turkdevops / pusher-js

Pusher Javascript library
http://pusher.com
MIT License
0 stars 0 forks source link

[Snyk] Security upgrade karma-webpack from 4.0.2 to 5.0.0 #117

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 713/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.4
Prototype Pollution
SNYK-JS-JSON5-3182856
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: karma-webpack The new version differs by 33 commits.
  • 46a5505 Merge branch 'master' into next
  • 71fc63a fix(config): ignore entry options (#479)
  • 05cfa79 fix(docs): fixed warning inaccuracy (#478)
  • 1598fa6 fix(config): force default output.filename (#477)
  • d603679 change(readme): made minor adjustments (#476)
  • 5300200 refactor(*): break up into individual modules (#474)
  • 8ad09d1 fix(test): handle scenario test rejection (#473)
  • da86766 chore(release): 5.0.0-alpha.6
  • 98b3ec9 chore(deps): bump hotfix dependencies (#472)
  • ea5dc8e fix(preprocess): auto fix missing webpack framework (#471)
  • b044404 chore(test): refactored hash method into util (#470)
  • ea3dabe fix(controller): add entropy to default dir (#469)
  • 57b131e chore(test): fix testing on linux (#468)
  • 52ac365 chore(lint): fix linter settings (#467)
  • 6369729 feat(ci): added github workflow for testing (#464)
  • e8ad372 chore(test): set up integration testing (#461)
  • f7af31f chore(readme): add next tag to install command
  • 2cc5495 chore(readme): add info about webpack v5
  • a300178 chore(release): 5.0.0-alpha.5
  • 2e0ca74 chore(package): update peer dependency to webpack v5
  • 2e2ca3f chore(release): 5.0.0-alpha.4
  • 4fe1f60 chore(controller): change the webpack watch logic
  • 8d7366f chore: fix support for webpack v5
  • 3cc35b3 test(plugin): add tests to prevent some regressions (#419)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution