oaeproject / 3akai-ux

Open Academic Environment (OAE) Front-End
http://www.oaeproject.org
Educational Community License v2.0
134 stars 206 forks source link

[Snyk] Security upgrade lerna from 3.16.4 to 3.18.0 #4236

Open snyk-bot opened 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-YARGSPARSER-560381
No Proof of Concept
Commit messages
Package name: lerna The new version differs by 42 commits.
  • 0ea8fb1 chore(release): v3.18.0
  • 31eff33 chore: reset lockfile
  • ccf32e1 feat(package-graph): Deprecate method `pruneCycleNodes()`
  • d4912c9 refactor(package-graph): Split classes into separate files
  • 31ad11e chore: Upgrade eslint + plugins
  • ec95403 feat: Remove unused @lerna/run-parallel-batches
  • d136fb5 feat: Remove unused @lerna/batch-packages
  • f2c3a92 feat(filter-options): Rename `--include-filtered-*` options
  • 73badee feat(filter-options): Use figgy-pudding in getFilteredPackages()
  • ff50e29 feat(filter-options): Add `--exclude-dependents` option
  • 54dca56 fix(bootstrap): Move all filter logging into get-filtered-packages method
  • a706023 feat(filter-options): Allow command to continue if no packages are matched (#2280)
  • 5e60213 feat: Upgrade to yargs@14
  • ac8385d fix(options): Explicit `--use-workspaces`
  • 6948a11 fix(options): Explicit `--force-local`
  • 1d9552c fix(options): Explicit `--pre-dist-tag`
  • 343a751 fix(options): Explicit `--force-publish`
  • f3581ae fix(options): Explicit `--conventional-prerelease`
  • f73e6ed fix(options): Explicit `--conventional-graduate`
  • efcb3bd fix(options): Explicit `--ignore-scripts`
  • fa21723 fix(options): Explicit `--ignore-prepublish`
  • f2c8ab3 test: Add prepublish to lifecycle leaf
  • 276682b chore: Add options argument to run-lifecycle mock
  • b822060 docs: Add `command.publish.registry` example (#2300)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

πŸ›  Adjust project settings

πŸ“š Read more about Snyk's upgrade and patch logic


This change is Reviewable