rangle / angular-ssr

Angular 4+ server-side rendering solution compatible with @angular/material, jQuery, and other libraries that touch the DOM (as well as providing a rich feature set!)
BSD 2-Clause "Simplified" License
279 stars 38 forks source link

[Snyk] Security upgrade npm from 4.6.1 to 5.0.1 #114

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NPMUSERVALIDATE-1019352
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: npm The new version differs by 241 commits.
  • 19397ad 5.0.1
  • 45b13d9 update AUTHORS
  • 25ebbb1 doc: update changelog for npm@5.0.1
  • 7e5ce87 pacote@2.7.26
  • f3cb84b docs: update cli usage for test command (#16771)
  • acbe85b view: wait until write completes to call cb (#16791)
  • dc2823a docs: package-lock.json is never allowed in tarballs (#16799)
  • 80ab521 deps: pull in dependency updates with bugfixes
  • e61e68d publish: adapt config for publish RegClient (#16762)
  • 9aac984 finalize: Guard against being unable to compute _requested source
  • 3cb8432 standard: minor linter fix
  • 9f81483 error-handler: remove unused argument (#16757)
  • c3e0b42 docs: preserve same name convention for command (#16296)
  • 6612623 ls: remove unused argument (#16756)
  • 923fd58 utils: Remove slow assertion from module-name util (#16749)
  • ebafe48 hamilton: Talk less, complete more (#16750)
  • 39495d0 5.0.0
  • 0d91907 doc: update changelog for npm@5.0.0
  • 8a173da docs: END OF AN ERA OF CHANGELOGS 😭
  • 794c10e pkglock: remove packageIntegrity field of doom
  • 674004c lifecycle: added prepack and postpack (#16725)
  • db76632 cacache@9.2.5
  • 0d35975 preinstall: Runs in the final dest, not the staging folder
  • a976fa1 pacote: more alwaysAuth logic
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic