toddmotto / echo

Lazy-loading images with data-* attributes
http://toddmotto.com/labs/echo
3.72k stars 504 forks source link

[Snyk] Fix for 1 vulnerabilities #145

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: gulp The new version differs by 98 commits.
  • edcf732 3.8.7
  • c186ce8 update gulp-util for new errors
  • d191c26 Merge pull request #608 from megakote/patch-3
  • 917a965 Fixed recipes for new browserify/watchify
  • e74b89b Fixed recipes for new browserify/watchify
  • 1bf9abc Merge pull request #604 from samccone/sjs/remove
  • f5ff2cf Remove explitive in gulp src
  • ac2175d Merge pull request #598 from pkozlowski-opensource/patch-2
  • 2fcf180 fix markdown formatting for the "silent" option
  • 3a62b2b add silent docs
  • 01cd087 Merge pull request #595 from pkozlowski-opensource/patch-1
  • cce8dd2 update URL to the search plugins site
  • 39178a2 Merge pull request #588 from CaryLandholt/master
  • 8564ca2 Merge pull request #589 from shakyShane/master
  • 761398e Docs: return stream & fix syntax highlighting
  • 38984e5 Add "Gulp-The Basics" screencast in documentation
  • 8fdf0ab clean up code for #587 close
  • c61c245 log unknown errors. closes #587
  • 3848327 Merge pull request #567 from AntouanK/add-new-recipe
  • 9e80e69 One var per line
  • cc0c5c7 change promises to event-stream
  • 1810a73 Merge pull request #585 from fcambus/master
  • 1390d31 Adding "Building With Gulp" article in documentation
  • 6833ab1 Merge pull request #582 from appleboy/patch
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic