nodeshift / opossum

Node.js circuit breaker - fails fast ⚡️
https://nodeshift.dev/opossum/
Apache License 2.0
1.33k stars 107 forks source link

[Snyk] Upgrade eslint-plugin-import from 2.27.5 to 2.29.1 #845

Closed lholmquist closed 7 months ago

lholmquist commented 11 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade eslint-plugin-import from 2.27.5 to 2.29.1.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **4 versions** ahead of your current version. - The recommended version was released **22 days ago**, on 2023-12-14. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Prototype Pollution
[SNYK-JS-JSON5-3182856](https://snyk.io/vuln/SNYK-JS-JSON5-3182856) | **427/1000**
**Why?** Proof of Concept exploit, CVSS 6.4 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: eslint-plugin-import
  • 2.29.1 - 2023-12-14

    Full Changelog: v2.29.0...v2.29.1

      </li>
      <li>
        <b>2.29.0</b> - <a href="https://snyk.io/redirect/github/import-js/eslint-plugin-import/releases/tag/v2.29.0">2023-10-23</a></br><p><strong>Full Changelog</strong>: <a class="commit-link" href="https://snyk.io/redirect/github/import-js/eslint-plugin-import/compare/v2.28.1...v2.29.0"><tt>v2.28.1...v2.29.0</tt></a></p>
      </li>
      <li>
        <b>2.28.1</b> - <a href="https://snyk.io/redirect/github/import-js/eslint-plugin-import/releases/tag/v2.28.1">2023-08-18</a></br><p><strong>Full Changelog</strong>: <a class="commit-link" href="https://snyk.io/redirect/github/import-js/eslint-plugin-import/compare/v2.28.0...v2.28.1"><tt>v2.28.0...v2.28.1</tt></a></p>
      </li>
      <li>
        <b>2.28.0</b> - 2023-07-28
      </li>
      <li>
        <b>2.27.5</b> - 2023-01-16
      </li>
    </ul>
    from <a href="https://snyk.io/redirect/github/import-js/eslint-plugin-import/releases">eslint-plugin-import GitHub release notes</a>


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

coveralls commented 11 months ago

Pull Request Test Coverage Report for Build 7423430323


Totals Coverage Status
Change from base Build 7034846062: 0.0%
Covered Lines: 374
Relevant Lines: 375

💛 - Coveralls
github-actions[bot] commented 10 months ago

This pull request is stale because it has been open 30 days with no activity.