nodeshift-archived / license-reporter

license-reporter is a tool that gathers licenses for project's dependencies and produces a output in XML, JSON, YAML and HTML format.
Apache License 2.0
13 stars 10 forks source link

[Snyk] Upgrade jest from 27.0.6 to 27.4.0 #411

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade jest from 27.0.6 to 27.4.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TMPL-1583443
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PROMPTS-1729737
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: jest from jest GitHub release notes
Commit messages
Package name: jest
  • 0dc6dde v27.4.0
  • c6b1ed8 chore: update changelog for release
  • 585beb6 docs: fix typos in CodeTransformation.md (#12034)
  • a3bc271 chore(CONTRIBUTING.md): recommend using node v16 (#12012)
  • 9e2c7b1 jest-worker: Unable to customize thread execArgv with enableThreadWorkers (#12069)
  • 2e6c217 fix(cli, config, docs): improve `mock` related cli messages, config template entries and documentation (#12047)
  • ee24dfc adding ts-jest mock util functions in jest-mock (#12089)
  • c739748 docs: Clarify setupFiles run order (#11641)
  • 9d14c5d fix: avoid unhandled promise rejections when concurrent tests fail (#11987)
  • 5cd75f4 Enhancing the `toHaveProperty` matcher to support array selection (#12092)
  • f8c6e75 Add `types` entry in export map (#12073)
  • ef25c46 docs: changed 'before' and 'after' ---> 'beforeAll' and 'afterAll' (#12065)
  • 7039cb1 docs: alphabetize cli options (#11586)
  • 2a5e515 Removed explicit type declarations (#12038)
  • a9a7c33 README.md: HTTP => HTTPS (#12063)
  • 7bc4a10 chore(jest-runner): Add info regarding timers to forceExited message (#12083)
  • 1f813fa docs(jest-matcher-utils): fix link (#12072)
  • 9947a2a fix(jest-config): add missing slash dependency (#12080)
  • 7bb400c replaced `substr` with `substring` (#12066)
  • 0486a3c chore: fix PnP test by forcing older version of typescript
  • 42b020f Remove cycle in printDiffs, diffLines and joinAlignedDiffs (#10818)
  • 7a34a69 Do not reset global.document before CustomElement:disconnectedCallbac… (#11871)
  • 8f2cdad fix(docs): add missing table of contents to The Jest Object documentation page (#12039)
  • 95f4969 Replaced module with namespace (#12018)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs