omermorad / mockingbird

🐦 Decorator Powered TypeScript Library for Creating Mocks
MIT License
86 stars 5 forks source link

[Snyk] Security upgrade commitizen from 4.2.4 to 4.2.5 #142

Closed snyk-bot closed 1 year ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 506/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
Prototype Pollution
SNYK-JS-MINIMIST-2429795
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: commitizen The new version differs by 48 commits.
  • 0939910 ci(release): defined a github workflow to release with semantic-release (#923)
  • 757a806 chore(deps): update all non-major dependencies
  • 25dc80c fix: fix the "isFunction" utility to match both "asyncFunction"s and "Function"s (#927)
  • fc283fb chore(deps): update dependency semver to v7.3.7
  • c35a3c7 chore(deps): update all non-major dependencies
  • 69de704 fix(deps): update all non-major dependencies
  • e79f3ee chore(deps): update dependency @ babel/core to v7.17.8
  • 69689fb chore(deps): update all non-major dependencies to v7.17.7
  • 3c2553f fix(deps): update all non-major dependencies
  • 4118263 docs: add cz-git commitizen adapter (#905)
  • 70ca1f4 docs: adjust example to a valid husky prepare-commit-msg command (#908)
  • fcc85e5 docs(readme): match casing of tutorial's title
  • bcd9c73 docs(readme): fix dead link to tutorial
  • 941bf38 chore(deps): update all non-major dependencies
  • a3f4ffa chore(deps): update dependency @ babel/core to v7.17.2
  • 8f76acd chore(deps): update dependency node-fetch to 2.6.7 [security] (#902)
  • d4e39c6 chore(deps): update all non-major dependencies to v7.17.0
  • 056b0ed chore(deps): update all non-major dependencies (#891)
  • 5b2c458 chore: remove unused dev-dependency axios (#894)
  • 9c7e863 fix(deps): update dependency inquirer to v8 (#874)
  • 218d454 chore: remove unused Travis-CI config (#880)
  • f1cf649 chore(deps): update all non-major dependencies
  • dc7ac60 chore(deps): update all non-major dependencies
  • c6a2857 chore(deps): update dependency conventional-changelog-conventionalcommits to v4.6.2
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution