snyk / vulncost

Find security vulnerabilities in open source npm packages while you code
https://marketplace.visualstudio.com/items?itemName=snyk-security.vscode-vuln-cost
MIT License
200 stars 34 forks source link

[Snyk] Upgrade: @babel/parser, @babel/traverse, @babel/types #59

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on
@babel/parser
from 7.12.11 to 7.13.16
14 versions ahead of your current version 25 days ago
on 2021-04-20
@babel/traverse
from 7.12.12 to 7.13.17
6 versions ahead of your current version 24 days ago
on 2021-04-20
@babel/types
from 7.12.12 to 7.13.17
8 versions ahead of your current version 24 days ago
on 2021-04-20

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Command Injection
SNYK-JS-LODASH-1040724
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
467/1000
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @babel/parser
  • 7.13.16 - 2021-04-20

    v7.13.16 (2021-04-20)

    Thanks @ codyatwork and @ nwalters512 for your first PRs!

    👓 Spec Compliance

    • babel-parser
      • #13143 fix: raise SyntaxError for declare before getter/setter (@ fedeci)

    🐛 Bug Fix

    • babel-helpers, babel-plugin-transform-modules-commonjs, babel-plugin-transform-regenerator, babel-plugin-transform-spread, babel-preset-env, babel-runtime-corejs2, babel-runtime
    • babel-helper-compilation-targets
    • babel-generator

    📝 Documentation

    🏠 Internal

    • babel-helper-bindify-decorators, babel-helper-explode-class
      • #13160 Archive helper-explode-class and helper-bindify-decorators (@ JLHwung)
    • Other
    • babel-helper-call-delegate
    • babel-helper-hoist-variables, babel-plugin-transform-block-scoping
    • babel-cli, babel-core, babel-generator, babel-plugin-transform-function-name, babel-register, babel-types

    Committers: 7

  • 7.13.15 - 2021-04-08

    v7.13.15 (2021-04-08)

    👓 Spec Compliance

    • babel-parser
      • #13099 fix: raise SyntaxError for unparenthesized assert and assign (@ fedeci)
      • #13049 fix: the LHS in for-of loop should not start with let (@ JLHwung)

    🐛 Bug Fix

    • babel-parser
      • #13101 fix(ts): allow trailing comma after rest parameter in TSDeclareFunction (@ fedeci)
    • babel-plugin-proposal-do-expressions, babel-traverse
    • Other
      • #13106 fix: do not filter report from functions within class elements (@ JLHwung)
    • babel-compat-data, babel-preset-env

    💅 Polish

    📝 Documentation

    🏠 Internal

    • babel-plugin-transform-regenerator, babel-standalone
    • babel-helper-transform-fixture-test-runner

    🏃‍♀️ Performance

    Committers: 5

  • 7.13.13 - 2021-03-26

    v7.13.13 (2021-03-26)

    👓 Spec Compliance

    🐛 Bug Fix

    • babel-core
    • babel-core, babel-preset-env
    • babel-plugin-transform-react-constant-elements
      • #13054 fix: constant variables only enable constant react elements (@ cgood92)
    • babel-types
    • babel-node
    • babel-parser

    💅 Polish

    • babel-cli, babel-core

    🏠 Internal

    🏃‍♀️ Performance

    Committers: 8

  • 7.13.12 - 2021-03-22

    v7.13.12 (2021-03-22)

    Thanks @ hajnalbendeguz for your first PR!

    🐛 Bug Fix

    • babel-standalone
    • babel-plugin-bugfix-v8-spread-parameters-in-optional-chaining, babel-plugin-proposal-optional-chaining, babel-preset-env
      • #13009 Implement @ babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining (@ JLHwung)
    • babel-types
      • #12971 fix: do not throw when creating type annotation based on bigint (@ JLHwung)
    • babel-compat-data, babel-preset-env

    💅 Polish

    • babel-plugin-transform-react-jsx

    🏠 Internal

    Committers: 6

  • 7.13.11 - 2021-03-15

    v7.13.11 (2021-03-15)

    👓 Spec Compliance

    • babel-parser, babel-plugin-proposal-class-static-block

    🐛 Bug Fix

    • babel-compat-data
    • babel-parser
    • babel-compat-data, babel-helper-compilation-targets

    🔬 Output optimization

    • babel-helper-create-class-features-plugin, babel-plugin-proposal-async-generator-functions, babel-plugin-proposal-class-properties, babel-plugin-proposal-private-methods, babel-plugin-proposal-private-property-in-object, babel-plugin-transform-typescript, babel-preset-env

    Committers: 3

  • 7.13.10 - 2021-03-08
    Read more
  • 7.13.9 - 2021-03-01
    Read more
  • 7.13.4 - 2021-02-23
  • 7.13.0 - 2021-02-22
  • 7.12.17 - 2021-02-18
  • 7.12.16 - 2021-02-11
  • 7.12.15 - 2021-02-04
  • 7.12.14 - 2021-02-03
  • 7.12.13 - 2021-02-03
  • 7.12.11 - 2020-12-15
from @babel/parser GitHub release notes
Package name: @babel/traverse from @babel/traverse GitHub release notes
Package name: @babel/types from @babel/types GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs