Open snyk-bot opened 2 years ago
*Ruff* :dog: I wasn't able to find any Docker Compose files in your repository at any of the given paths in the pull-dog.json
configuration file, or the default docker-compose.yml
file :weary: Make sure the given paths are correct.
Files checked:
docker-compose.yml
:warning: We detected 1 security issue in this pull request:
Mode: paranoid | Total findings: 1 | Considered vulnerability: 1
👉 Go to the dashboard for detailed results.
📥 Happy? Share your feedback with us.
Snyk has created this PR to upgrade grunt from 1.3.0 to 1.5.1.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
npm:underscore.string:20170908
Why? CVSS 7.5
SNYK-JS-ASYNC-2441827
Why? CVSS 7.5
SNYK-JS-GRUNT-2635969
Why? CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: grunt
v1.5.0...v1.5.1
v1.4.1...v1.5.0
v1.4.0...v1.4.1
v1.3.0...v1.4.0
safeLoad
for loading YML files viafile.readYAML
. e350ceav1.2.1...v1.3.0
Commit messages
Package name: grunt
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs