strugee / node-crawl-mf2

Crawl microformats2 data for h-entry and h-feeds
GNU Lesser General Public License v3.0
1 stars 1 forks source link

[Snyk] Upgrade microformat-node from 2.0.1 to 2.0.4 #6

Open strugee opened 5 months ago

strugee commented 5 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade microformat-node from 2.0.1 to 2.0.4.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **1 version** ahead of your current version. - The recommended version was released **21 days ago**, on 2024-04-16. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-NTHCHECK-1586032](https://snyk.io/vuln/SNYK-JS-NTHCHECK-1586032) | **482/1000**
**Why?** Proof of Concept exploit, CVSS 7.5 | Proof of Concept | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-CSSWHAT-3035488](https://snyk.io/vuln/SNYK-JS-CSSWHAT-3035488) | **482/1000**
**Why?** Proof of Concept exploit, CVSS 7.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: microformat-node
  • 2.0.4 - 2024-04-16
  • 2.0.1 - 2016-10-26

    Fixes and minnor upgrades to parsing

    • Updated to version v2.0.3 of microformats-shiv
      • Parse error in impliedDate rule #35
      • Include id fail parse issue #34

    Added PRs

    • Decoding entities #32
    • Change microformats-shiv to reference npm #31
    • Document baseUrl option #30
      </li>
    </ul>
    from <a href="https://snyk.io/redirect/github/glennjones/microformat-node/releases">microformat-node GitHub release notes</a>

Commit messages
Package name: microformat-node
  • 04fd04d fix: Added multipart: true to post endpoints
  • e0e7587 fix: removed bluebird, add ent-replace
  • b47fac0 fix: minnor update to readme
  • cd04315 fix: cheerio.load issue 2
  • 24ed2dc fix: cheerio.load issue
  • 53d2ab0 fixed: mocha tests with cheerio.load issue
  • 67a2732 fix: devDependencies updated
  • 432942c fix: updated cheerio and fix backcompat issue
  • de73ad0 fix: updated grunt modules
  • d80c6ae fix: updated hapi.js modules
  • d817ebf Updated handlebar module
  • df98eb3 Updated readme
  • ca334d3 v2.0.2
  • 1538e8a Readme correction
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs