shellscape / webpack-command

A superior CLI experience for webpack. Modular and opinionated.
MIT License
2 stars 1 forks source link

[Snyk] Security upgrade meow from 5.0.0 to 6.1.0 #3

Closed snyk-bot closed 3 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-YARGSPARSER-560381
Yes Proof of Concept
Commit messages
Package name: meow The new version differs by 27 commits.
  • 2954ed2 6.1.0
  • 3f331d9 Meta tweaks
  • 4527b45 Update `yargs-parser` dependency (#137)
  • f17525e 6.0.1
  • 16640f1 Replace `minimist-options` types with own ones (#135)
  • 5975fe6 6.0.0
  • 3e05a2e Add type information for flags (#122)
  • 499d186 Update dependencies
  • 5ef9478 Add support for `number` flag type (#103)
  • 8e5248e Fix typo (#121)
  • cd29865 Only consider enabling autoHelp/autoVersion in case there is only one argument in `process.argv` (#114)
  • 54e1f22 Tidelift tasks
  • 47fe20f Create funding.yml
  • 927e6e8 Add Node.js 12 to testing (#118)
  • 167d1ec Update dependencies, refactor TypeScript definition to CommonJS compatible export (#117)
  • fd537b8 Update dependencies
  • f1036df Add TypeScript definition (#116)
  • f36715c Remove flag's aliases from the `flags` property (#108)
  • 646f30b Fix Travis
  • 439ac9b Fix docs regarding meow arguments
  • cd635d4 Require Node.js 8
  • 2bcfee7 Add `hardRejection` option
  • f60c26e Switch from `loud-rejection` to `hard-rejection`
  • 89f8983 Minor code tweaks
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic