 4.25.1
  • d1e2146 get() minor bounds test fix, updated docs
  • bcdbf99 updated docs
  • e44e13e 4.25.0
  • 8fa0d30 get() added function to get partial system info
  • ba3469d 4.24.2
  • 8e783f2 cpu() fix BSD, networkStats() fix BSD
  • 1fd784f 4.24.1
  • 7715043 processes() fix parsing command and params
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic