shbatm / MMM-OnScreenMenu

MagicMirror² utility module that provides a simple on screen menu for control
MIT License
63 stars 22 forks source link

[Snyk] Security upgrade pm2 from 2.10.4 to 3.0.0 #33

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 748/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.1
Improper Privilege Management
SNYK-JS-SHELLJS-2332187
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: pm2 The new version differs by 200 commits.
  • 47eecb9 fix: README update + downgrade promptly
  • 5a17688 docs: update documentation, change monitor to monit
  • a082a5f docs: update documentation about new pm2 apm and metrics system
  • 29cccd9 Merge remote-tracking branch 'origin/development'
  • ca968cf Merge pull request #3728 from Unitech/release_3.0.0
  • 9cb24dd test: remove tests on http:transaction from apm, it was removed in apm 2.0.2
  • 2e91827 chore: upgrade pm2-io-apm to 2.0.2
  • 64c1ac8 Update README.md
  • 6392a38 chore: upgrade pm2-io-apm to 2.0.1 to fix https patching
  • b6e0650 Merge pull request #3734 from f-hj/development
  • 792cef8 Fix #3669
  • 6e3b45f chore: upgrade mocha to version 5
  • 9459937 chore: upgrades node modules
  • 66d5e06 chore: display active transport
  • dfd3d62 fix: format cpu usage at root
  • a3c2900 refactor: change default log date format
  • 439c373 chore: update readme with breaking changes
  • 829fcb3 chore: update version to 3.0.0
  • 09aacdc chore: upgrade module and version
  • df081ed Merge remote-tracking branch 'origin/master' into development
  • 0255c5a Merge pull request #3726 from soyuka/fix-list
  • d39a424 Fix cpu value for modules
  • a39eb4f Merge pull request #3725 from soyuka/fix-list
  • 623eb78 Fix pm2 list cpu display
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic