shbatm / MMM-OnScreenMenu

MagicMirror² utility module that provides a simple on screen menu for control
MIT License
62 stars 22 forks source link

[Snyk] Security upgrade pm2 from 2.10.4 to 4.0.0 #31

Open shbatm opened 3 years ago

shbatm commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: pm2 The new version differs by 250 commits.
  • e24fc12 pm2@4.0.0
  • 4c55d83 fix: test dependency
  • 8f954d0 pm2@4.0.0
  • ecfcf5d Merge pull request #4436 from niftylettuce/master
  • ff5d3be feat: added Lad to framework list
  • 4e933d2 pm2@4.0.0-beta-9
  • 869b1d3 chore: drop ADVANCED_README.md
  • 2c7765d Merge pull request #4391 from ykolbin/migrate-pm2-cli
  • 5b2f15f fix: adapt new pm2 register flow
  • 7d6ffef chore: upgrade pm2/io and chokidar
  • 01b2949 pm2@4.0.0-beta-8
  • daca87c Merge pull request #4377 from RiaanWest/fix/lodash-version
  • 474ac37 Merge pull request #4392 from mib008/patch/issue_4378
  • 76dfc07 fix: add property 'type' for compatible with old version.
  • 886c5c5 fix: remove garbage whitespace.
  • 5676974 refactor: Simplify bin/pm2 and move content to lib/binaries/CLI.js
  • f59911e fix: update lodash version
  • 21af03f chore: update README
  • 6bbee22 chore: change link
  • e44ac95 chore: upgrade logo
  • 9389dfe chore: upgrade systeminformation
  • 0c79406 Update package.json
  • cf20f15 chore: upgrade async to 3.1
  • 359c8c2 docs: update info links
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic