reactioncommerce / api-plugin-products

Products plugin for the Reaction API
GNU General Public License v3.0
3 stars 22 forks source link

[Snyk] Upgrade @reactioncommerce/api-utils from 1.14.3 to 1.16.0 #23

Closed snyk-bot closed 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade @reactioncommerce/api-utils from 1.14.3 to 1.16.0.

merge advice As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090602
336/1000
Why? Recently disclosed, CVSS 5.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090601
336/1000
Why? Recently disclosed, CVSS 5.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090600
336/1000
Why? Recently disclosed, CVSS 5.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VALIDATOR-1090599
336/1000
Why? Recently disclosed, CVSS 5.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @reactioncommerce/api-utils from @reactioncommerce/api-utils GitHub release notes
Commit messages
Package name: @reactioncommerce/api-utils
  • cdea087 Merge pull request #54 from CatalinBoiangiu/patch-1
  • de281ce feat: Add RON currency
  • 88f4639 Merge pull request #58 from dineshdb/patch-1
  • 27e45dd feat: Add Nepali Currency definition
  • 3747255 Merge pull request #50 from reactioncommerce/dependabot/npm_and_yarn/lodash-4.17.19
  • 7ca1142 chore(deps): Bump lodash from 4.17.15 to 4.17.19
  • 3dc93ca Merge pull request #59 from reactioncommerce/dependabot/npm_and_yarn/npm-6.14.8
  • c7344d1 chore(deps): Bump npm from 6.14.4 to 6.14.8
  • f769070 Merge pull request #56 from reactioncommerce/dependabot/npm_and_yarn/node-fetch-2.6.1
  • 330ab3f chore(deps): Bump node-fetch from 2.6.0 to 2.6.1
  • 5b32c00 Merge pull request #43 from reactioncommerce/snyk-upgrade-f08227d8f5e7f7f0c1283b087c6592cb
  • 3acbb20 fix: upgrade transliteration from 2.1.8 to 2.1.9
  • 5575bdd Merge pull request #46 from reactioncommerce/fix-45-mikemurray-aggregate-offset-pagination
  • 05626dc test: ensure skip comes before limit
  • c8ed0af fix: update pipelines to fix pagination
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

πŸ›  Adjust upgrade PR settings

πŸ”• Ignore this dependency or unsubscribe from future upgrade PRs