shopizer-ecommerce / shopizer-admin

MIT License
51 stars 142 forks source link

[Snyk] Security upgrade @biesbjerg/ngx-translate-extract from 2.3.4 to 7.0.3 #10

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 758/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-Y18N-1021887
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @biesbjerg/ngx-translate-extract The new version differs by 128 commits.
  • acdffe0 Merge branch 'master' of https://github.com/biesbjerg/ngx-translate-extract into master
  • 116133b Bump version 7.0.3
  • 50b2ca6 (chore) Update deps, allow newer version of typescript and angular compiler
  • b46a914 Update README.md
  • bc3e5fb fix typo
  • ea990d6 update deps, bump version
  • c60705d run prettier on code
  • 85cd1e4 fix(directive-parser) add support for bound attributes
  • 8afbb2f bump version
  • 329c24d update deps
  • a30a6f9 clean up some tests
  • 2adec54 fix(directive-parser) refactor + correct handling of whitespace
  • 619b3c5 fix(pipe-parser): add support for more sophisticated expressions that worked in version 4.2.0 with the regex based parser (#185)
  • 5e0da55 Add username to GitHub sponsors
  • 5f2eb2a Update package.json example scripts
  • 90b5979 Bump version to 6.0.4
  • deb6b23 Remove noUnusedLocals since they are removed by prettier on commit anyway
  • 17dec7d fix(npm-package): move typescript and angular to peer-dependencies (#183)
  • 71f4f42 Tests about support of HTML tags in translations keys with GetText (#172)
  • 73f39d6 add single quote rule
  • 3bf2aac Trim leading/trailing whitespace. Closes #175
  • 05d1917 Bump version 6.0.3
  • e50d520 Fix created vs replaced/merge message
  • cb8731e Bump version to 6.0.2
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic