maikvandergaag / msft-extensions

Repository for extensions mainly used for Azure DevOps Extensions
https://msftplayground.com
MIT License
126 stars 80 forks source link

[Snyk] Upgrade azure-pipelines-task-lib from 4.4.0 to 4.13.0 #551

Open maikvandergaag opened 1 week ago

maikvandergaag commented 1 week ago

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to upgrade azure-pipelines-task-lib from 4.4.0 to 4.13.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **15 versions** ahead of your current version. - The recommended version was released on **24 days ago**. #### Issues fixed by the recommended upgrade: | | Issue | Score | Exploit Maturity | :-------------------------:|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | Prototype Pollution
[SNYK-JS-MOCKERY-3043117](https://snyk.io/vuln/SNYK-JS-MOCKERY-3043117) | **589** | No Known Exploit
Release notes
Package name: azure-pipelines-task-lib
  • 4.13.0 - 2024-05-27
  • 4.12.1 - 2024-05-22
  • 4.12.0 - 2024-05-02
  • 4.11.0 - 2024-04-11
  • 4.10.1 - 2024-03-18
  • 4.10.0 - 2024-02-26
  • 4.9.1 - 2024-02-15
  • 4.9.0 - 2024-01-30
  • 4.8.2 - 2024-01-22
  • 4.8.1 - 2024-01-18
  • 4.8.0 - 2024-01-16
  • 4.7.0 - 2023-11-09
  • 4.6.1 - 2023-10-12
  • 4.6.0 - 2023-09-19
  • 4.5.0 - 2023-08-29
  • 4.4.0 - 2023-06-16
from azure-pipelines-task-lib GitHub release notes
--- > [!IMPORTANT] > > - Check the changes in this PR to ensure they won't cause issues with your project. > - This PR was automatically created by Snyk using the credentials of a real user. > - Max score is 1000. Note that the real score may have changed since the PR was raised. --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs._ **For more information:** > - 🧐 [View latest project report](https://app.snyk.io/org/maikvandergaag/project/9d54e4a7-e40a-42a6-a6b2-2f93f6da989b?utm_source=github&utm_medium=referral&page=upgrade-pr) > - πŸ“œ [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates) > - πŸ›  [Adjust upgrade PR settings](https://app.snyk.io/org/maikvandergaag/project/9d54e4a7-e40a-42a6-a6b2-2f93f6da989b/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) > - πŸ”• [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/maikvandergaag/project/9d54e4a7-e40a-42a6-a6b2-2f93f6da989b/settings/integration?pkg=azure-pipelines-task-lib&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)