raindigi / cloudcannon-suite

:couch_and_lamp: An opinionated set of tools to build and maintain static sites
https://suite.cloudcannon.com/
0 stars 0 forks source link

[Snyk] Security upgrade browser-sync from 2.26.4 to 2.27.10 #123

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-ASYNC-2441827
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: browser-sync The new version differs by 115 commits.
  • f6965a6 v2.27.10
  • e6c7bed Updated portscanner to 2.2.0 (#1960)
  • 6a587ec fix readme's
  • 91258ae Merge branch 'browser-sync-1946-esbuild'
  • f48d6b4 👋 app veyor
  • 30c24dc Merge pull request #1947
  • 9d24de5 drop webpack from UI
  • 7a00341 build client with esbuild
  • c30868a v2.27.9
  • 9b5fcdc fix(cli): Where's the command help? fixes #1929 (#1945)
  • 8840282 v2.27.8
  • 58ab4ab more version bumps + github actions (#1940)
  • 6e8d2b2 Merge pull request #1936 from lachieh/socket-io-upgrade
  • e909447 update browser-sync-client ts version
  • daa8cd0 restore test setting
  • 3c5777a Upgrade to latest version of socket.io. Fixes #1847
  • a7c14c8 v2.27.7
  • 40ebbd8 fixes #1916
  • e557aac v2.27.6
  • 6976fe9 v2.27.5
  • 8ba1c17 updated lockfile format
  • c99273c Merge pull request #1915 from iwt-philipzeh/fix/ua-parser-version-security
  • 6648032 security-patches
  • c2bc05d Merge pull request #1738 from davezuko/patch-1
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution