scrapd / scrapdviz

Visualize Austin traffic fatalities from another angle
https://viz.scrapd.org
MIT License
1 stars 10 forks source link

[Snyk] Security upgrade lighthouse-ci from 1.10.1 to 1.13.0 #233

Closed snyk-bot closed 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: lighthouse-ci The new version differs by 27 commits.
  • 51cd27d 1.13.0
  • c87c46c Update Readme
  • 0fb07c3 Refactoring
  • 476e9c7 Update report-generator
  • 3f6d6e7 Bump lighthouse to v8
  • 1205b07 Update copyright
  • c4e5d3c 1.12.0
  • 67727ef Add timing budget documetation
  • 60654dc Support timing budgets (#81)
  • 3ffcfdb feat(calculate-results): Add better failure messages (#80)
  • 6fb9d9f 1.11.0
  • 31a280f chore(package.json): Bump dependencies (#79)
  • 280a8bb chore(package.json): Update dev Dependencies (#78)
  • b303e05 chore(README): Switching to main branch (#77)
  • f613659 feat(lighthouse-reporter): Better reports (#76)
  • f14979c Add @ Remi-p as a contributor
  • dd9b04d Add @ marcschaller as a contributor
  • caaf11f test: ensure that the `reporter` is working correctly (#72)
  • 026066a fix: correct arguments order for `launchChromeAndRunLighthouse` function (#71)
  • 913a722 Update Node version in Travis
  • 113528c 1.10.3
  • f682a19 "fix(package.json): Set Node 10.13 as minimum supported version
  • af55678 "fix(xo): Fix XO errors"
  • 2ba13b6 "fix(core): Remove Snyk from direct dependencies
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic