shenxianpeng / blog

Xianpeng Shen's Blog
http://shenxianpeng.github.io
GNU General Public License v3.0
1 stars 0 forks source link

[Snyk] Security upgrade hexo-renderer-ejs from 1.0.0 to 2.0.0 #40

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Remote Code Execution (RCE)
SNYK-JS-EJS-2803307
Yes Proof of Concept
Commit messages
Package name: hexo-renderer-ejs The new version differs by 13 commits.
  • 8dd9fda V2 (#45)
  • deabc8b chore(deps-dev): bump eslint from 7.32.0 to 8.1.0 (#49)
  • 5af7160 chore(deps-dev): bump mocha from 8.4.0 to 9.1.0 (#44)
  • 6beb035 Drop node 10 (#46)
  • 81c9307 Upgrade to GitHub-native Dependabot (#39)
  • 09cb553 chore(deps-dev): bump mocha from 7.2.0 to 8.0.1 (#38)
  • ddacbfd chore(deps-dev): bump eslint from 6.8.0 to 7.0.0 (#37)
  • 8c2415d chore(deps-dev): bump hexo-fs from 2.0.0 to 3.0.1 (#35)
  • 0b24ab5 chore(deps-dev): bump mocha from 6.2.3 to 7.1.2 (#36)
  • 5ab0f81 chore(deps-dev): bump nyc from 14.1.1 to 15.0.0 (#29)
  • 80c3ef3 chore(deps-dev): bump eslint-config-hexo from 3.0.0 to 4.0.0 (#28)
  • cc5e1b6 chore(deps): bump ejs from 2.7.4 to 3.0.1 (#26)
  • 2f17874 test: update to new include syntax (#27)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Remote Code Execution (RCE)

netlify[bot] commented 2 years ago

Deploy Preview for shenxianpeng-blog ready!

Name Link
Latest commit dd87539550a426f50e0d758d37c72b8b1542a5c6
Latest deploy log https://app.netlify.com/sites/shenxianpeng-blog/deploys/62e1f915d7c9c500088b0fec
Deploy Preview https://deploy-preview-40--shenxianpeng-blog.netlify.app
Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.