salesforce / akita

πŸš€ State Management Tailored-Made for JS Applications
https://salesforce.github.io/akita/
Apache License 2.0
3.7k stars 342 forks source link

[Snyk] Upgrade tslib from 2.4.0 to 2.4.1 #1043

Closed snyk-bot closed 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to upgrade tslib from 2.4.0 to 2.4.1.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
265/1000
Why? CVSS 5.3
No Known Exploit
Prototype Pollution
SNYK-JS-MINIMIST-2429795
265/1000
Why? CVSS 5.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: tslib from tslib GitHub release notes
Commit messages
Package name: tslib
  • 8acd4b3 Bump version to 2.4.1.
  • 5f7365e Remove extra line in generator.md
  • b1d38ee Fix early call to return/throw on generator (#186)
  • 4e27e9f Merge pull request #181 from microsoft/users/GitHubPolicyService/201dd6b7-4ca8-49f3-9744-61af1a7eb442
  • 7af3973 Microsoft mandatory file
  • 5bfaf87 Merge pull request #172 from microsoft/add-test-vite
  • a7129c7 Update bower.json
  • f541748 Drop node@10 from test matrix, add node@16
  • 8860d61 Add a test for vite
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

πŸ›  Adjust upgrade PR settings

πŸ”• Ignore this dependency or unsubscribe from future upgrade PRs