sheerun / prettier-standard

Formats with Prettier and lints with ESLint+Standard! (✿◠‿◠)
MIT License
868 stars 44 forks source link

[Snyk] Security upgrade prettierx from 0.11.3 to 0.18.0 #118

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: prettierx The new version differs by 250 commits.
  • ec29f1c prettierx: version 0.18.0
  • 5749c8b prettierx: update yarn.lock --dev (#519)
  • c5ef079 prettierx: update dependencies notes in package.json
  • faf2593 prettierx: tslib back to 1.14.1
  • ca0120d prettierx: Update eslint-plugin-unicorn -> 29.0.0 - devDependency (#510)
  • 44343c4 prettierx: Update tslib -> 2.2.0 - dependency (#515)
  • 66f3499 build(deps): bump node-fetch from 2.1.2 to 2.6.1 in /scripts/release (#374)
  • aa12c04 prettierx: remove Prettier website code
  • 3c88783 prettierx: Update resolve -> 1.20.0 - dependency (#465)
  • bb0d7f3 prettierx: no code coverage in GitHub action
  • 4be76fe prettierx: Update rollup -> 2.45.1 - devDependency (#507)
  • af9e719 prettierx: Update semver -> 7.3.5 - dependency (#508)
  • 148baca prettierx: Update postcss-less -> 4.0.1 - dependency (#487)
  • 9ac0586 prettierx: Update mem -> 8.1.0 - dependency (#486)
  • d2ea597 prettierx: Update globby -> 11.0.3 - dependency (#499)
  • 70a73ff prettierx: Update diff -> 5.0.0 - dependency (#482)
  • 98aa7b3 prettierx: Update ci-info -> 3.1.1 - dependency (#480)
  • d1d4b76 prettierx: update @ babel/code-frame -> 7.12.13 (...)
  • e9a1092 prettierx: update jest-watch-typeahead -> 0.6.2 --dev
  • a9fa6f3 prettierx: update eslint-plugin-react -> 7.23.2 --dev
  • abad553 prettierx: update eslint -> 7.24.0 --dev
  • de86fb3 prettierx: update @ babel/preset-env -> 7.13.15 --dev
  • e984cf9 prettierx: update @ babel/core -> 7.13.15 --dev
  • 35e38a3 prettierx: Update tempy -> 1.0.1 - devDependency (#491)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic