victornpb / eleventy-plugin-page-assets

MIT License
21 stars 17 forks source link

[Snyk] Upgrade jsdom from 16.4.0 to 16.7.0 #9

Open victornpb opened 1 year ago

victornpb commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade jsdom from 16.4.0 to 16.7.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **6 versions** ahead of your current version. - The recommended version was released **2 years ago**, on 2021-08-01. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Prototype Pollution
[SNYK-JS-JSONSCHEMA-1920922](https://snyk.io/vuln/SNYK-JS-JSONSCHEMA-1920922) | **430/1000**
**Why?** CVSS 8.6 | No Known Exploit | Command Injection
[SNYK-JS-LODASH-1040724](https://snyk.io/vuln/SNYK-JS-LODASH-1040724) | **430/1000**
**Why?** CVSS 8.6 | Proof of Concept | Prototype Poisoning
[SNYK-JS-QS-3153490](https://snyk.io/vuln/SNYK-JS-QS-3153490) | **430/1000**
**Why?** CVSS 8.6 | Proof of Concept | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-LODASH-1018905](https://snyk.io/vuln/SNYK-JS-LODASH-1018905) | **430/1000**
**Why?** CVSS 8.6 | Proof of Concept | Denial of Service (DoS)
[SNYK-JS-NWSAPI-2841516](https://snyk.io/vuln/SNYK-JS-NWSAPI-2841516) | **430/1000**
**Why?** CVSS 8.6 | No Known Exploit | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-WS-1296835](https://snyk.io/vuln/SNYK-JS-WS-1296835) | **430/1000**
**Why?** CVSS 8.6 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: jsdom
  • 16.7.0 - 2021-08-01
  • 16.6.0 - 2021-05-23
  • 16.5.3 - 2021-04-11
  • 16.5.2 - 2021-03-28
  • 16.5.1 - 2021-03-13
  • 16.5.0 - 2021-03-07
  • 16.4.0 - 2020-08-08
from jsdom GitHub release notes
Commit messages
Package name: jsdom
  • 1aa3cbc Version 16.7.0
  • df1f551 Don't run WebSocketStream tests
  • eb105b2 Fix browser tests by enabling SharedArrayBuffer
  • 0dedfc0 Fix some bad cascade computation in getComputedStyle()
  • 8021a56 Fix "configuation" typo (#3213)
  • a7febe3 Fix typo in level2/html.js (#3222)
  • c9896c0 Return x, y properties from Element.getBoundingClientRect (#3187)
  • 346ea98 Update web-platform tests (#3203)
  • 364c77d Bump to ws 7.4.6
  • 93ba6a0 We are now on Matrix (#3207)
  • 0024630 Replace two HTTP README links with HTTPS
  • 74a8d1e Version 16.6.0
  • f51f2ec Remove the dependency on request
  • 2b6d5ae Update dependencies
  • b72b33b Disable now-crashing canvas test
  • 39b7972 Handle null and undefined thrown as exceptions
  • 04f6c13 Add ParentNode.replaceChildren() (#3176)
  • e4c4004 Version 16.5.3
  • 2f41466 Fix MutationObserver infinite loop bugs (#3173)
  • b232f2a Run partially-failing WPTs in the custom-elements directory
  • 35e103e Run partially-failing WPTs in the cors directory
  • 77b660a Run partially-failing WPTs in the FileAPI directory
  • d8a245f Use `InnerHTML` mixin for `innerHTML` definition (#2981)
  • bd50bbe Version 16.5.2
Compare

**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/victornpb/project/c285b400-093d-47a0-bb04-77c28e2424f4?utm_source=github&utm_medium=referral&page=upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/victornpb/project/c285b400-093d-47a0-bb04-77c28e2424f4/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/victornpb/project/c285b400-093d-47a0-bb04-77c28e2424f4/settings/integration?pkg=jsdom&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)