zuzak / foruli

Basic booklist creator
http://lunarllama.co.uk
0 stars 1 forks source link

[Snyk] Security upgrade convict from 0.4.3 to 6.2.3 #33

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-CONVICT-2774757
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: convict The new version differs by 250 commits.
  • deef5d7 v6.2.3
  • 5e64b53 More recent Ubuntu dist for Travis CI build
  • 1ea0ab1 More more complete fix for prototype pollution
  • c7acb02 Update info regarding publishing on NPM
  • 4da12f8 v6.2.2
  • 8ad66b5 Update CHANGELOG
  • 3b86be0 More complete fix against prototype pollution
  • e3173b1 Clearer variable name
  • 5eb1314 v6.2.1
  • 5ad62d6 Update CHANGELOG
  • c682086 fix misspelling of the word optional in the error message (#397)
  • bdd8a4e v6.2.0
  • f693077 Provide working links in the CHANGELOG
  • d90f2f8 Update CHANGELOG
  • 11ef47e chore: update dependencies (#390)
  • 41e8c4a v6.1.0
  • 8d198ef Update CHANGELOG for next 6.1.0 release
  • b31d451 Update CHANGELOG for previous release
  • 342fab6 Allow null additionally to any format (#386)
  • 7e068d8 v6.0.1
  • 81771b3 ran npm audit fix
  • dc17a2e Merge pull request #384 from 418sec/1-npm-convict
  • 180d692 Merge pull request #1 from arjunshibu/master
  • 688c46a Security fix for prototype pollution
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution