Skip to content

[Snyk] Fix for 1 vulnerabilities#37

Open
mskhirwar wants to merge 1 commit into
masterfrom
snyk-fix-e8006122a762ae6345b2caa44070080b
Open

[Snyk] Fix for 1 vulnerabilities#37
mskhirwar wants to merge 1 commit into
masterfrom
snyk-fix-e8006122a762ae6345b2caa44070080b

Conversation

@mskhirwar
Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: env-cmd The new version differs by 28 commits.
  • 065b110 chore(travis): update ci configuration
  • 020998a docs(readme): added expand env and silent docs
  • 27a2705 feat(flags): add silent flag to ignore errors
  • 500cf6a chore: rebuild ts files
  • 9a6ff59 Merge pull request #110 from elliottsj/version-fix
  • a253a62 chore(package): update devDependencies
  • 1b39ca1 fix: print correct package version
  • f92f8b5 feat(signal-termination): handle error codes in the signal value
  • fda2518 chore(package): update dependencies
  • d15248b Merge pull request #103 from omeid/master
  • 8318637 feat: Support env vars expansion in cmd and args
  • bd090e7 Merge pull request #101 from toddbluhm/add-verbos-flag
  • 3656bb0 chore(package): update commander dependency
  • 5d685b6 feat(flags): add --verbose flag and option
  • 0ff6bad chore(package): update ts-standard to version 3.0.0 (#102)
  • 27afb75 Fix typo (#100)
  • f7929ce chore(package): update ts-standard to v2
  • c00dd73 chore(readme): reference ts-standard instead of js-standard
  • 19148b6 fix(package): update cross-spawn to version 7.0.0 (#90)
  • 1cd2feb Fixed bug causing env-cmd to fail when no failure had occurred
  • 0106295 Update changelog
  • bbc4b78 Convert over to using ts-standard
  • f5e2e33 Updated typescript-eslint packages and fixed lint errors
  • ae79816 Added Env default locations (#81)

See the full diff

Package name: node-sass The new version differs by 88 commits.
  • c167004 6.0.1
  • 911d4db remove mkdirp dep (#3108)
  • 30a52f7 build(deps): bump meow from 3.7.0 to 9.0.0
  • 7e08463 build(deps-dev): bump mocha from 8.4.0 to 9.0.1
  • cfcbb2c chore: Use default Apline version from docker-node (#3121)
  • 886319b chore: Drop Node 10 support
  • c908f4f fix: Bump OSX minimum to 10.11
  • 8ab02da fix: Remove old compiler gyp settings
  • 3d7b9d0 chore: Add Node 16 support
  • 4115e9d build(deps): bump actions/setup-node from v2.1.4 to v2.1.5
  • 06f3ab4 Update TROUBLESHOOTING.md
  • c1cb367 build(deps): bump actions/setup-node from v2.1.3 to v2.1.4
  • 769f3a6 build(deps): bump actions/setup-node from v2.1.2 to v2.1.3
  • a2a3a78 chore: Bump dependabot limit
  • 7105b0a 5.0.0 (#3015)
  • 0648b5a chore: Add Node 15 support (#2983)
  • e2391c2 Add a deprecation message to the readme (#3011)
  • 6a33e53 chore: Don't upload artifacts on PRs
  • d763506 chore: Only run coverage on main repo
  • d4ebe72 build(deps): update actions/setup-node requirement to v2.1.2
  • 2bebe05 build(deps-dev): bump rimraf from 2.7.1 to 3.0.2
  • f877689 chore: Don't double build DependaBot PRs
  • b48fac4 chore: Add weekly DependaBot updates
  • 91c40a0 Remove deprecated process.sass API

See the full diff

Package name: sass-loader The new version differs by 61 commits.
  • 3b51d47 chore(release): 8.0.1
  • 6c59e37 fix: support webpack@5 (#794)
  • 5611f73 docs: improved documentation after breaking changes in release version 8.0.0 (#780)
  • 4834287 refactor: use startsWith (#792)
  • 22c597b refactor: use Array.includes (#777)
  • ed345fa chore(deps): switch to memfs (#791)
  • 2e14b68 chore: removed the duplicated prettier config (#781)
  • 9274387 chore(deps): update (#772)
  • 6d11b7b docs: overhaul readme (#771)
  • 185ba80 test: sass modules "@ use" (#770)
  • aa9b53b chore(release): 8.0.0
  • 45ad0be chore: next (#748)
  • 194fea4 chore(release): 7.3.1
  • 1175920 fix: minimum `node` version in `package.json` (#733)
  • a3ac649 chore(release): 7.3.0
  • 6f4ea37 feat: `webpackImporter` option (#732)
  • 0330253 docs: standardize readme (#730)
  • 997a255 fix: handle module import ending `/` as module (#728)
  • 071fa88 test: alias on directory with `_index` file (#727)
  • 6be93c8 test: import without quotes (#726)
  • dc23895 refactor: code (#725)
  • 97c93dd test: manual test (#724)
  • b2af379 fix: use "compressed" output when mode is "production" (#723)
  • 3545434 refactor: code

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants