twilio / twilio-video-diagnostics-react-app

A diagnostics tool that tests a participant's ability to have a quality video call. Built with the twilio-video.js SDK, RTC Diagnostics SDK, and React.js.
Apache License 2.0
40 stars 24 forks source link

[Snyk] Security upgrade cli-ux from 5.6.7 to 6.0.9 #68

Open twilio-product-security opened 4 months ago

twilio-product-security commented 4 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user. #### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **125/1000**
**Why?** Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5 | Uncontrolled resource consumption
[SNYK-JS-BRACES-6838727](https://snyk.io/vuln/SNYK-JS-BRACES-6838727) | Yes | No Known Exploit ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **125/1000**
**Why?** Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.08, Score Version: V5 | Inefficient Regular Expression Complexity
[SNYK-JS-MICROMATCH-6838728](https://snyk.io/vuln/SNYK-JS-MICROMATCH-6838728) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: cli-ux The new version differs by 40 commits.
  • 94a2dbf chore(release): 6.0.9 [ci skip]
  • 270efe3 fix: deprecate cli ux (#477)
  • 82449f0 chore(release): 6.0.8 [ci skip]
  • 0511944 fix(security): bump cli-progress
  • bab8a2b chore(release): 6.0.7 [ci skip]
  • ce8cec5 fix: bump @ oclif/core (#475)
  • 8c2ee67 Merge pull request #474 from oclif/dependabot-npm_and_yarn-typescript-4.5.4
  • 4358d81 chore(deps-dev): bump typescript from 4.5.2 to 4.5.4
  • e76b18c chore: sync dependabot.yml (#419)
  • 3889c2e ci: sync .circleci/config.yml (#470) [skip ci]
  • ed5d19f chore: fix url hyperlink test (#469)
  • cd4e665 Merge pull request #466 from oclif/dependabot-npm_and_yarn-axios-0.24.0
  • 7be5090 Merge pull request #467 from oclif/dependabot-npm_and_yarn-typescript-4.5.2
  • a2ae094 chore: replace instances of master with main [skip ci]
  • 474e88e chore: update author [skip ci]
  • 5ce5f19 chore: release as latest [skip ci]
  • 0b2017f chore(deps-dev): bump typescript from 4.4.3 to 4.5.2
  • ac0d7f6 chore(deps-dev): bump axios from 0.21.4 to 0.24.0
  • 21e8525 chore(release): 6.0.6 [ci skip]
  • 44eecd0 fix: bump deps and fix tests (#465)
  • 9da5c51 chore: add windows tests [skip ci]
  • 256325e chore(release): 6.0.5 [ci skip]
  • 2b8699d fix: bump deps (#462)
  • 641a2fb chore(dependabot): add versioning-strategy [skip ci]
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/twilio-47w/project/f7a2febd-12a9-482d-a6bb-b79c5f912b47?utm_source=github-enterprise&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/twilio-47w/project/f7a2febd-12a9-482d-a6bb-b79c5f912b47?utm_source=github-enterprise&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"52463c6a-2e15-48ac-887e-5a48da01e96b","prPublicId":"52463c6a-2e15-48ac-887e-5a48da01e96b","dependencies":[{"name":"cli-ux","from":"5.6.7","to":"6.0.9"}],"packageManager":"npm","projectPublicId":"f7a2febd-12a9-482d-a6bb-b79c5f912b47","projectUrl":"https://app.snyk.io/org/twilio-47w/project/f7a2febd-12a9-482d-a6bb-b79c5f912b47?utm_source=github-enterprise&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"upgrade":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[125,125],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Uncontrolled resource consumption](https://learn.snyk.io/lesson/redos/?loc=fix-pr)