snyk / vulncost

Find security vulnerabilities in open source npm packages while you code
https://marketplace.visualstudio.com/items?itemName=snyk-security.vscode-vuln-cost
MIT License
200 stars 34 forks source link

[Snyk] Upgrade: @babel/parser, @babel/traverse, @babel/types #52

Closed snyk-internal-pr-bot closed 3 years ago

snyk-internal-pr-bot commented 3 years ago

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on
@babel/parser
from 7.12.11 to 7.12.14
2 versions ahead of your current version 21 days ago
on 2021-02-03
@babel/traverse
from 7.12.12 to 7.12.13
1 version ahead of your current version 22 days ago
on 2021-02-03
@babel/types
from 7.12.12 to 7.12.13
1 version ahead of your current version 22 days ago
on 2021-02-03

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Command Injection
SNYK-JS-LODASH-1040724
539/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.2
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
539/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.2
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @babel/parser
  • 7.12.14 - 2021-02-03

    v7.12.14 (2021-02-03)

    Thanks @ fedeci for the quick regression fix! (#12745)

    🐛 Bug Fix

    • babel-parser
      • #12748 fix(ts): allow abstract methods with export default abstract class (@ fedeci)

    🏠 Internal

    • babel-core

    Committers: 2

  • 7.12.13 - 2021-02-03

    v7.12.13 (2021-02-03)

    Thanks @ bradzacher, @ bz2, @ ChALkeR, @ FauxFaux, @ fedeci, @ karansapolia, @ panzarino, @ shrinktofit, and @ Zalathar for your first PRs!

    👓 Spec Compliance

    • babel-parser
      • #12661 spec: disable await binding identifier within static block (@ JLHwung)
    • babel-helper-create-class-features-plugin, babel-helpers, babel-plugin-proposal-private-methods, babel-runtime-corejs2, babel-runtime-corejs3, babel-runtime
      • #12689 fix: throw error when accessing private method without a getter (@ fedeci)
    • babel-plugin-transform-computed-properties, babel-plugin-transform-shorthand-properties

    🐛 Bug Fix

    • babel-plugin-proposal-class-properties, babel-traverse
    • babel-plugin-proposal-class-properties, babel-plugin-transform-classes
    • babel-parser, babel-template
      • #12725 Permit %%placeholder%% in left-hand-side of a let declaration (@ Zalathar)
    • babel-core, babel-helper-transform-fixture-test-runner, babel-register
    • babel-parser
    • babel-helpers, babel-plugin-transform-classes
    • babel-generator
      • #12653 fix: avoid line breaks between class members head and key (@ JLHwung)
    • babel-register
    • babel-node
    • babel-types
    • babel-plugin-transform-modules-systemjs
    • babel-plugin-transform-for-of
    • babel-helper-create-class-features-plugin, babel-helper-replace-supers, babel-plugin-transform-classes
      • #12544 Correctly access shadowed class binding in super.* (@ Zzzen)
    • babel-helper-module-imports, babel-plugin-transform-react-jsx-development, babel-plugin-transform-react-jsx

    💅 Polish

    • babel-helper-transform-fixture-test-runner, babel-parser, babel-preset-env
      • #12716 refactor: raise AwaitNotInAsyncContext when an AwaitExpression will be parsed (@ JLHwung)
    • babel-cli, babel-core, babel-parser
    • babel-helper-create-class-features-plugin, babel-plugin-proposal-private-methods
    • babel-helper-compilation-targets, babel-preset-env
    • babel-code-frame

    📝 Documentation

    🏠 Internal

    • babel-traverse, babel-types
    • babel-register
    • Other
    • babel-generator, babel-preset-env
    • babel-core, babel-helper-compilation-targets, babel-plugin-transform-classes, babel-plugin-transform-function-name, babel-plugin-transform-parameters, babel-plugin-transform-regenerator, babel-preset-env

    🔬 Output optimization

    • babel-plugin-transform-modules-commonjs, babel-plugin-transform-template-literals, babel-plugin-transform-unicode-escapes, babel-preset-env
    • babel-plugin-transform-react-jsx
      • #12557 Optimize jsx spreads of object expressions (@ bz2)

    Committers: 22

  • 7.12.11 - 2020-12-15
    Read more
from @babel/parser GitHub release notes
Package name: @babel/traverse from @babel/traverse GitHub release notes
Package name: @babel/types from @babel/types GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs