twilio / twilio-voice-notification-app

Reference app built in ReactJS that demonstrates how to leverage Twilio Programmable Voice and Twilio SDKs to create a voice notification system.
Apache License 2.0
36 stars 26 forks source link

[Snyk] Fix for 1 vulnerabilities #28

Closed snyk-bot closed 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 758/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-Y18N-1021887
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: mocha The new version differs by 221 commits.
  • afe8daa Release v8.2.0
  • 20d3d4c update CHANGELOG for v8.2.0 [ci skip]
  • 932c09a fix scripts/linkify-changelog to not blast fenced code blocks
  • 3b333ec chore(deps): chokidar@3.4.3
  • 058b2e7 attempt to force colors in karma config
  • 60e3662 replace promise.allsettled with @ungap/promise-all-settled; closes #4474
  • f132448 remove duplicated/problem reporter tests; closes #4469
  • 31116db fix: remove job count from parallel mode debug log (#4416)
  • 478ca6a add "fixture flowchart" to docs (#4440)
  • 9c28990 support leading dots in --extension
  • 2852505 chore(deps): upgrade to latest stable
  • b216fcd Support multipart extensions like ".test.js" (#4442)
  • 1aa182b refactor: utils.type() (#4457); closes #4306
  • fd9fe95 Change serializer errors to use error codes (#4464)
  • 6ceca82 make guarantees about orphaned processes
  • f24f190 avoid deprecated add-path in GHA workflow
  • ca9bfc7 parallel mode: enable custom worker reporters and object references (#4409); closes #4403
  • df8e9e6 run all node.js tests on GHA (#4459)
  • 238268d cleanup a little bit of eslint config
  • 8f5d6a9 Update eslint version (#4443)
  • bb96de1 implement Open Collective categories for extended filtering
  • 28f970e ci(win): setup GH actions for windows CI (#4402)
  • 738a575 Add speed in -R json option (#4226) (#4434)
  • 5bdc208 remove unused interface tests (#4247)
See the full diff
Package name: mochawesome-merge The new version differs by 3 commits.
  • aedc7e8 Merge pull request #34 from Antontelesh/fix/33-files
  • 0d048bc fix(cli): accept list of source files
  • 5488967 feat(options): migrate API to use glob patterns
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic