watson-developer-cloud / node-sdk

:comet: Node.js library to access IBM Watson services.
https://www.npmjs.com/package/ibm-watson
Apache License 2.0
1.48k stars 669 forks source link

[Snyk] Security upgrade ibm-cloud-sdk-core from 2.14.3 to 3.0.0 #1167

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JS-FILETYPE-2958042
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: ibm-cloud-sdk-core The new version differs by 55 commits.
  • 552239b chore(release): 3.0.0 [skip ci]
  • 843e66d fix: update file-type to resolve vulnerability (#205)
  • c0e9cd8 chore(release): 2.17.15 [skip ci]
  • 1b3ef62 fix: ensure dist/docs is a directory during build (#202)
  • ab0f3e1 build(deps-dev): bump semantic-release from 19.0.2 to 19.0.3 (#200)
  • 3a490a7 build(deps): bump semver-regex from 3.1.3 to 3.1.4 (#199)
  • 4299ce6 build(deps): bump npm from 8.6.0 to 8.12.0 (#198)
  • 4085b9e chore(release): 2.17.14 [skip ci]
  • 5cb9081 fix: do not retry on 501 (#197)
  • 4340c8e chore(release): 2.17.13 [skip ci]
  • 4de8a9d fix: bump dependencies to avoid minimist vulnerability (#195)
  • 21da9b5 chore(release): 2.17.12 [skip ci]
  • dfbebee fix: update minimum Node version in package.json (#192)
  • 92c1715 chore(release): 2.17.11 [skip ci]
  • 59a440a fix: use correct type for cookie jar option
  • 90e0417 fix: update axios to remove vulnerability
  • 3f19fce chore(release): 2.17.10 [skip ci]
  • 8a69d8e fix: bump follow-redirects to avoid vuln (#191)
  • aa14b18 chore(release): 2.17.9 [skip ci]
  • b88c67a fix: bump version of follow-redirects to avoid vulnerability (#189)
  • f4f4258 chore(release): 2.17.8 [skip ci]
  • d05ea1a fix: avoid errors during logging of requests/responses (#188)
  • 60f5013 chore(release): 2.17.7 [skip ci]
  • 3a0aea5 fix: remove 'module' entry from package.json (#187)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

CLAassistant commented 2 years ago

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.