snyk / vulncost

Find security vulnerabilities in open source npm packages while you code
MIT License
200 stars 34 forks source link

[Snyk] Upgrade: @babel/parser, @babel/traverse, @babel/types #59

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on
from 7.12.11 to 7.13.16
14 versions ahead of your current version 25 days ago
on 2021-04-20
from 7.12.12 to 7.13.17
6 versions ahead of your current version 24 days ago
on 2021-04-20
from 7.12.12 to 7.13.17
8 versions ahead of your current version 24 days ago
on 2021-04-20

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Command Injection
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept
Regular Expression Denial of Service (ReDoS)
Why? Proof of Concept exploit, CVSS 7.2
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @babel/parser
  • 7.13.16 - 2021-04-20

    v7.13.16 (2021-04-20)

    Thanks @ codyatwork and @ nwalters512 for your first PRs!

    👓 Spec Compliance

    • babel-parser
      • #13143 fix: raise SyntaxError for declare before getter/setter (@ fedeci)

    🐛 Bug Fix

    • babel-helpers, babel-plugin-transform-modules-commonjs, babel-plugin-transform-regenerator, babel-plugin-transform-spread, babel-preset-env, babel-runtime-corejs2, babel-runtime
    • babel-helper-compilation-targets
    • babel-generator

    📝 Documentation

    🏠 Internal

    • babel-helper-bindify-decorators, babel-helper-explode-class
      • #13160 Archive helper-explode-class and helper-bindify-decorators (@ JLHwung)
    • Other
    • babel-helper-call-delegate
    • babel-helper-hoist-variables, babel-plugin-transform-block-scoping
    • babel-cli, babel-core, babel-generator, babel-plugin-transform-function-name, babel-register, babel-types

    Committers: 7

  • 7.13.15 - 2021-04-08

    v7.13.15 (2021-04-08)

    👓 Spec Compliance

    • babel-parser
      • #13099 fix: raise SyntaxError for unparenthesized assert and assign (@ fedeci)
      • #13049 fix: the LHS in for-of loop should not start with let (@ JLHwung)

    🐛 Bug Fix

    • babel-parser
      • #13101 fix(ts): allow trailing comma after rest parameter in TSDeclareFunction (@ fedeci)
    • babel-plugin-proposal-do-expressions, babel-traverse
    • Other
      • #13106 fix: do not filter report from functions within class elements (@ JLHwung)
    • babel-compat-data, babel-preset-env

    💅 Polish

    📝 Documentation

    🏠 Internal

    • babel-plugin-transform-regenerator, babel-standalone
    • babel-helper-transform-fixture-test-runner

    🏃‍♀️ Performance

    Committers: 5

  • 7.13.13 - 2021-03-26

    v7.13.13 (2021-03-26)

    👓 Spec Compliance

    🐛 Bug Fix

    • babel-core
    • babel-core, babel-preset-env
    • babel-plugin-transform-react-constant-elements
      • #13054 fix: constant variables only enable constant react elements (@ cgood92)
    • babel-types
    • babel-node
    • babel-parser

    💅 Polish

    • babel-cli, babel-core

    🏠 Internal

    🏃‍♀️ Performance

    Committers: 8

  • 7.13.12 - 2021-03-22

    v7.13.12 (2021-03-22)

    Thanks @ hajnalbendeguz for your first PR!

    🐛 Bug Fix

    • babel-standalone
    • babel-plugin-bugfix-v8-spread-parameters-in-optional-chaining, babel-plugin-proposal-optional-chaining, babel-preset-env
      • #13009 Implement @ babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining (@ JLHwung)
    • babel-types
      • #12971 fix: do not throw when creating type annotation based on bigint (@ JLHwung)
    • babel-compat-data, babel-preset-env

    💅 Polish

    • babel-plugin-transform-react-jsx

    🏠 Internal

    Committers: 6

  • 7.13.11 - 2021-03-15

    v7.13.11 (2021-03-15)

    👓 Spec Compliance

    • babel-parser, babel-plugin-proposal-class-static-block

    🐛 Bug Fix

    • babel-compat-data
    • babel-parser
    • babel-compat-data, babel-helper-compilation-targets

    🔬 Output optimization

    • babel-helper-create-class-features-plugin, babel-plugin-proposal-async-generator-functions, babel-plugin-proposal-class-properties, babel-plugin-proposal-private-methods, babel-plugin-proposal-private-property-in-object, babel-plugin-transform-typescript, babel-preset-env

    Committers: 3

  • 7.13.10 - 2021-03-08
    Read more
  • 7.13.9 - 2021-03-01
    Read more
  • 7.13.4 - 2021-02-23
  • 7.13.0 - 2021-02-22
  • 7.12.17 - 2021-02-18
  • 7.12.16 - 2021-02-11
  • 7.12.15 - 2021-02-04
  • 7.12.14 - 2021-02-03
  • 7.12.13 - 2021-02-03
  • 7.12.11 - 2020-12-15
from @babel/parser GitHub release notes
Package name: @babel/traverse from @babel/traverse GitHub release notes
Package name: @babel/types from @babel/types GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs