twilio / twilio-voice-notification-app

Reference app built in ReactJS that demonstrates how to leverage Twilio Programmable Voice and Twilio SDKs to create a voice notification system.
Apache License 2.0
36 stars 25 forks source link

[Snyk] Security upgrade @nestjs/cli from 7.6.0 to 8.1.3 #88

Closed twilio-product-security closed 2 years ago

twilio-product-security commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @nestjs/cli The new version differs by 250 commits.
  • bcaa0ab Merge pull request #1359 from iloverink/fix-dep
  • 36a4507 Merge pull request #1254 from nestjs/renovate/webpack-5.x
  • 400b52e Merge pull request #1357 from nestjs/renovate/fork-ts-checker-webpack-plugin-6.x
  • bfed4d2 Merge pull request #1377 from nestjs/renovate/ts-jest-27.x
  • 6332547 Merge pull request #1351 from nestjs/renovate/angular-cli-monorepo
  • 0f72db9 chore(deps): update dependency ts-jest to v27.0.7
  • 7c1c23b chore(deps): update dependency ts-jest to v27.0.6
  • 6d05e89 chore(deps): update dependency @ types/node to v14.17.27
  • f1707ed fix(deps): update dependency fork-ts-checker-webpack-plugin to v6.3.4
  • bc301a6 chore(deps): update dependency eslint to v8.0.1
  • 10f67c7 chore(deps): update dependency @ types/node to v14.17.26
  • 68a99c1 fix(deps): update angular-cli monorepo to v12.2.10
  • 8ed6fba fix(deps): update dependency webpack to v5.58.2
  • b4e9db1 chore(deps): update dependency eslint-plugin-import to v2.25.2
  • 0fa4d58 chore(deps): update dependency @ types/node to v14.17.22
  • 586738b chore(deps): update dependency eslint-plugin-import to v2.25.1
  • 8057c17 chore(deps): update typescript-eslint monorepo to v5
  • 737367b chore(deps): update dependency ts-node to v10.3.0
  • d6bc804 chore(deps): update dependency @ types/webpack-node-externals to v2.5.3
  • 1012e51 chore(deps): update dependency cli-table3 to v0.6.0
  • 26a584d chore(deps): update dependency eslint to v8
  • 6519dab chore(deps): update dependency @ commitlint/cli to v13.2.1
  • 938687c chore(deps): update dependency jest to v27.2.5
  • 293749f chore(deps): update dependency @ types/node to v14.17.21
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

πŸ›  Adjust project settings

πŸ“š Read more about Snyk's upgrade and patch logic

ricardotwilio commented 2 years ago

Will update dependencies manually