sverweij / mscgen_js

text => sequence charts
https://mscgen.js.org
GNU General Public License v3.0
207 stars 25 forks source link

[Snyk] Security upgrade codemirror from 5.58.0 to 5.58.2 #265

Closed snyk-bot closed 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-CODEMIRROR-1016937
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: codemirror The new version differs by 15 commits.
  • 23b7a99 Add WebAssembly to meta
  • 212bafa [stylus mode] Recognize "url-prefix" token properly
  • 9885241 [javascript mode] Don't indent in template strings
  • 9caacec [sparql mode] Improve parsing of IRI atoms
  • 55d0333 [javascript mode] Fix potentially-exponential regexp
  • cdb228a Fix horizontal scrolling-into-view with non-fixed gutters
  • 1cb6de2 Fix doc/releases.html copy-paste mistake
  • 719a912 Fixes #6402. Adds option to turn off highlighting of non-standard CSS properties
  • 8bc57f7 Remove link to gitter room
  • fdc2de3 [tern demo] Use unpkg, now that the URL structure of ternjs.net changed
  • 58c5534 Fixes #6331. Backticks are stripped from SQL query words before comparison
  • f3dde7c [julia mode] Fix infinite recursion
  • 1c60749 Mark version 5.58.1
  • ca046d7 [placeholder addon] Fix composition handling
  • c74a1ca Fix use of ES6 in addon
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

sverweij commented 4 years ago

need to unconfigure this