theamazingfedex / owod-cs

A digital character sheet for the Old World of Darkness pen and paper games.
MIT License
2 stars 0 forks source link

[Snyk] Security upgrade serve from 11.0.0 to 12.0.0 #26

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Prototype Pollution
SNYK-JS-AJV-584908
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: serve The new version differs by 36 commits.
  • d941baa 12.0.0
  • 6341041 Breaking: Update `clipboardy` to v2.3.0 (drops support for Node 8, end of life) (#612)
  • 3281c57 Bump lodash from 4.17.19 to 4.17.21 (#654)
  • a85bd9d Add flag for disabling port switching (#579)
  • b71af1a Fix undefined local network address (#572)
  • e3fe70a Fix spacing for CORS documentation (#610)
  • 818b5e9 Add `-p` port flag to the help command output. (#607)
  • 61731b1 Update repo location in package.json to be vercel/serve (#641)
  • fbf6376 fix: Bump ajv to 6.12.6 (#635)
  • cd7dcf2 Bump ini from 1.3.5 to 1.3.7 (#638)
  • 850cc0b Bump lodash from 4.17.15 to 4.17.19 (#619)
  • c81f55c 11.3.2
  • f3ecedb Update Readme to use Vercel instead of Zeit
  • 059c852 Regenerate `yarn.lock` file
  • 04b42e7 Update `serve-handler` to v6.1.3
  • f65ac29 Document CORS option (#599)
  • 4ad704c 11.3.1
  • 03b7ebb Link to Vercel (#595)
  • b0f7134 Updated asset link (#596)
  • 6eac679 Bump acorn from 6.3.0 to 6.4.1 (#583)
  • f14e267 11.3.0
  • 6213de8 Add back `--cors` option (#527)
  • cbc6c4a 11.2.0
  • 9360686 Bumped `serve-handler` to the latest version (#559)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic